[DNSOP] Re: PQ DNSSEC?

Peter Thomassen <[email protected]> Wed, 22 Jul 2026 15:04:13 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Hi Michael,

(As discussed responding in public.)

On 7/22/26 12:08, Michael Richardson wrote:
>      > On 7/21/26 14:41, Philip Homburg wrote:
>      >> I wonder, is it time that somebody signs a zone with ML-DSA-44 and
>      >> then uses RIPE Atlas to see what breaks?
> 
>      > We (deSEC in collaboration with SandboxAQ) have done this two years ago
>      > when it was still Dilithium2, results at the bottom of our test bed
>      > page at https://pq-dnssec.dedyn.io/.
> 
>      > For Dilithium2, we used algorithm number 18. Our BIND setup has
>      > separate KSK and ZSK keys, and pdns setup uses just one CSK. We found
>      > failure rates between 10% and 40% (slide numbers from [1]):
> 
>      > Query for an existing record: - Slide 6: BIND auth, UDP failure rate
>      > 29-33%, TCP failure rate 21-22% - Slide 7: pdns auth, UDP failure rate
>      > 10-11%, TCP failure rate ~7%
> 
> RIPE Atlas has TCP stack, so the failures must have been port-53 blocked, right?
> 
> Any idea how/why?

I don't think so. We pre-selected only probes where the same query worked with RSA (algorithm 8) -- so, these probes worked with RSA over TCP with/without DO bit etc. That doesn't seem compatible with blocking port 53/TCP.

We decided to not go into speculation too much, first because interpretation is difficult, and second because RIPE Atlas is very noisy. Look, for example, on slide 12/13 which shows (again pre-filtered for RSA support) the percentage of responses that had the AD bit set for NXDOMAIN queries.

You can see that for Falcon via UDP with DO bit set, that rate is about 8% -- which impossibly can be actually authenticated data (we used a proprietary implementation that we don't expect any resolver to support, except for our testbed one.) In other words, all of the numbers are in accurate on the order of at least 10%-points.

So, this rather emphasizes that further research is needed, but we can't conclude much otherwise.

Best,
Peter

-- 
Like our community service? 💛
Please consider donating at

https://desec.io/

deSEC e.V.
Möckernstraße 74
10965 Berlin
Germany

Vorstandsvorsitz: Nils Wisiol
Registergericht: AG Berlin (Charlottenburg) VR 37525

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]