[DNSOP] Re: PQ DNSSEC?
Frederico A C Neves <[email protected]> Mon, 20 Jul 2026 08:42:57 -0300
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Jul 20, 2026 at 03:35:03AM -0400, Paul Wouters wrote: > > Bas wrote: > > > > If we care for PQ DNSSEC by 2031, what would be the most practical path? We can't be too ambitious. > > > > > > So what are we looking at? The only practical [1] signature scheme available on this timeframe is ML-DSA-44 with 2,420 byte signatures and 1,322 byte public keys. We can't have authoritatives include these by default: it'll break clients that can't fall back to TCP, or are buggy in other ways. > > This assumes we are stuck with the current transport. The real question > is, should we fix the tranport so we then no longer care about size of > signaures, or should we limit the new PQ crypto based on the current > packet size issues. I feel it might be better to think of a DNS protocol > fragmentation support so that from a DNS protocol point of view, we can > just send huge packets. We have alternative transports, DoQ, and we're working already on a way to signal it for a while with Deleg. The question is will we succeed on time and does DoQ has better prognostics of lower failure rates than Do53 over TCP??? Fred _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]