Review GCP DNSSEC signing algorithms

Migrate to a recommended DNSSEC algorithm while preserving the trust chain.

Description

RSASHA1 uses SHA-1 for DNSSEC signatures and is not recommended for new signing. Even with DNSSEC enabled, review algorithms and key settings against organizational cryptographic requirements.

Algorithm changes affect zone signing and parent DS records. DNSSEC validates origin and integrity; it does not encrypt the communication.

Potential impact

  • Older signing algorithms may not meet security requirements.
  • Mismatched keys and DS records during changes can interrupt name resolution.

Remediation

  • Choose a recommended algorithm supported by Cloud DNS and validating clients, and provide both key-signing and zone-signing settings.
  • For signed zones, follow official DS and TTL transition procedures. Change default_key_specs while state is off, and verify signing and validation afterward.

Examples

These examples compare key settings before enabling signing. Both keep state = "off" and do not enable DNSSEC. Replace the name and domain with actual values and configure the keys and parent chain according to the actual transition procedure.

Before

hcl
resource "google_dns_managed_zone" "example" {
  name     = "example-zone"
  dns_name = "example.com."

  dnssec_config {
    state = "off"
    default_key_specs {
      algorithm  = "rsasha1"
      key_type   = "keySigning"
      key_length = 2048
    }
    default_key_specs {
      algorithm  = "rsasha1"
      key_type   = "zoneSigning"
      key_length = 2048
    }
  }
}

After

hcl
resource "google_dns_managed_zone" "example" {
  name     = "example-zone"
  dns_name = "example.com."

  dnssec_config {
    state = "off"
    default_key_specs {
      algorithm  = "rsasha256"
      key_type   = "keySigning"
      key_length = 2048
    }
    default_key_specs {
      algorithm  = "rsasha256"
      key_type   = "zoneSigning"
      key_length = 2048
    }
  }
}

Explanation:

  • Before: RSASHA1 is selected for both key types, but zone signing is off.
  • After: RSASHA256 is selected for both key types. Configure DNSSEC signing and parent DS records separately before relying on protection.

References