Description
RSASHA1 uses SHA-1 for DNSSEC signatures and is not recommended for new signing. An algorithm accepted by the service must still be assessed against organizational cryptographic requirements and current security guidance.
DNSSEC validates the origin and integrity of DNS data; it does not encrypt the traffic. Algorithm changes affect both zone signing and DS records in the parent zone.
Potential impact
- Continued use of an older signing algorithm may not meet cryptographic security requirements.
- Mismatched keys or DS records during migration can interrupt name resolution through validation failures.
Remediation
Migrate to a recommended algorithm supported by Cloud DNS and validating clients. Provide the correct key-signing and zone-signing settings in default_key_specs. For an already signed zone, follow Cloud DNS procedures for DS records and TTLs and verify actual name resolution.
Examples
These examples compare key settings before DNSSEC is enabled. default_key_specs can be changed while DNSSEC is off. Replace the zone, project and service account JSON file path with actual values.
Before
- name: create a managed zone
google.cloud.gcp_dns_managed_zone:
name: test-zone
dns_name: test.somewild2.example.com.
description: test zone
project: test_project
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
dnssec_config:
default_key_specs:
- algorithm: rsasha1
key_type: keySigning
key_length: 2048
- algorithm: rsasha1
key_type: zoneSigning
key_length: 2048
state: "off"
This selects rsasha1 for key-signing and zone-signing keys. With state set to "off", the example itself does not enable DNSSEC signing.
After
- name: create a managed zone
google.cloud.gcp_dns_managed_zone:
name: test-zone
dns_name: test.somewild2.example.com.
description: test zone
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
dnssec_config:
default_key_specs:
- algorithm: rsasha256
key_type: keySigning
key_length: 2048
- algorithm: rsasha256
key_type: zoneSigning
key_length: 2048
state: "off"
This selects rsasha256 for both key types. DNSSEC remains off, so configure signing and the parent trust chain separately before relying on validation.