Skip to content
  • Tony Finch's avatar
    Deprecate SHA-1 in `dnssec-dsfromkey` · 796a6c4e
    Tony Finch authored and Evan Hunt's avatar Evan Hunt committed
    This makes the `-12a` options to `dnssec-dsfromkey` work more like
    `dnssec-cds`, in that you can specify more than one digest and you
    will get multiple records. (Previously you could only get one
    non-default digest type at a time.)
    
    The default is now `-2`. You can get the old behaviour with `-12`.
    
    Tests and tools that use `dnssec-dsfromkey` have been updated to use
    `-12` where necessary.
    
    This is for conformance with the DS/CDS algorithm requirements in
    https://tools.ietf.org/html/draft-ietf-dnsop-algorithm-update
    796a6c4e