Review Cloud DNS DNSSEC signing algorithms

Use a recommended DNSSEC signing algorithm and preserve the trust chain during migration.

Description

RSASHA1 uses SHA-1 for DNSSEC signatures and is not recommended for new signing. An algorithm accepted by the service must still be assessed against organizational cryptographic requirements and current security guidance.

DNSSEC validates the origin and integrity of DNS data; it does not encrypt the traffic. Algorithm changes affect both zone signing and DS records in the parent zone.

Potential impact

  • Continued use of an older signing algorithm may not meet cryptographic security requirements.
  • Mismatched keys or DS records during migration can interrupt name resolution through validation failures.

Remediation

Migrate to a recommended algorithm supported by Cloud DNS and validating clients. Provide the correct key-signing and zone-signing settings in default_key_specs. For an already signed zone, follow Cloud DNS procedures for DS records and TTLs and verify actual name resolution.

Examples

These examples compare key settings before DNSSEC is enabled. default_key_specs can be changed while DNSSEC is off. Replace the zone, project and service account JSON file path with actual values.

Before

yaml
- name: create a managed zone
  google.cloud.gcp_dns_managed_zone:
    name: test-zone
    dns_name: test.somewild2.example.com.
    description: test zone
    project: test_project
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present
    dnssec_config:
      default_key_specs:
        - algorithm: rsasha1
          key_type: keySigning
          key_length: 2048
        - algorithm: rsasha1
          key_type: zoneSigning
          key_length: 2048
      state: "off"

This selects rsasha1 for key-signing and zone-signing keys. With state set to "off", the example itself does not enable DNSSEC signing.

After

yaml
- name: create a managed zone
  google.cloud.gcp_dns_managed_zone:
    name: test-zone
    dns_name: test.somewild2.example.com.
    description: test zone
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
    dnssec_config:
      default_key_specs:
        - algorithm: rsasha256
          key_type: keySigning
          key_length: 2048
        - algorithm: rsasha256
          key_type: zoneSigning
          key_length: 2048
      state: "off"

This selects rsasha256 for both key types. DNSSEC remains off, so configure signing and the parent trust chain separately before relying on validation.

References