DNSSEC uses RSASHA1

Review DNSSEC signing algorithms and preserve the chain of trust during key changes.

Description

RSASHA1 is an older DNSSEC signing algorithm that uses SHA-1 and is not recommended for new signatures. Enabling DNSSEC alone does not establish that the algorithm and key configuration meet security requirements.

DNSSEC validates DNS response origin and integrity; it does not encrypt communications. Algorithm changes affect zone signing and the parent DS records.

Potential impact

  • An outdated signing algorithm may not meet organizational cryptographic requirements.
  • Inconsistent keys and parent DS records during a change can interrupt name resolution.

Remediation

  • Select a recommended algorithm supported by Cloud DNS and validating clients, and prepare both key-signing and zone-signing settings.
  • Follow the documented DS and TTL transition procedure for an existing zone. defaultKeySpecs can be changed only while the state is off; do not simply replace values on a live signed zone. Verify signing and validation afterward.

Examples

These excerpts show only algorithm selection in the retired Deployment Manager format. Required settings such as names, domains and key types are omitted. Prepare a complete key configuration in a supported tool. These are not an update procedure to apply directly to an existing signed zone.

Before

yaml
resources:
  - name: dns
    type: dns.v1.managedZone
    properties:
      dnssecConfig:
        state: "on"
        defaultKeySpecs:
          - algorithm: rsasha1

After

yaml
resources:
  - name: dns
    type: dns.v1.managedZone
    properties:
      dnssecConfig:
        state: "on"
        defaultKeySpecs:
          - algorithm: rsasha256

Explanation:

  • Before: RSASHA1 is selected.
  • After: RSASHA256 is selected. Verify the configuration of both key types and the parent chain of trust as well.

References