Skip to main content

3. DNS Security Algorithm Numbers Registry Column Values

Initial values for the use and implementation recommendation columns in the "DNS Security Algorithm Numbers" registry under the "Domain Name System Security (DNSSEC) Algorithm Numbers" registry group are shown in Table 2.

When there are multiple RECOMMENDED algorithms in the "Use for" columns, operators should choose the best algorithm according to local policy.

No.MnemonicsUse for DNSSEC SigningUse for DNSSEC ValidationImplement for DNSSEC SigningImplement for DNSSEC Validation
1RSAMD5MUST NOTMUST NOTMUST NOTMUST NOT
3DSAMUST NOTMUST NOTMUST NOTMUST NOT
5RSASHA1NOT RECOMMENDEDRECOMMENDEDNOT RECOMMENDEDMUST
6DSA-NSEC3-SHA1MUST NOTMUST NOTMUST NOTMUST NOT
7RSASHA1-NSEC3-SHA1NOT RECOMMENDEDRECOMMENDEDNOT RECOMMENDEDMUST
8RSASHA256RECOMMENDEDRECOMMENDEDMUSTMUST
10RSASHA512NOT RECOMMENDEDRECOMMENDEDNOT RECOMMENDEDMUST
12ECC-GOSTMUST NOTMAYMUST NOTMAY
13ECDSAP256SHA256RECOMMENDEDRECOMMENDEDMUSTMUST
14ECDSAP384SHA384MAYRECOMMENDEDMAYRECOMMENDED
15ED25519RECOMMENDEDRECOMMENDEDRECOMMENDEDRECOMMENDED
16ED448MAYRECOMMENDEDMAYRECOMMENDED
17SM2SM3MAYMAYMAYMAY
23ECC-GOST12MAYMAYMAYMAY
253PRIVATEDNSMAYMAYMAYMAY
254PRIVATEOIDMAYMAYMAYMAY

Table 2: Initial Values for the DNS Security Algorithm Numbers Registry Columns