[DNSOP] Re: PQ DNSSEC?

Warren Kumari <[email protected]> Mon, 20 Jul 2026 15:47:46 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <CAHw9_iJ1HM_59jiTv7qSuMmWXFhqz7JX+rkLTB_zcm5xoJdexQ@mail.gmail.com>
On Mon, Jul 20, 2026 at 2:13 PM Shumon Huque <[email protected]> wrote:
>
> On Sun, Jul 19, 2026 at 1:16 PM Bas Westerbaan <[email protected]> wrote:
>>
>>  We can't have authoritatives include these by default: it'll break clients that can't fall back to TCP, ...
>
>
> Does anyone have any current measurements about how prevalent these deficient DNS clients are?
>
> Maybe it's now time to consider breaking them (or at least not designing protocol enhancements around bugs) and have natural selection take care of the problem.

I don't really think it is so much "clients that can't fall back to
TCP..." (although they do exist), it is more "concerns around scale of
clients falling back to TCP". There is some belief that some / many
TLDs and auths will become overloaded if all recursive resolvers fall
back to TCP[0]. TCP is also noticeably slower, even if you do
pipelineing, presistance, etc., etc.

W
[0]: One could make the argument that if you run a TLD you are getting
paid to answer queries, and so if the # of queries increase, well, you
should scale up... but I'm just reporting what people have said.

>
> Shumon.
>
> _______________________________________________
> DNSOP mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]