[DNSOP] Re: PQ DNSSEC?

Philip Homburg <[email protected]> Tue, 21 Jul 2026 15:50:33 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
> For Dilithium2, we used algorithm number 18. Our BIND setup has
> separate KSK and ZSK keys, and pdns setup uses just one CSK. We
> found failure rates between 10% and 40% (slide numbers from [1]):
> 
> Query for an existing record:  - Slide 6: BIND auth, UDP failure
> rate 29-33%, TCP failure rate 21-22% - Slide 7: pdns auth, UDP
> failure rate 10-11%, TCP failure rate ~7%

I'm a bit confused by these results. 

I would expect a zone such as ML-DSA-44.example.com and then in that zone
www.ML-DSA-44.example.com IN AAAA 2001:db8::1

and a RIPE Atlas measurement asking all proves to resolve
www.ML-DSA-44.example.com/AAAA.

The atlas probes should not do TCP or set DO because that's not what a
normal stub resolver would do (I'm ignoring systemd-resolver and other proxies)

>From the graphs it is not clear to me which one corresponds to this
measurement.


_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]