@techreport{fanf-dnsop-sha-ll-not-00, number = {draft-fanf-dnsop-sha-ll-not-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-fanf-dnsop-sha-ll-not/00/}, author = {Tony Finch}, title = {{Hardening DNSSEC against collision weaknesses in SHA-1 and other cryptographic hash algorithms}}, pagetotal = 18, year = 2020, month = mar, day = 9, abstract = {DNSSEC deployments have often used the SHA-1 cryptographic hash algorithm to provide authentication of DNS data. This document explains why SHA-1 is no longer secure for this purpose, and deprecates its use in DNSSEC signatures. This document updates RFC 8624.}, }