> On Oct 9, 2020, at 12:08 PM, Ben Schwartz <bem...@google.com> wrote:
> 6.2.  Use of Multiple ZONEMD Hash Algorithms
>    When a zone publishes multiple ZONEMD RRs, the overall security is
>    only as good as the weakest hash algorithm in use.
> Why not require recipients to verify all digests with recognized algorithms?

That text stating that one is sufficient was based on a conversation in the 
working group that started here:



Attachment: smime.p7s
Description: S/MIME cryptographic signature

DNSOP mailing list

Reply via email to