I-D Action: draft-jabley-dnsop-local-signing-algorithm-policy-00.txt
[email protected] Thu, 06 Aug 2026 05:39:52 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178601999280.154596.85825679283961585@dt-datatracker-559c48c7fb-qkhml> |
Internet-Draft draft-jabley-dnsop-local-signing-algorithm-policy-00.txt is now available. Title: Supporting Quantum-Safe Algorithms in DNSSEC with Local Resolver Policy Author: Joe Abley Name: draft-jabley-dnsop-local-signing-algorithm-policy-00.txt Pages: 7 Dates: 2026-08-06 Abstract: Security-aware resolvers validate signatures, where available, in order to protect their clients from inauthentic data. DNSSEC treats all algorithms as equal when it comes to validation, such that a single valid signature is considered sufficient proof of authenticity, and that data is only to be judged to be inauthentic if all available signatures are found to be invalid. However, a resolver might have a different local policy, e.g. in its handling of quantum-safe signatures. This document discusses such local policy and describes a means to indicate to a client that specific local policy has been applied to response validation. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-jabley-dnsop-local-signing-algorithm-policy/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-jabley-dnsop-local-signing-algorithm-policy-00.html Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]