[DNSOP] Re: PQ DNSSEC?
Philip Homburg <[email protected]> Tue, 21 Jul 2026 15:50:33 +0200
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
> For Dilithium2, we used algorithm number 18. Our BIND setup has > separate KSK and ZSK keys, and pdns setup uses just one CSK. We > found failure rates between 10% and 40% (slide numbers from [1]): > > Query for an existing record: - Slide 6: BIND auth, UDP failure > rate 29-33%, TCP failure rate 21-22% - Slide 7: pdns auth, UDP > failure rate 10-11%, TCP failure rate ~7% I'm a bit confused by these results. I would expect a zone such as ML-DSA-44.example.com and then in that zone www.ML-DSA-44.example.com IN AAAA 2001:db8::1 and a RIPE Atlas measurement asking all proves to resolve www.ML-DSA-44.example.com/AAAA. The atlas probes should not do TCP or set DO because that's not what a normal stub resolver would do (I'm ignoring systemd-resolver and other proxies) >From the graphs it is not clear to me which one corresponds to this measurement. _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]