[DNSOP] Re: PQ DNSSEC?
"Wessels, Duane" <[email protected]> Mon, 20 Jul 2026 14:35:41 +0000
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
> On Jul 20, 2026, at 3:47 PM, Warren Kumari <[email protected]> wrote: > > I don't really think it is so much "clients that can't fall back to > TCP..." (although they do exist), it is more "concerns around scale of > clients falling back to TCP". There is some belief that some / many > TLDs and auths will become overloaded if all recursive resolvers fall > back to TCP[0]. TCP is also noticeably slower, even if you do > pipelineing, presistance, etc., etc. When Verisign transitioned from RSA to ECDSA using double-signing, the size of signed NXDOMAIN responses exceeded 1500 bytes. We observed quite a few resolver clients that were unable to fall fall back to TCP. We know this because they very aggressively retried over UDP. Slide 10 of https://indico.dns-oarc.net/event/48/contributions/1036/attachments/1004/1920/challenges-truncation-tcp-combined%20v2.pdf shows some data on an “experiment” we did prior to the algorithm transition. So its not just about more TCP load, but also about more UDP load due to futile retries. Slide 20 of https://indico.dns-oarc.net/event/48/contributions/1043/attachments/1003/1927/wessels-verisign-algrolls.pdf shows that truncation rates were about 3x of TCP rates during the algorithm transition. DW _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]
smime.p7s
(application/pkcs7-signature, 3.9 KB) - not displayed