[DNSOP] Re: Call for adoption: draft-huque-dnsop-multi-alg -rules-08 (Ends 2026-08-31)
Christian Elmerot <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CAMcE8dzxEGHHS19sznMBCoiUDBzsub9PCn_pFHMko3cw5e5ZQw@mail.gmail.com> |
On Fri, Aug 14, 2026 at 10:17 AM Philip Homburg <[email protected]> wrote: > > This message starts a > > dnsop WG Call for Adoption of: draft-huque-dnsop-multi-alg-rules-08 > > > > This Working Group Call for Adoption ends on 2026-08-31 > > > > Abstract: > > This document restates the requirements on DNSSEC signing and > > validation and makes small adjustments in order to allow for > > more flexible handling of configurations that advertise multiple > > Secure Entry Points (SEP) with different signing algorithms via > > their DS record or trust anchor set. The adjusted rules allow > > both for multi- signer operation and for the transfer of signed > > DNS zones between providers, where the providers support disjoint > > DNSSEC algorithm sets. In addition, the proposal enables > > pre-publication of a trust anchor in preparation for an algorithm > > rollover, such as of the root zone. > > > > This document updates RFCs 4035 and 6840. > > > > Please reply to this message and indicate whether or not you support > > adoption of this Internet-Draft by the dnsop WG. Comments to explain > > your preference are greatly appreciated. Please reply to all > > recipients of this message and include this message in your response. > > I support adoption. As the abstract outlines, this is important to simplify > DNSSEC operation in quite a few cases. > > An issue that may need to be addressed is the desire to strictly prefer > PQC algorithms over traditional ones. That may conflict with the concepts > used in this draft. It would be nice to deal with that in this draft > though it could be addressed later when we create standards for PQC. > I support adoption, not only as an author but primarily because I've had to work through some operational hoops in order to deal with the current status of multi-algorithm setups. PQ DNSSEC deployments need to be discussed further as part of this process but I also agree that resolving PQC downgrade attacks can be postponed. / Christian _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]