[DNSOP] Re: PQ DNSSEC?
Peter Thomassen <[email protected]> Tue, 21 Jul 2026 15:59:51 +0200
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
Hi Philip, On 7/21/26 15:50, Philip Homburg wrote: > I'm a bit confused by these results. > > I would expect a zone such as ML-DSA-44.example.com and then in that zone > www.ML-DSA-44.example.com IN AAAA 2001:db8::1 > > and a RIPE Atlas measurement asking all proves to resolve > www.ML-DSA-44.example.com/AAAA. > > The atlas probes should not do TCP or set DO because that's not what a > normal stub resolver would do (I'm ignoring systemd-resolver and other proxies) Right. We used the probe's local resolver, and the TCP/UDP and DO choice is the client's (think dig +tcp etc.). If that +tcp switch changes the error rate, then the bottleneck may be between the stub and the resolver, not upstream. So, yes, interpretation is necessary. Best, Peter _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]