Skip to main content

4. Digest Algorithms Registry Column Values

Initial values for the use and implementation recommendation columns in the "Digest Algorithms" registry under the "DNSSEC Delegation Signer (DS) Resource Record (RR) Type Digest Algorithms" registry group are shown in Table 3.

When there are multiple RECOMMENDED algorithms in the "Use for" columns, operators should choose the best algorithm according to local policy.

ValueDescriptionUse for DNSSEC DelegationUse for DNSSEC ValidationImplement for DNSSEC DelegationImplement for DNSSEC Validation
0NULL (CDS only)MUST NOTMUST NOTMUST NOTMUST NOT
1SHA-1MUST NOTRECOMMENDEDMUST NOTMUST
2SHA-256RECOMMENDEDRECOMMENDEDMUSTMUST
3GOST R 34.11-94MUST NOTMAYMUST NOTMAY
4SHA-384MAYRECOMMENDEDMAYRECOMMENDED
5GOST R 34.11-2012MAYMAYMAYMAY
6SM3MAYMAYMAYMAY

Table 3: Initial Values for the Digest Algorithms Registry Columns