Commit 85523853 authored by Jan Včelák's avatar Jan Včelák 🚀

doc: new default DNSSEC algorithm

parent 2e64ea6d
......@@ -463,14 +463,14 @@ of the following parameters:
Signing algorithm
An algorithm of signing keys and issued signatures. The default value is
*RSA-SHA-256*.
*ECDSA-P256-SHA256*.
:abbr:`KSK (Key Signing Key)` size
Desired length of the newly generated ZSK keys. The default value is 2048
bits.
Desired length of the newly generated ZSK keys. The default value is 256
bits (the only feasible value for the default signing algorithm).
:abbr:`ZSK (Zone Signing Key)` size
Desired length of the newly generated ZSK keys. The default value is 1024
Desired length of the newly generated ZSK keys. The default value is 256
bits.
DNSKEY TTL
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment