Movatterモバイル変換


[0]ホーム

URL:


Internet Assigned Numbers Authority

Domain Name System Security (DNSSEC) Algorithm Numbers

Created
2003-11-03
Last Updated
2025-11-13
Available Formats

XML

HTML

Plain text

Registries Included Below

DNS Security Algorithm Numbers

Registration Procedure(s)
Standards Action or Specification Required
Expert(s)
Unassigned
Reference
[RFC4034][RFC3755][RFC6014][RFC6944][RFC-ietf-dnsop-rfc8624-bis-13]
Note
Adding a new entry to the "DNS Security Algorithm Numbers”registry with a recommended value of "MAY" in the "Use for DNSSECSigning", "Use for DNSSEC Validation", "Implement for DNSSECSigning", or "Implement for DNSSEC Validation" columns will besubject to the Specification Required policy as defined in [RFC8126] in order to promote continued evolution of DNSSECalgorithms and DNSSEC agility. New entries added through theSpecification Required process will have the value of "MAY” forall columns.Adding a new entry to, or changing an existing value in, the “DNSSecurity Algorithm Numbers" registry that has any value other than"MAY" in the "Use for DNSSEC Signing", "Use for DNSSECValidation", "Implement for DNSSEC Signing", or "Implement forDNSSEC Validation" columns requires Standards Action.If an item is not marked as "RECOMMENDED", it does not necessarily meanthat it is flawed; rather, it indicates that the item either has not beenthrough the IETF consensus process, has limited applicability, or isintended only for specific use cases.
Note
The KEY, SIG, DNSKEY, RRSIG, DS, and CERT RRs use an 8-bit number usedto identify the security algorithm being used.All algorithm numbers in this registry may be used in CERT RRs. Zonesigning (DNSSEC) and transaction security mechanisms (SIG(0) and TSIG)make use of particular subsets of these algorithms. Only algorithmsusable for zone signing may appear in DNSKEY, RRSIG, and DS RRs.Only those usable for SIG(0) and TSIG may appear in SIG and KEY RRs.* There has been no determination of standardization of the use of thisalgorithm with Transaction Security.
Available Formats

CSV
NumberDescriptionMnemonicZone
Signing
Trans.
Sec.
Use for
DNSSEC Signing
Use for
DNSSEC Validation
Implement for
DNSSEC Signing
Implement for
DNSSEC Validation
Reference
0Delete DSDELETENN[RFC4034][proposed standard][RFC4398][proposed standard][RFC8078][proposed standard]
1RSA/MD5 (DEPRECATED, see 5)RSAMD5NYMUST NOTMUST NOTMUST NOTMUST NOT[RFC3110][proposed standard][RFC4034][proposed standard]
2Diffie-HellmanDHNY[RFC2539][proposed standard]
3DSA/SHA1DSAYYMUST NOTMUST NOTMUST NOTMUST NOT[RFC3755][proposed standard][RFC2536][proposed standard][Federal Information Processing Standards Publication (FIPS PUB) 186,Digital Signature Standard, 18 May 1994.][Federal Information Processing Standards Publication (FIPS PUB) 180-1,Secure Hash Standard, 17 April 1995.(Supersedes FIPS PUB 180 dated 11 May 1993.)]
4Reserved[RFC6725][proposed standard]
5RSA/SHA-1RSASHA1YYMUST NOTRECOMMENDEDNOT RECOMMENDEDMUST[RFC3110][proposed standard][RFC4034][proposed standard][RFC-ietf-dnsop-must-not-sha1-09]
6DSA-NSEC3-SHA1DSA-NSEC3-SHA1YYMUST NOTMUST NOTMUST NOTMUST NOT[RFC5155][proposed standard]
7RSASHA1-NSEC3-SHA1RSASHA1-NSEC3-SHA1YYMUST NOTRECOMMENDEDNOT RECOMMENDEDMUST[RFC5155][proposed standard][RFC-ietf-dnsop-must-not-sha1-09]
8RSA/SHA-256RSASHA256Y*RECOMMENDEDRECOMMENDEDMUSTMUST[RFC5702][proposed standard]
9Reserved[RFC6725][proposed standard]
10RSA/SHA-512RSASHA512Y*NOT RECOMMENDEDRECOMMENDEDNOT RECOMMENDEDMUST[RFC5702][proposed standard]
11Reserved[RFC6725][proposed standard]
12GOST R 34.10-2001 (DEPRECATED)ECC-GOSTY*MUST NOTMUST NOTMUST NOTMUST NOT[RFC5933][proposed standard][Change the status of GOST Signature Algorithms in DNSSEC in the IETF stream to Historic][RFC-ietf-dnsop-must-not-ecc-gost-07]
13ECDSA Curve P-256 with SHA-256ECDSAP256SHA256Y*RECOMMENDEDRECOMMENDEDMUSTMUST[RFC6605][proposed standard]
14ECDSA Curve P-384 with SHA-384ECDSAP384SHA384Y*MAYRECOMMENDEDMAYRECOMMENDED[RFC6605][proposed standard]
15Ed25519ED25519Y*RECOMMENDEDRECOMMENDEDRECOMMENDEDRECOMMENDED[RFC8080][proposed standard]
16Ed448ED448Y*MAYRECOMMENDEDMAYRECOMMENDED[RFC8080][proposed standard]
17SM2 signing algorithm with SM3 hashing algorithmSM2SM3Y*MAYMAYMAYMAY[RFC9563][informational]
18-22Unassigned
23GOST R 34.10-2012ECC-GOST12Y*MAYMAYMAYMAY[RFC9558][informational]
24-122Unassigned
123-251Reserved[RFC4034][proposed standard][RFC6014][proposed standard]
252Reserved for Indirect KeysINDIRECTNN[RFC4034][proposed standard]
253private algorithmPRIVATEDNSYYMAYMAYMAYMAY[RFC4034][proposed standard]
254private algorithm OIDPRIVATEOIDYYMAYMAYMAYMAY[RFC4034][proposed standard]
255Reserved[RFC4034][proposed standard]

DNS KEY Record Diffie-Hellman Prime Lengths

Registration Procedure(s)
IETF Review
Reference
[RFC2539]
Available Formats

CSV
ValueDescriptionReference
0Unassigned
1index into well-known table[RFC2539]
2index into well-known table[RFC2539]
3-15Unassigned

DNS KEY Record Diffie-Hellman Well-Known Prime/Generator Pairs

Reference
[RFC2539]
Available Formats

CSV
RangeRegistration Procedures
0x0000-0x07ffStandards Action
0x0800-0xbfffRFC Required
ValueDescriptionReference
0x0000Unassigned
0x0001Well-Known Group 1: A 768 bit prime[RFC2539]
0x0002Well-Known Group 2: A 1024 bit prime[RFC2539]
0x0003-0xbfffUnassigned
0xc000-0xffffPrivate Use[RFC2539]

[8]ページ先頭

©2009-2025 Movatter.jp