4. Operational Considerations
Zone owners currently making use of SHA-1-based algorithms should immediately switch to algorithms with stronger cryptographic algorithms, such as the recommended algorithms in the IANA registries [DNSKEY-IANA] [DS-IANA].
Operators should take care when deploying software packages and operating systems that may have already removed support for the SHA-1 algorithm. In these situations, software may need to be manually built and deployed by an operator to continue supporting the required levels indicated by the "Use for DNSSEC Validation" and "Implement for DNSSEC Validation" columns, which this document is not changing.