[DNSOP] Re: Call for adoption: draft-huque-dnsop-multi-alg -rules-08 (Ends 2026-08-31)
Shumon Huque <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CAHPuVdUObJkb+K-zOOj-Yhu7OYzFKf0C-O4qUYRY0aOT+E7K8A@mail.gmail.com> |
On Thu, Aug 13, 2026 at 9:45 AM Benno Overeinder via Datatracker < [email protected]> wrote: > This message starts a dnsop WG Call for Adoption of: > draft-huque-dnsop-multi-alg-rules-08 > > This Working Group Call for Adoption ends on 2026-08-31 > > Abstract: > This document restates the requirements on DNSSEC signing and > validation and makes small adjustments in order to allow for more > flexible handling of configurations that advertise multiple Secure > Entry Points (SEP) with different signing algorithms via their DS > record or trust anchor set. The adjusted rules allow both for multi- > signer operation and for the transfer of signed DNS zones between > providers, where the providers support disjoint DNSSEC algorithm > sets. In addition, the proposal enables pre-publication of a trust > anchor in preparation for an algorithm rollover, such as of the root > zone. > > This document updates RFCs 4035 and 6840. > > Please reply to this message and indicate whether or not you support > adoption > of this Internet-Draft by the dnsop WG. Comments to explain your preference > are greatly appreciated. Please reply to all recipients of this message and > include this message in your response. > As an author of this draft, obviously I support adoption, but I want to take this opportunity to make a few general remarks .. I realize that Mark Andrews is strongly opposed to this draft. But the sense of the authors is that there is a wide group of people that agree that the use cases cited are valid (multi-signer and provider transfer across disjoint algorithms, pre-publication of trust anchors for algorithm roll, deploying disjoint KSK/ZSK algorithms, selectively returning signatures of a specific algorithm, gracefully dealing with mainstream algorithm disablement, etc.), and I hope the working group on balance will agree. Note that most of the workings of this draft can already be implemented in the field today with custom signer software, and existing validator rules. This draft tries to formalize how to do this safely, and updates the protocol rules accordingly. I am also fairly certain that additional tweaks to the DNSSEC multi-algorithm rules will be needed, likely in follow-on drafts. For example, algorithm downgrade protection & selective signature delivery for PQC vs classical - a discussion that has already started, and folks are thinking about (but we should tackle that separately). Shumon. _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]