[DNSOP] Re: Sanity tl;dr for Multi-algorithm DNSSEC Requir ements

Shumon Huque <[email protected]> Mon, 27 Jul 2026 08:41:08 -0400
Newsgroups gmane.ietf.dnsop
Message-ID <CAHPuVdUh4SZN0SYAjXQfdRoKK7SWmxVywpKh4jvqMbztQVCc7g@mail.gmail.com>
--===============1387850876109049613==
Content-Type: multipart/alternative; boundary="000000000000ff1de906579709a3"

--000000000000ff1de906579709a3
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Mon, Jul 27, 2026 at 8:16=E2=80=AFAM Bas Westerbaan <[email protected]>=
 wrote:

>
> On Mon, Jul 27, 2026 at 2:09=E2=80=AFPM Shumon Huque <[email protected]> w=
rote:
>
>> [...] additional explicit signaling is likely needed for that, and it
>> would be a painful slog to get the long tail of validators in the field
>> upgraded to implement such an enhancement.
>>
>
> What signalling would be required for the validator to insist on ML-DSA-4=
4
> if it sees a DS for it?
>

We'd have to come up with a design. Most likely the signal would have to be
encoded in the DS RRset (see the various "DS hack" proposals for various
things in the past), or in a DNSKEY flag. (If we wait for DELEG, which may
be too late, then a purpose built DELEG parameter could be designed).

Shumon.

--000000000000ff1de906579709a3
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr">On Mon, Jul 27, 2026 at 8:16=E2=80=AFAM B=
as Westerbaan &lt;<a href=3D"mailto:[email protected]">[email protected]<=
/a>&gt; wrote:</div><div class=3D"gmail_quote gmail_quote_container"><block=
quote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1=
px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div dir=3D"lt=
r"><br></div><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_att=
r">On Mon, Jul 27, 2026 at 2:09=E2=80=AFPM Shumon Huque &lt;<a href=3D"mail=
to:[email protected]" target=3D"_blank">[email protected]</a>&gt; wrote:<br><=
/div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bo=
rder-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><di=
v dir=3D"ltr"><span style=3D"background-color:transparent">[...] additional=
 explicit signaling is likely needed for that, and it would be a painful sl=
og to get the long tail of validators in the field upgraded to implement su=
ch an enhancement.</span></div></div></blockquote><div><br></div><div>What =
signalling would be=C2=A0required=C2=A0for the validator to insist on ML-DS=
A-44 if it sees a DS for it?</div></div></div></blockquote><div><br></div><=
div>We&#39;d have to come up with a design. Most likely the signal would ha=
ve to be encoded in the DS RRset (see the various &quot;DS hack&quot; propo=
sals for various things in the past), or in a DNSKEY flag. (If we wait for =
DELEG,=C2=A0which=C2=A0may be too late, then a purpose built DELEG paramete=
r could be designed).</div><div><br></div><div>Shumon.</div><div><br></div>=
</div></div>

--000000000000ff1de906579709a3--


--===============1387850876109049613==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp
bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg
dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK

--===============1387850876109049613==--