Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSEC

E738665

"Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSEC" (RFC 5702) is an IETF standards-track document that specifies how to employ SHA-2 hash algorithms with RSA signatures in DNSSEC to enhance the security of DNS authentication.

All labels observed (2)

How this entity was disambiguated

Statements (42)

Predicate Object
instanceOf IETF standards-track document
Request for Comments
addresses use of stronger hash functions than SHA-1 in DNSSEC
aimsTo improve robustness of DNSSEC signatures
appliesTo DNSKEY resource records
RRSIG resource records
area Security
category Standards Track
contributesTo overall security of the DNS infrastructure
defines new DNSSEC algorithm identifiers for RSA with SHA-2
definesAlgorithmForDNSSEC RSA/SHA-256
RSA/SHA-512
linked to: RSA
definesFieldUsage DNSKEY algorithm field for RSA/SHA-2
RRSIG algorithm field for RSA/SHA-2
definesUseOf SHA-2 hash algorithms with RSA in DNSSEC
hashAlgorithmFamily SHA-2
intendedFor DNS operators
protocol implementers
security practitioners
motivatedBy cryptographic weaknesses of SHA-1
obsoletesAlgorithmUsage exclusive reliance on RSA/SHA-1 in DNSSEC
partOf DNSSEC standards corpus
linked to: DNSSEC
protocol DNSSEC
publishedBy Internet Engineering Task Force
publishedInSeries RFC series
linked to: RFCs
purpose to enhance the security of DNS authentication
relatedTo DNSSEC algorithm agility
relevantTo DNS authoritative name servers
DNS resolvers
DNSSEC validators
shortTitle Use of SHA-2 Algorithms with RSA in DNSSEC
signatureAlgorithmFamily RSA
specifies operational considerations for deploying RSA/SHA-2 in DNSSEC
wire format considerations for RSA/SHA-2 in DNSSEC
specifiesUseInRecordType DNSKEY
RRSIG
linked to: DNSKEY
standardizes use of SHA-256 with RSA in DNSSEC
use of SHA-512 with RSA in DNSSEC
status Proposed Standard
stream IETF
title Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSEC
updatesSpecificationFor Domain Name System Security Extensions

How these facts were elicited

Referenced by (3)

Full triples — surface form annotated when it differs from this entity's canonical label.

RFC 5702 title Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSEC
RFC 5702 title Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSEC
RFC 5702 shortTitle Use of SHA-2 Algorithms with RSA in DNSSEC
linked to: Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSEC