[DNSOP] Re: Sanity tl;dr for Multi-algorithm DNSSEC Requir ements
Bas Westerbaan <[email protected]> Mon, 27 Jul 2026 16:11:59 +0200
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CAMjbhoXwEquAeX6nLiR62YfcH6yz0JehGHc2WuiQvHa=beMskA@mail.gmail.com> |
--===============5392605551646193096== Content-Type: multipart/alternative; boundary="000000000000eaa21c0657984e35" --000000000000eaa21c0657984e35 Content-Type: text/plain; charset="UTF-8" > I think there is still an assumption in the DNSSEC specs that local > validator policy always wins. I sense your suggestion is along those lines. > It's not about policy, but about keeping things simpler. Fundamentally the security of any authentication does not depend on how strong the proof of the legitimate authenticatee is, but rather what the weakest proof is that the verifier is willing to accept. [1] Best, Bas [1] Sounds obvious, but it's a common misconception that only having PQ TLS certificates installed on your web server makes it PQ secure. Instead it's about what the TLS client is willing to accept. --000000000000eaa21c0657984e35 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><div class=3D"gmail_quote gmail= _quote_container"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px= 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div di= r=3D"ltr"><div class=3D"gmail_quote"><div><span style=3D"background-color:t= ransparent">I think there is still an assumption in the DNSSEC specs that l= ocal validator policy always wins. I sense your suggestion is along those l= ines.</span></div></div></div></blockquote><div><br></div><div>It's not= about policy, but about keeping things simpler. Fundamentally the security= of any authentication does not depend on how strong the proof of the legit= imate authenticatee is, but rather what the weakest proof is that the verif= ier is willing to accept. [1]</div><div><br></div><div>Best,</div><div><br>= </div><div>=C2=A0Bas</div><div><br></div><div><br></div><div>[1] Sounds obv= ious, but it's a common misconception that only having PQ TLS certifica= tes installed on your web server makes it PQ secure. Instead it's about= what the TLS client is willing to accept.</div><div><br></div></div></div> --000000000000eaa21c0657984e35-- --===============5392605551646193096== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK --===============5392605551646193096==--