    Deprecate SHA-1 in `dnssec-dsfromkey` · 796a6c4e
    Tony Finch authored
    This makes the `-12a` options to `dnssec-dsfromkey` work more like
    `dnssec-cds`, in that you can specify more than one digest and you
    will get multiple records. (Previously you could only get one
    non-default digest type at a time.)
    The default is now `-2`. You can get the old behaviour with `-12`.
    Tests and tools that use `dnssec-dsfromkey` have been updated to use
    `-12` where necessary.
    This is for conformance with the DS/CDS algorithm requirements in
