Description
RSASHA1 is an older DNSSEC signing algorithm that uses SHA-1 and is not recommended for new signatures. Enabling DNSSEC alone does not establish that the algorithm and key configuration meet security requirements.
DNSSEC validates DNS response origin and integrity; it does not encrypt communications. Algorithm changes affect zone signing and the parent DS records.
Potential impact
- An outdated signing algorithm may not meet organizational cryptographic requirements.
- Inconsistent keys and parent DS records during a change can interrupt name resolution.
Remediation
- Select a recommended algorithm supported by Cloud DNS and validating clients, and prepare both key-signing and zone-signing settings.
- Follow the documented DS and TTL transition procedure for an existing zone.
defaultKeySpecscan be changed only while the state isoff; do not simply replace values on a live signed zone. Verify signing and validation afterward.
Examples
These excerpts show only algorithm selection in the retired Deployment Manager format. Required settings such as names, domains and key types are omitted. Prepare a complete key configuration in a supported tool. These are not an update procedure to apply directly to an existing signed zone.
Before
resources:
- name: dns
type: dns.v1.managedZone
properties:
dnssecConfig:
state: "on"
defaultKeySpecs:
- algorithm: rsasha1
After
resources:
- name: dns
type: dns.v1.managedZone
properties:
dnssecConfig:
state: "on"
defaultKeySpecs:
- algorithm: rsasha256
Explanation:
- Before: RSASHA1 is selected.
- After: RSASHA256 is selected. Verify the configuration of both key types and the parent chain of trust as well.