Skip to main content

3. DNS 安全算法编号注册表列值 (DNS Security Algorithm Numbers Registry Column Values)

"域名系统安全 (DNSSEC) 算法编号"注册表组下的"DNS 安全算法编号"注册表中使用和实现推荐列的初始值如表 2 所示。

当"用于"列中有多个 RECOMMENDED (推荐) 算法时,运营者应根据本地策略选择最佳算法。

编号助记符用于 DNSSEC 签名用于 DNSSEC 验证实现用于 DNSSEC 签名实现用于 DNSSEC 验证
1RSAMD5MUST NOTMUST NOTMUST NOTMUST NOT
3DSAMUST NOTMUST NOTMUST NOTMUST NOT
5RSASHA1NOT RECOMMENDEDRECOMMENDEDNOT RECOMMENDEDMUST
6DSA-NSEC3-SHA1MUST NOTMUST NOTMUST NOTMUST NOT
7RSASHA1-NSEC3-SHA1NOT RECOMMENDEDRECOMMENDEDNOT RECOMMENDEDMUST
8RSASHA256RECOMMENDEDRECOMMENDEDMUSTMUST
10RSASHA512NOT RECOMMENDEDRECOMMENDEDNOT RECOMMENDEDMUST
12ECC-GOSTMUST NOTMAYMUST NOTMAY
13ECDSAP256SHA256RECOMMENDEDRECOMMENDEDMUSTMUST
14ECDSAP384SHA384MAYRECOMMENDEDMAYRECOMMENDED
15ED25519RECOMMENDEDRECOMMENDEDRECOMMENDEDRECOMMENDED
16ED448MAYRECOMMENDEDMAYRECOMMENDED
17SM2SM3MAYMAYMAYMAY
23ECC-GOST12MAYMAYMAYMAY
253PRIVATEDNSMAYMAYMAYMAY
254PRIVATEOIDMAYMAYMAYMAY

表 2: DNS 安全算法编号注册表列的初始值