I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last-call comments. This document updates the old GOST digital signature and hash algorithm with the new ones for usage in DNSKEY, RRSIG, and DS resource records. Section 8 explains how the paragraph describing the state of GOST algorithms in section 3.1 of RFC 8624 is updated. Why is section 3.3 of RFC 8624 containing the text "GOST R 34.11-2012 has not been standardized for use in DNSSEC." not updated in a similar fashion?