Re: [DNSOP] RFC5155 and hash collision vs RFC9276

2023-01-17 Thread Frederico A C Neves
On Tue, Jan 17, 2023 at 01:56:04PM +0100, Otto Moerbeek wrote: > Hi, > > I was wondering about RFC9276 which says: "SHOULD NOT use salt", while > RFC5155 section 7.1. says: > > "If a hash collision is detected, then a new salt has to be chosen, > and the signing process restarted." > > Now I kno

[DNSOP] RFC5155 and hash collision vs RFC9276

2023-01-17 Thread Otto Moerbeek
Hi, I was wondering about RFC9276 which says: "SHOULD NOT use salt", while RFC5155 section 7.1. says: "If a hash collision is detected, then a new salt has to be chosen, and the signing process restarted." Now I know it is *very* unlikely to see a collision when signing a zone, but is this perha