DNSSEC records signed with RSASHA1 and NSEC3RSASHA1 fail to verify
Issue
DNSSEC records signed with the SHA-1 digest algorithm will fail to verify in Red Hat Enterprise Linux 9. The SHA-1 digest algorithm is no longer considered secure and it is deprecated in Red Hat Enterprise Linux 9.
Environment
- Red Hat Enterprise Linux 9
- bind or unbound packages
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.