[DNSOP] Re: [Ext] An unofficial DNSSEC algorithm testing registry

Jim Reid <[email protected]> Tue, 14 Jul 2026 15:20:42 +0100
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>

> On 14 Jul 2026, at 14:20, Petr Špaček <[email protected]> wrote:
> 
> I think the fundamental problem is: The registry range is too limited so we need to care.

I disagree Petr. The current registry range is just fine and IMO there's no compelling case so far to extend it. The *last* thing DNSSEC needs is yet more moving parts and complications. YMMV.

Let our great-great-great grandchildren worry about the algorithm registry size - assuming DNSSEC is still a thing two centuries from now. We've burnt through ~20 code points in the ~30 years since DNSSEC started. Some of those code points have been deprecated and others never got any significant deployment. At this rate, there are enough left to keep IANA busy for 200+ years.

I'm not convinced a dedicated code point is needed for test purposes. It's not clear to me why these tests can't make use of the existing code points that have been set aside for private purposes. Or re-cycle the zombie code points that had been allocated to (say) DSA/SHA1 or RSA/MD5. I don't object to assigning a code point for testing. Though I'd like to see a more convincing justification.

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]