[DNSOP] Re: PQ DNSSEC?

Mukund Sivaraman <[email protected]> Tue, 21 Jul 2026 04:51:38 +0800
Newsgroups gmane.ietf.dnsop
Message-ID <al6KWrKIS8QaIR5y@p5>
Hi Peter

On Mon, Jul 20, 2026 at 03:32:40PM +0200, Peter Thomassen wrote:
> Hi Mukund,
> 
> On 7/20/26 10:14, Mukund Sivaraman wrote:
> > If it's that answer + RRSIG RRsets ought to pass over UDP to a client
> > that's not a validating resolver which queries for it and it can't pass
> > over UDP, it'll get a response with TC=1 for DO=1 and won't be able to
> > query it over UDP. But can this not be considered negligible considering
> > the client can't do UDP and it's not going to be validating? RFC 6840
> > allows AD flag signal in the response if the query has AD=1 even if
> > DO=0, so a client that can only use UDP and wants just the answer but
> > also wants to know if it is authenticated can still get just that signal
> > in the AD bit without any of the RRSIGs, and the validation happens on a
> > resolver that's capable of TCP.
> 
> That clients don't validate is the current operational reality, but not a DNSSEC design limitation. Clients can get all the info they need to do validation, and things like RFC 7901 can make it easier.
> 
> Just reducing clients' role in DNSSEC (including their future role) to looking at the AD bit is a significant conceptual change to the security model, turning current practical issues into a design limitation -- and that in my view undermines the whole concept.

My last response was not to withhold DNSSEC RR types for all clients. It
mentioned that a client that's limited to UDP with small datagram sizes
can still receive answers with a DNSSEC AD indicator. A client that can
use DNS over TCP can receive anything. The point was, can a client
that's limited to UDP be considered a negligible case?

		Mukund

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 1.5 KB)
-----BEGIN PGP SIGNATURE-----

iQQzBAABCgAdFiEEqPyXNiYqnt+m+AGHd1TIVyxnymkFAmpeilcACgkQd1TIVyxn
ymnsKR//S4AgsgFHihujXlU52Ldqmsoc+rJArf+atKWr3t+tmIG5ydn9+bAa8FLA
d6xQfYBTBwCza6onL0TvFeedCjt4EHGAsq/dMFYa5ouP+K+4C0DPLMkM62gQDdn2
KbySwtTPOwvUF2HYXnh61IJQFEbTfMct8ndV9zlPwBn4etA1A2vkpqqUZVwD3PhM
x1wWQtuxaumPJ3ipfc5WtMpcn1m28JCyULVg0f8uADlOuQMfi1QyLy1pp3L5PsX2
IKp2KOGNta6ad6qxn0Gd1rkAINuRkkyGmITexTBaudSkzG7ZySXpsGy42wies16g
wE5fwYcXeax8wkqqbVijk3BHXGNfebNtcVDSyZYLSnzQrmJOtm62+z5+TogJz7l1
1MnwNBt8mF5ojWnf5v7GjUdgY34AV/9QUQID6MSMkVfgqoAZW07LVa0YWtGiU9JL
VQP9W+WPbRcgO1gvES8Lw+ufF6LGUVV9wvqWUCAd/UPidhWtWEE5vYF56rzGZK+f
p4JHDpeWZa+4HO8Zm7+DeILTmlgFIcjDeHVfxauupK9AQPro42hp9xQ9HwfsPMPM
0hhT7N2qyUz3aShElvLIWHdwqD0JjrglE/H9GWMhFBRceFkOKTdg3XNzvpadCGkJ
rZB9+4oslzlnrKWTdo0S64Lj/JEA/+7OToJWwnR+z+yE/9tJJS3df9/+IeYcG+LB
GCPQzrNOVERcf3mXMsSdHATBp/vcFeZZlwIrwJpdsMv9LDt9OxBht1gACQWUvwoQ
tpoQwAaMCaCZhGdkhYWYRR3bSBHR2iUWyHVV81Gh5/OlR1sQgt8Rrk68K+osHYAr
K/A1dT6NitegjX6yL6IKp2t2BSbP3P9DKIEqx96cuXOTihm8lHEGN+P6DZrkQZ4Q
5TYkWumdYbu0NwmXp2pQbIVRMMhZUS0huZFvqjm3+sCSMQLHB7Sh6T+bT3BCcvdp
94RjQY+HvxY9VUIB2Gq8cWnlITB8dhFYJT7hRTSUBBl9JVw1KyuseybBaOP0cGfi
7XMBvazRMQP6QUVrZ1tyBwI6wWsInGiEeaVKrweItschUj7r7AcrhvHfcx49Wmtb
CXhfiXHeLaC6guBcFvjEcctjlBNO6XZkM/PYo18+9fXTf4ANrHXnWNxTk2QPp1kt
wpiuH3wvujuPJ262JZBsL31VOyll6ZkSFoD9FFmjYQdwIjMfyGxN8KPEx4IrmyNC
q5pTnBy4Jop+wmWnSOPO0RLnYt+aLIE4bJr8QN2YpFdwcVwzOAlquPy7xtCVlHnL
8pGrkeb302TDBbY4Ktq76wbJgGi/CEsHMKTcM56syqlV0U5lHjU766OqIuAeMZi6
TxMhlKDIWd5HXA2RiKiAxbaSZ5/0vw==
=S4du
-----END PGP SIGNATURE-----