[Errata Verified] RFC6944 (4932)

RFC Errata System <[email protected]> Tue, 28 Feb 2017 17:40:33 -0800 (PST)
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
The following errata report has been verified for RFC6944,
"Applicability Statement: DNS Security (DNSSEC) DNSKEY Algorithm Implementation Status". 

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=6944&eid=4932

--------------------------------------
Status: Verified
Type: Technical

Reported by: Petr Spacek <[email protected]>
Date Reported: 2017-02-12
Verified by: Terry Manderson (IESG)

Section: 3

Original Text
-------------
   This document lists the implementation status of cryptographic
   algorithms used with DNSSEC.  These algorithms are maintained in an
   IANA registry at http://www.iana.org/assignments/dns-sec-alg-numbers.
   Because this document establishes the implementation status of every
   algorithm, it has been listed as a reference for the registry itself.

Corrected Text
--------------
   This document lists the implementation status of cryptographic
   algorithms used with DNSSEC.  These algorithms are maintained in an
   IANA registry at http://www.iana.org/assignments/dns-sec-alg-numbers.
   Because this document establishes the implementation status of every
   algorithm, it has been listed as a reference for the registry itself.

   Given significance of status change of RSAMD5 algorithm, a reference
   to this RFC should be added to the registry.

Notes
-----
"RSAMD5 has an implementation status of Must Not Implement because of known weaknesses in MD5."

This is very important. An additional reference would lower likelihood that DNS Implementors will overlook the important piece of information.

--------------------------------------
RFC6944 (draft-ietf-dnsext-dnssec-algo-imp-status-04)
--------------------------------------
Title               : Applicability Statement: DNS Security (DNSSEC) DNSKEY Algorithm Implementation Status
Publication Date    : April 2013
Author(s)           : S. Rose
Category            : PROPOSED STANDARD
Source              : DNS Extensions
Area                : Internet
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext