[DNSOP] Re: PQ DNSSEC?

Peter Thomassen <[email protected]> Tue, 21 Jul 2026 15:59:51 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Hi Philip,

On 7/21/26 15:50, Philip Homburg wrote:
> I'm a bit confused by these results.
> 
> I would expect a zone such as ML-DSA-44.example.com and then in that zone
> www.ML-DSA-44.example.com IN AAAA 2001:db8::1
> 
> and a RIPE Atlas measurement asking all proves to resolve
> www.ML-DSA-44.example.com/AAAA.
> 
> The atlas probes should not do TCP or set DO because that's not what a
> normal stub resolver would do (I'm ignoring systemd-resolver and other proxies)
Right. We used the probe's local resolver, and the TCP/UDP and DO choice is the client's (think dig +tcp etc.).

If that +tcp switch changes the error rate, then the bottleneck may be between the stub and the resolver, not upstream. So, yes, interpretation is necessary.

Best,
Peter

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]