Deploy360 3 March 2017

Comments? Internet Draft on DNSSEC Crypto Algorithm Agility

By Dan YorkSenior Advisor

DNSSEC badgeWhat are the challenges in deploying new cryptographic algorithms for DNSSEC? As we look to move to using new crypto algorithms such as ECDSA, what are the barriers to getting those new algorithms rolled out? And how can we overcome those barriers?

A few of us wrote an Internet Draft on this topic:

and with IETF 98 fast approaching I am considering whether we need to publish a revision.  So I’m curious – what do you think? Are there  topics that we missed? Text that we could make a bit more clear? Additional points to consider?

We’d welcome any and all feedback. You can leave comments here on the blog post, or on social media where this appears… or you could just do that old-fashioned email thing.

Thanks in advance!

Disclaimer: Viewpoints expressed in this post are those of the author and may or may not reflect official Internet Society positions.

Related Posts

Improving Technical Security 15 March 2019

DNS Privacy Frequently Asked Questions (FAQ)

We previously posted about how the DNS does not inherently employ any mechanisms to provide confidentiality for DNS transactions,...

Improving Technical Security 14 March 2019

Introduction to DNS Privacy

Almost every time we use an Internet application, it starts with a DNS (Domain Name System) transaction to map...

Improving Technical Security 13 March 2019

IPv6 Security for IPv4 Engineers

It is often argued that IPv4 practices should be forgotten when deploying IPv6, as after all IPv6 is a...