[DNSOP] Local validation policy to require valid PQ path where available (was: Re: Call for adoption: draft-huque-dnsop -multi-alg-rules-08)

Joe Abley <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
On 14 Aug 2026, at 10:17, Philip Homburg <[email protected]> wrote:

> An issue that may need to be addressed is the desire to strictly prefer
> PQC algorithms over traditional ones. That may conflict with the concepts
> used in this draft. It would be nice to deal with that in this draft
> though it could be addressed later when we create standards for PQC.

This seems like a reasonable moment to mention that I wrote up something about this the other day. 

Changing the fundamental architecture for algorithm agility in DNSSEC from "any valid path is acceptable" to "some valid paths are mandatory and some are optional" depending on algorithms seems controversial. Which is not to say that I am suggesting it shouldn't happen. I think change will be necessary but I think it will be complicated to find consensus. 

In the mean time, early implementers can use the remaining local policy provision to gain operational experience. This draft describes such a policy and includes guidance for how to communicate the local policy to those affected by it. 

Perhaps this approach would give us some more breathing room to be able to make more informed changes in the future. 

https://datatracker.ietf.org/doc/draft-jabley-dnsop-local-signing-algorithm-policy/


Joe

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.