[DNSOP] Re: PQ DNSSEC?

Joe Abley <[email protected]> Mon, 20 Jul 2026 09:52:11 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
On 20 Jul 2026, at 02:53, Watson Ladd <[email protected]> wrote:

> Since singing is designed to be offline,

Signing may have been designed with off-line machinery in mind, but the prevalence of on-line signers today suggests this is likely not a good line of reasoning...

> We know
> verification doesn't matter given people regularly turn it off rather
> than fail closed when verification is failing.

... and this reinforces that impression. 

People turn off validation when they have a good reason to believe that's the right thing to do. This does not scale beyond TLDs and a handful of high-profile domain names whose operators are reachable and known. End users generally don't know what DNSSEC is and hence don't have much opportunity to make decisions about it.

There was once a concern that ISPs might disable validation once their helpdesk felt the weight of complaints relating to signing problems. But, in practice, the target reliability for an ISP resolver is to fail the same way as the big public resolvers, which is where users tend to go when ISP resolvers fail. The big public resolvers all do validation.


Joe

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]