[DNSOP] Re: PQ DNSSEC?

Havard Eidnes <[email protected]> Mon, 20 Jul 2026 16:14:13 +0200 (CEST)
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
>>  We can't have authoritatives include these by default: it'll break
>> clients that can't fall back to TCP, or are buggy in other ways.
>
> I vote against complicating the protocol with thoughts about
> TCP-unable clients or buggy in other ways. Let's finally throw
> them overboard.

I tend to agree.  We already have two published "proposed standard"
RFCs (5966 from 2010, 7766 from 2016), which effectively change the
requirement from "SHOULD" to "MUST" for "support TCP as transport for
DNS".

While I'm generally for preserving backwards compatibility, it should
have its reasonable limits, and 16 and 10 years is IMHO pushing it
beyond what could be characterized as reasonable.  It becomes a
question of how much leeway we should give to implementations or
deployments which have chosen to ignore this requirement.

Regards,

- Håvard

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]