You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For security and performance reasons a lot of implementations are moving from RSA to ECDSA or direct to ed25519.
This should also be mentioned to DNSKEY's.
Can you add on one site the DNSKEY in your DNS section and also the Algorithm used in the dnssec part?
Maybe with the information which older DS/DNSKEY algorithms should be updated to something more secure?
Would be nice to show that information to different domain owners who have no clue and not any tool to see that for themselves.
There could be a hint if the Algorithm of the configured DNSKEY is for example not recommend.
like:
RFC 4034 B.1
Algorithm 1 (RSA/MD5)
Please note that Algorithm 1 is NOT RECOMMENDED.
Torsten
The text was updated successfully, but these errors were encountered: