[DNSOP] Re: PQ DNSSEC downgrade protection (Was: Sanity tl;dr for Multi-algorithm DNSSEC Requirements)

Vladimír Čunát <[email protected]> Mon, 27 Jul 2026 12:35:50 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============8551295715137255881==
Content-Type: multipart/alternative;
 boundary="------------O5GCrYgnDPnnABUEsKdebfnd"
Content-Language: cs, en-US

This is a multi-part message in MIME format.
--------------O5GCrYgnDPnnABUEsKdebfnd
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit

On 27/07/2026 12.12, Bas Westerbaan wrote:
> the MUST accept any path is a problem

We already have a similar precedent for SHA1 in DS:
https://datatracker.ietf.org/doc/html/rfc4509#section-3

--------------O5GCrYgnDPnnABUEsKdebfnd
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">On 27/07/2026 12.12, Bas Westerbaan
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAMjbhoUiqDvLOaH9eZQAvHwDL0Lfh8M-vJwBprAe=b1CLXA-Eg@mail.gmail.com">the
      MUST accept any path is a problem</blockquote>
    <p>We already have a similar precedent for SHA1 in DS:<br>
      <a class="moz-txt-link-freetext" href="https://datatracker.ietf.org/doc/html/rfc4509#section-3">https://datatracker.ietf.org/doc/html/rfc4509#section-3</a></p>
  </body>
</html>

--------------O5GCrYgnDPnnABUEsKdebfnd--


--===============8551295715137255881==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp
bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg
dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK

--===============8551295715137255881==--