I-D Action: draft-jabley-dnsop-local-signing-algorithm-policy-00.txt

[email protected] Thu, 06 Aug 2026 05:39:52 -0700
Newsgroups gmane.ietf.announce
Message-ID <178601999280.154596.85825679283961585@dt-datatracker-559c48c7fb-qkhml>
Internet-Draft draft-jabley-dnsop-local-signing-algorithm-policy-00.txt is now
available.

   Title:   Supporting Quantum-Safe Algorithms in DNSSEC with Local Resolver Policy
   Author:  Joe Abley
   Name:    draft-jabley-dnsop-local-signing-algorithm-policy-00.txt
   Pages:   7
   Dates:   2026-08-06

Abstract:

   Security-aware resolvers validate signatures, where available, in
   order to protect their clients from inauthentic data.  DNSSEC treats
   all algorithms as equal when it comes to validation, such that a
   single valid signature is considered sufficient proof of
   authenticity, and that data is only to be judged to be inauthentic if
   all available signatures are found to be invalid.  However, a
   resolver might have a different local policy, e.g. in its handling of
   quantum-safe signatures.  This document discusses such local policy
   and describes a means to indicate to a client that specific local
   policy has been applied to response validation.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-jabley-dnsop-local-signing-algorithm-policy/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-jabley-dnsop-local-signing-algorithm-policy-00.html

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]