[DNSOP] Re: PQ DNSSEC?

Peter Thomassen <[email protected]> Mon, 20 Jul 2026 15:32:40 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Hi Mukund,

On 7/20/26 10:14, Mukund Sivaraman wrote:
> If it's that answer + RRSIG RRsets ought to pass over UDP to a client
> that's not a validating resolver which queries for it and it can't pass
> over UDP, it'll get a response with TC=1 for DO=1 and won't be able to
> query it over UDP. But can this not be considered negligible considering
> the client can't do UDP and it's not going to be validating? RFC 6840
> allows AD flag signal in the response if the query has AD=1 even if
> DO=0, so a client that can only use UDP and wants just the answer but
> also wants to know if it is authenticated can still get just that signal
> in the AD bit without any of the RRSIGs, and the validation happens on a
> resolver that's capable of TCP.

That clients don't validate is the current operational reality, but not a DNSSEC design limitation. Clients can get all the info they need to do validation, and things like RFC 7901 can make it easier.

Just reducing clients' role in DNSSEC (including their future role) to looking at the AD bit is a significant conceptual change to the security model, turning current practical issues into a design limitation -- and that in my view undermines the whole concept.

We should not "solve" the problem using this paradigm shift as a starting point.

Best,
Peter

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]