[DNSOP] Re: Call for adoption: draft-huque-dnsop-multi-alg -rules-08 (Ends 2026-08-31)

Shumon Huque <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <CAHPuVdUObJkb+K-zOOj-Yhu7OYzFKf0C-O4qUYRY0aOT+E7K8A@mail.gmail.com>
On Thu, Aug 13, 2026 at 9:45 AM Benno Overeinder via Datatracker <
[email protected]> wrote:

> This message starts a dnsop WG Call for Adoption of:
> draft-huque-dnsop-multi-alg-rules-08
>
> This Working Group Call for Adoption ends on 2026-08-31
>
> Abstract:
>    This document restates the requirements on DNSSEC signing and
>    validation and makes small adjustments in order to allow for more
>    flexible handling of configurations that advertise multiple Secure
>    Entry Points (SEP) with different signing algorithms via their DS
>    record or trust anchor set.  The adjusted rules allow both for multi-
>    signer operation and for the transfer of signed DNS zones between
>    providers, where the providers support disjoint DNSSEC algorithm
>    sets.  In addition, the proposal enables pre-publication of a trust
>    anchor in preparation for an algorithm rollover, such as of the root
>    zone.
>
>    This document updates RFCs 4035 and 6840.
>
> Please reply to this message and indicate whether or not you support
> adoption
> of this Internet-Draft by the dnsop WG. Comments to explain your preference
> are greatly appreciated. Please reply to all recipients of this message and
> include this message in your response.
>

As an author of this draft, obviously I support adoption, but I want to
take this opportunity to make a few general remarks ..

I realize that Mark Andrews is strongly opposed to this draft. But the
sense of the authors is that there is a wide group of people that agree
that the use cases cited are valid (multi-signer and provider transfer
across disjoint algorithms, pre-publication of trust anchors for algorithm
roll, deploying disjoint KSK/ZSK algorithms, selectively returning
signatures of a specific algorithm, gracefully dealing with mainstream
algorithm disablement, etc.), and I hope the working group on balance will
agree.

Note that most of the workings of this draft can already be implemented in
the field today with custom signer software, and existing validator rules.
This draft tries to formalize how to do this safely, and updates the
protocol rules accordingly.

I am also fairly certain that additional tweaks to the DNSSEC
multi-algorithm rules will be needed, likely in follow-on drafts. For
example, algorithm downgrade protection & selective signature delivery for
PQC vs classical - a discussion that has already started, and folks are
thinking about (but we should tackle that separately).

Shumon.

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.