DNSSEC Delegation Signer (DS) Resource Record (RR) Type Digest Algorithms

Created
2003-10-31
Last Updated
2026-01-13
Available Formats

XML

HTML

TXT

Registry Included Below

Digest Algorithms

Registration Procedure(s)
Standards Action or Specification Required
Expert(s)
Mark Andrews, Roy Arends, Warren Kumari, Wes Hardaker
Reference
[RFC 3658][RFC 4034][RFC 4035][RFC 9157][RFC 9904]
Note
Adding a new entry to the "Digest Algorithms" registry with a
recommended value of "MAY" in the "Use for DNSSEC Delegation”,
"Use for DNSSEC Validation", "Implement for DNSSEC Delegation", or
"Implement for DNSSEC Validation" columns SHALL follow the
Specification Required policy as defined in [RFC 8126].

Adding a new entry to, or changing an existing value in, the
"Digest Algorithms" registry that has any value other than “MAY"
in the "Use for DNSSEC Delegation", "Use for DNSSEC Validation”,
"Implement for DNSSEC Delegation", or "Implement for DNSSEC
Validation" columns requires Standards Action.

If an item is not marked as "RECOMMENDED", it does not
necessarily mean that it is flawed; rather, it indicates
that the item either has not been through the IETF consensus
process, has limited applicability, or is intended only for
specific use cases.
    
Available Formats

CSV
Value Description Use for DNSSEC Delegation Use for DNSSEC Validation Implement for DNSSEC Delegation Implement for DNSSEC Validation Reference
0 Reserved MUST NOT MUST NOT MUST NOT MUST NOT [RFC 3658]
1 SHA-1 MUST NOT RECOMMENDED MUST NOT MUST [RFC 3658][RFC 9905]
2 SHA-256 RECOMMENDED RECOMMENDED MUST MUST [RFC 4509]
3 GOST R 34.11-94 (DEPRECATED) MUST NOT MUST NOT MUST NOT MUST NOT [RFC 5933][Change the status of GOST Signature Algorithms in DNSSEC in the IETF stream to Historic][RFC 9906]
4 SHA-384 MAY RECOMMENDED MAY RECOMMENDED [RFC 6605]
5 GOST R 34.11-2012 MAY MAY MAY MAY [RFC 9558]
6 SM3 MAY MAY MAY MAY [RFC 9563]
7-127 Unassigned
128-252 Reserved [RFC 9904]
253-254 Reserved for Private Use [RFC 9904]
255 Unassigned