[DNSOP] Re: PQ DNSSEC?
Tommy Jensen <[email protected]> Mon, 20 Jul 2026 16:42:53 +0200
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CABDV=UO=Jr9fPQ36-MShKw97AmP5AqTJxEwnPt89bPDR7iHmZw@mail.gmail.com> |
(no hats) FYI there was previous discussion on the topic of not using UDP 53 after someone wrote an controversial draft about saying future documents need not accommodate its use. Similar points were raised there as well. Draft: https://datatracker.ietf.org/doc/draft-tojens-dnsop-do-not-accommodate-udp53/ Mailing list discussion: https://mailarchive.ietf.org/arch/search/?q=%22draft-tojens-dnsop-do-not-accommodate-udp53%22 On Mon, Jul 20, 2026 at 4:36 PM Wessels, Duane <dwessels= [email protected]> wrote: > > > > On Jul 20, 2026, at 3:47 PM, Warren Kumari <[email protected]> wrote: > > > > I don't really think it is so much "clients that can't fall back to > > TCP..." (although they do exist), it is more "concerns around scale of > > clients falling back to TCP". There is some belief that some / many > > TLDs and auths will become overloaded if all recursive resolvers fall > > back to TCP[0]. TCP is also noticeably slower, even if you do > > pipelineing, presistance, etc., etc. > > When Verisign transitioned from RSA to ECDSA using double-signing, > the size of signed NXDOMAIN responses exceeded 1500 bytes. We observed > quite > a few resolver clients that were unable to fall fall back to TCP. We know > this because they very aggressively retried over UDP. > > Slide 10 of > https://indico.dns-oarc.net/event/48/contributions/1036/attachments/1004/1920/challenges-truncation-tcp-combined%20v2.pdf > shows some data on an “experiment” we did prior to the algorithm > transition. > > So its not just about more TCP load, but also about more UDP load > due to futile retries. > > Slide 20 of > https://indico.dns-oarc.net/event/48/contributions/1043/attachments/1003/1927/wessels-verisign-algrolls.pdf > shows that truncation rates were about 3x of TCP rates during the algorithm > transition. > > DW > > > _______________________________________________ > DNSOP mailing list -- [email protected] > To unsubscribe send an email to [email protected] > _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]