[DNSOP] Re: PQ DNSSEC?

Frederico A C Neves <[email protected]> Mon, 20 Jul 2026 08:42:57 -0300
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
On Mon, Jul 20, 2026 at 03:35:03AM -0400, Paul Wouters wrote:
>
> Bas wrote:
>
> > > If we care for PQ DNSSEC by 2031, what would be the most practical path? We can't be too ambitious.
> > >
> > > So what are we looking at? The only practical [1] signature scheme available on this timeframe is ML-DSA-44 with 2,420 byte signatures and 1,322 byte public keys. We can't have authoritatives include these by default: it'll break clients that can't fall back to TCP, or are buggy in other ways.
>
> This assumes we are stuck with the current transport. The real question
> is, should we fix the tranport so we then no longer care about size of
> signaures, or should we limit the new PQ crypto based on the current
> packet size issues. I feel it might be better to think of a DNS protocol
> fragmentation support so that from a DNS protocol point of view, we can
> just send huge packets.

We have alternative transports, DoQ, and we're working already on a
way to signal it for a while with Deleg. The question is will we
succeed on time and does DoQ has better prognostics of lower failure
rates than Do53 over TCP???

Fred

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]