[DNSOP] Re: Sanity tl;dr for Multi-algorithm DNSSEC Requir ements

Bas Westerbaan <[email protected]> Mon, 27 Jul 2026 16:11:59 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <CAMjbhoXwEquAeX6nLiR62YfcH6yz0JehGHc2WuiQvHa=beMskA@mail.gmail.com>
--===============5392605551646193096==
Content-Type: multipart/alternative; boundary="000000000000eaa21c0657984e35"

--000000000000eaa21c0657984e35
Content-Type: text/plain; charset="UTF-8"

> I think there is still an assumption in the DNSSEC specs that local
> validator policy always wins. I sense your suggestion is along those lines.
>

It's not about policy, but about keeping things simpler. Fundamentally the
security of any authentication does not depend on how strong the proof of
the legitimate authenticatee is, but rather what the weakest proof is that
the verifier is willing to accept. [1]

Best,

 Bas


[1] Sounds obvious, but it's a common misconception that only having PQ TLS
certificates installed on your web server makes it PQ secure. Instead it's
about what the TLS client is willing to accept.

--000000000000eaa21c0657984e35
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><div class=3D"gmail_quote gmail=
_quote_container"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px=
 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div di=
r=3D"ltr"><div class=3D"gmail_quote"><div><span style=3D"background-color:t=
ransparent">I think there is still an assumption in the DNSSEC specs that l=
ocal validator policy always wins. I sense your suggestion is along those l=
ines.</span></div></div></div></blockquote><div><br></div><div>It&#39;s not=
 about policy, but about keeping things simpler. Fundamentally the security=
 of any authentication does not depend on how strong the proof of the legit=
imate authenticatee is, but rather what the weakest proof is that the verif=
ier is willing to accept. [1]</div><div><br></div><div>Best,</div><div><br>=
</div><div>=C2=A0Bas</div><div><br></div><div><br></div><div>[1] Sounds obv=
ious, but it&#39;s a common misconception that only having PQ TLS certifica=
tes installed on your web server makes it PQ secure. Instead it&#39;s about=
 what the TLS client is willing to accept.</div><div><br></div></div></div>

--000000000000eaa21c0657984e35--


--===============5392605551646193096==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp
bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg
dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK

--===============5392605551646193096==--