[DNSOP] Re: PQ DNSSEC?
Mukund Sivaraman <[email protected]> Tue, 21 Jul 2026 04:51:38 +0800
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <al6KWrKIS8QaIR5y@p5> |
Hi Peter On Mon, Jul 20, 2026 at 03:32:40PM +0200, Peter Thomassen wrote: > Hi Mukund, > > On 7/20/26 10:14, Mukund Sivaraman wrote: > > If it's that answer + RRSIG RRsets ought to pass over UDP to a client > > that's not a validating resolver which queries for it and it can't pass > > over UDP, it'll get a response with TC=1 for DO=1 and won't be able to > > query it over UDP. But can this not be considered negligible considering > > the client can't do UDP and it's not going to be validating? RFC 6840 > > allows AD flag signal in the response if the query has AD=1 even if > > DO=0, so a client that can only use UDP and wants just the answer but > > also wants to know if it is authenticated can still get just that signal > > in the AD bit without any of the RRSIGs, and the validation happens on a > > resolver that's capable of TCP. > > That clients don't validate is the current operational reality, but not a DNSSEC design limitation. Clients can get all the info they need to do validation, and things like RFC 7901 can make it easier. > > Just reducing clients' role in DNSSEC (including their future role) to looking at the AD bit is a significant conceptual change to the security model, turning current practical issues into a design limitation -- and that in my view undermines the whole concept. My last response was not to withhold DNSSEC RR types for all clients. It mentioned that a client that's limited to UDP with small datagram sizes can still receive answers with a DNSSEC AD indicator. A client that can use DNS over TCP can receive anything. The point was, can a client that's limited to UDP be considered a negligible case? Mukund _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 1.5 KB)
-----BEGIN PGP SIGNATURE----- iQQzBAABCgAdFiEEqPyXNiYqnt+m+AGHd1TIVyxnymkFAmpeilcACgkQd1TIVyxn ymnsKR//S4AgsgFHihujXlU52Ldqmsoc+rJArf+atKWr3t+tmIG5ydn9+bAa8FLA d6xQfYBTBwCza6onL0TvFeedCjt4EHGAsq/dMFYa5ouP+K+4C0DPLMkM62gQDdn2 KbySwtTPOwvUF2HYXnh61IJQFEbTfMct8ndV9zlPwBn4etA1A2vkpqqUZVwD3PhM x1wWQtuxaumPJ3ipfc5WtMpcn1m28JCyULVg0f8uADlOuQMfi1QyLy1pp3L5PsX2 IKp2KOGNta6ad6qxn0Gd1rkAINuRkkyGmITexTBaudSkzG7ZySXpsGy42wies16g wE5fwYcXeax8wkqqbVijk3BHXGNfebNtcVDSyZYLSnzQrmJOtm62+z5+TogJz7l1 1MnwNBt8mF5ojWnf5v7GjUdgY34AV/9QUQID6MSMkVfgqoAZW07LVa0YWtGiU9JL VQP9W+WPbRcgO1gvES8Lw+ufF6LGUVV9wvqWUCAd/UPidhWtWEE5vYF56rzGZK+f p4JHDpeWZa+4HO8Zm7+DeILTmlgFIcjDeHVfxauupK9AQPro42hp9xQ9HwfsPMPM 0hhT7N2qyUz3aShElvLIWHdwqD0JjrglE/H9GWMhFBRceFkOKTdg3XNzvpadCGkJ rZB9+4oslzlnrKWTdo0S64Lj/JEA/+7OToJWwnR+z+yE/9tJJS3df9/+IeYcG+LB GCPQzrNOVERcf3mXMsSdHATBp/vcFeZZlwIrwJpdsMv9LDt9OxBht1gACQWUvwoQ tpoQwAaMCaCZhGdkhYWYRR3bSBHR2iUWyHVV81Gh5/OlR1sQgt8Rrk68K+osHYAr K/A1dT6NitegjX6yL6IKp2t2BSbP3P9DKIEqx96cuXOTihm8lHEGN+P6DZrkQZ4Q 5TYkWumdYbu0NwmXp2pQbIVRMMhZUS0huZFvqjm3+sCSMQLHB7Sh6T+bT3BCcvdp 94RjQY+HvxY9VUIB2Gq8cWnlITB8dhFYJT7hRTSUBBl9JVw1KyuseybBaOP0cGfi 7XMBvazRMQP6QUVrZ1tyBwI6wWsInGiEeaVKrweItschUj7r7AcrhvHfcx49Wmtb CXhfiXHeLaC6guBcFvjEcctjlBNO6XZkM/PYo18+9fXTf4ANrHXnWNxTk2QPp1kt wpiuH3wvujuPJ262JZBsL31VOyll6ZkSFoD9FFmjYQdwIjMfyGxN8KPEx4IrmyNC q5pTnBy4Jop+wmWnSOPO0RLnYt+aLIE4bJr8QN2YpFdwcVwzOAlquPy7xtCVlHnL 8pGrkeb302TDBbY4Ktq76wbJgGi/CEsHMKTcM56syqlV0U5lHjU766OqIuAeMZi6 TxMhlKDIWd5HXA2RiKiAxbaSZ5/0vw== =S4du -----END PGP SIGNATURE-----