[DNSOP] Re: Sanity tl;dr for Multi-algorithm DNSSEC Requir ements
Shumon Huque <[email protected]> Mon, 27 Jul 2026 08:41:08 -0400
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CAHPuVdUh4SZN0SYAjXQfdRoKK7SWmxVywpKh4jvqMbztQVCc7g@mail.gmail.com> |
--===============1387850876109049613== Content-Type: multipart/alternative; boundary="000000000000ff1de906579709a3" --000000000000ff1de906579709a3 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Mon, Jul 27, 2026 at 8:16=E2=80=AFAM Bas Westerbaan <[email protected]>= wrote: > > On Mon, Jul 27, 2026 at 2:09=E2=80=AFPM Shumon Huque <[email protected]> w= rote: > >> [...] additional explicit signaling is likely needed for that, and it >> would be a painful slog to get the long tail of validators in the field >> upgraded to implement such an enhancement. >> > > What signalling would be required for the validator to insist on ML-DSA-4= 4 > if it sees a DS for it? > We'd have to come up with a design. Most likely the signal would have to be encoded in the DS RRset (see the various "DS hack" proposals for various things in the past), or in a DNSKEY flag. (If we wait for DELEG, which may be too late, then a purpose built DELEG parameter could be designed). Shumon. --000000000000ff1de906579709a3 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr">On Mon, Jul 27, 2026 at 8:16=E2=80=AFAM B= as Westerbaan <<a href=3D"mailto:[email protected]">[email protected]<= /a>> wrote:</div><div class=3D"gmail_quote gmail_quote_container"><block= quote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1= px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div dir=3D"lt= r"><br></div><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_att= r">On Mon, Jul 27, 2026 at 2:09=E2=80=AFPM Shumon Huque <<a href=3D"mail= to:[email protected]" target=3D"_blank">[email protected]</a>> wrote:<br><= /div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bo= rder-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><di= v dir=3D"ltr"><span style=3D"background-color:transparent">[...] additional= explicit signaling is likely needed for that, and it would be a painful sl= og to get the long tail of validators in the field upgraded to implement su= ch an enhancement.</span></div></div></blockquote><div><br></div><div>What = signalling would be=C2=A0required=C2=A0for the validator to insist on ML-DS= A-44 if it sees a DS for it?</div></div></div></blockquote><div><br></div><= div>We'd have to come up with a design. Most likely the signal would ha= ve to be encoded in the DS RRset (see the various "DS hack" propo= sals for various things in the past), or in a DNSKEY flag. (If we wait for = DELEG,=C2=A0which=C2=A0may be too late, then a purpose built DELEG paramete= r could be designed).</div><div><br></div><div>Shumon.</div><div><br></div>= </div></div> --000000000000ff1de906579709a3-- --===============1387850876109049613== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK --===============1387850876109049613==--