[PR #2999] [MERGED] Remove unused fields: minimum algorithm/key length #3481

Closed
opened 2026-03-16 11:46:04 +03:00 by kerem · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/hickory-dns/hickory-dns/pull/2999
Author: @divergentdave
Created: 5/20/2025
Status: Merged
Merged: 5/20/2025
Merged by: @divergentdave

Base: mainHead: david/remove-minimum-algorithm


📝 Commits (1)

  • ede9538 Remove unused fields: minimum algorithm/key length

📊 Changes

1 file changed (+1 additions, -7 deletions)

View changed files

📝 crates/proto/src/dnssec/dnssec_dns_handle/mod.rs (+1 -7)

📄 Description

This removes two unused fields on DnssecDnsHandle. Setting a minimum algorithm identifier doesn't make sense, as the identifier values are not ordered by security strength. Downgrade attacks are best addressed by zone signers themselves, as they choose which algorithms and RSA key sizes to put in their own DNSKEY RRsets.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/hickory-dns/hickory-dns/pull/2999 **Author:** [@divergentdave](https://github.com/divergentdave) **Created:** 5/20/2025 **Status:** ✅ Merged **Merged:** 5/20/2025 **Merged by:** [@divergentdave](https://github.com/divergentdave) **Base:** `main` ← **Head:** `david/remove-minimum-algorithm` --- ### 📝 Commits (1) - [`ede9538`](https://github.com/hickory-dns/hickory-dns/commit/ede95384d8ab2b696393d4493941bdafcb6cd569) Remove unused fields: minimum algorithm/key length ### 📊 Changes **1 file changed** (+1 additions, -7 deletions) <details> <summary>View changed files</summary> 📝 `crates/proto/src/dnssec/dnssec_dns_handle/mod.rs` (+1 -7) </details> ### 📄 Description This removes two unused fields on `DnssecDnsHandle`. Setting a minimum algorithm identifier doesn't make sense, as the identifier values are not ordered by security strength. Downgrade attacks are best addressed by zone signers themselves, as they choose which algorithms and RSA key sizes to put in their own DNSKEY RRsets. --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
kerem 2026-03-16 11:46:04 +03:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/hickory-dns#3481
No description provided.