[DNSOP] Re: draft-johani-dnsop-dnssec-alg-experimental-range

Petr Špaček <[email protected]> Tue, 14 Jul 2026 13:49:40 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Hi.

First, I support goal of this document - having both ranges allocated.

On 25. 06. 26 21:08, Johan Stenstam wrote:
> The problem that the only “experimental use” DNSSEC algorithms are the 
> multiplexed 253+254 code points that have unique constraints on how they 
> can be used has been discussed repeatedly. And the problem simply 
> doesn’t go away.
Having said that, I disagree with most of the text in the document. Most 
of it is a very long description of laziness.

253 and 254 code points require one-time cost to code the support for 
it. It is in the spec for 20+ years, so it is basically technical debt.

I agree 253 and 254 are ugly because DS and RRSIG do not have the 
identifier. If that is considered to be a significant problem we could 
also standardize say 249 PRIVATEDNSBETTER and 250 PRIVATEOIDBETTER which 
do add the identifier to both fields. That would be marginally more 
work, but significantly more future proof, and IMHO better design design.

Having said all this, I recognize many people want to do their thing and 
are not interested in repaying technical debt (after all the draft says 
we don't care and number-squat already...).

For that sole reason I think it is better to get experimental and 
private ranges allocated now and legalize what folks are already doing.

-- 
Petr Špaček

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]