[DNSOP] Re: PQ DNSSEC?
Shumon Huque <[email protected]> Sun, 19 Jul 2026 09:03:30 -0400
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CAHPuVdUQGcrMz74SD=oSUaC6mxP+3SshrkpAvtMNHngTO-+yGg@mail.gmail.com> |
On Sun, Jul 19, 2026 at 1:16 PM Bas Westerbaan <bas= [email protected]> wrote: > Hey all, > > With various new regulatory timelines for valuable systems to be PQ by > 2031, we're getting questions what we're looking at with DNSSEC. Looking > from afar (and please forgive me my ignorance) it doesn't look good. There's a > lot of academic investigation and experimentation (great), IETF > side-meetings, but no thrust or plans to any deployment; no adopted drafts > or BoFs. > I agree that it's probably time to get PQ DNSSEC work officially into an IETF working group's charter. If we care for PQ DNSSEC by 2031, what would be the most practical path? We > can't be too ambitious. > > So what are we looking at? The only practical [1] signature scheme > available on this timeframe is ML-DSA-44 with 2,420 byte signatures and > 1,322 byte public keys. We can't have authoritatives include these by > default: it'll break clients that can't fall back to TCP, or are buggy in > other ways. > > Instead I suppose we have the client signal if it supports ML-DSA-44 [2], > and only in that case return those large RRSIGs. This allows for gradual > demployment, and only impacts those that care for PQ DNSSEC. While we wait > for the root to sign with ML-DSA-44, resolver can anchor on TLDs ML-DSA-44 > keys. > Selectively returning PQC signatures was in fact one of the use cases envisioned by that draft. It could be revived if there is renewed interest. (Link: https://datatracker.ietf.org/doc/html/draft-huque-dnssec-alg-nego-03 ) Shumon. _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]