ADVERT
NSEC3PARAM Checker
Fetch NSEC3PARAM values to review the hashing algorithm, salt, and iteration count used for DNSSEC denial of existence.
How to use this tool
- Query NSEC3PARAM records for the zone.
- Inspect algorithm, iterations, and salt values returned by DNS.
- Compare parameters with signer policy and active NSEC3 records.
Parameter checks
- Validate hash algorithm and iteration count against expected settings.
- Review salt changes during rollover and maintenance events.
- Use TTL to estimate propagation timing for parameter updates.
Operational guidance
- High iteration values can increase resolver workload and latency.
- Salt changes generally require full zone resigning and careful rollout.
- Keep NSEC3PARAM and generated NSEC3 chain settings in sync.
FAQ
- What does iteration count affect?
- It controls repeated hashing rounds, trading off brute-force resistance versus resolver processing cost.
- When should salt be rotated?
- Rotate on policy or incident requirements, and ensure the zone is resigned so updated hashes propagate correctly.
- Why is algorithm value often 1?
- Value 1 maps to SHA-1 in RFC 5155 and remains the common NSEC3 algorithm value in deployed zones.
Resources
ADVERT
ADVERT