Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

drill -s example.com print still SHA1 digest #262

Open
pemensik opened this issue Dec 3, 2024 · 0 comments
Open

drill -s example.com print still SHA1 digest #262

pemensik opened this issue Dec 3, 2024 · 0 comments

Comments

@pemensik
Copy link
Contributor

pemensik commented Dec 3, 2024

I think it should print only sha256 digest, unless explicitly requested. digest alg 1 is not considered secure enough I think.

$ drill -s dnskey example.com
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 32989
;; flags: qr rd ra ; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0 
;; QUESTION SECTION:
;; example.com.	IN	DNSKEY

;; ANSWER SECTION:
example.com.	3600	IN	DNSKEY	256 3 13 ai2pvpijJjeNTpBu4yg6T375JqIStPtLABDTAILb+f4J7XpofUNXGQn6FpQvZ6CARWn2xQapbjGtDRjTf4qYxg== ;{id = 60915 (zsk), size = 256b}
example.com.	3600	IN	DNSKEY	257 3 13 kXKkvWU3vGYfTJGl3qBd4qhiWp5aRs7YtkCJxD2d+t7KXqwahww5IgJtxJT2yFItlggazyfXqJEVOmMJ3qT0tQ== ;{id = 370 (ksk), size = 256b}

;; AUTHORITY SECTION:

;; ADDITIONAL SECTION:

;; Query time: 105 msec
;; SERVER: 127.0.0.1
;; WHEN: Tue Dec  3 17:56:14 2024
;; MSG SIZE  rcvd: 189
;
; equivalent DS records for key 60915:
; sha1: example.com.	3600	IN	DS	60915 13 1 c95eeb716d6ed9b309f18e5dc1ca65df341478a1
; sha256: example.com.	3600	IN	DS	60915 13 2 74510431a97d383d2d8b9101643ee493a6ec754aafb7431295210d59b6e501f6
;
; equivalent DS records for key 370:
; sha1: example.com.	3600	IN	DS	370 13 1 19c524a336c67620cf29c8b8f7bd3b6456e05a5e
; sha256: example.com.	3600	IN	DS	370 13 2 be74359954660069d5c63d200c39f5603827d7dd02b56f120ee9f3a86764247c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant