[DNSOP] Re: Local validation policy to require valid PQ path where available
Carlos Horowicz <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
Joe do you imagine that implementations would eventually expose this local policy via directives like pqc-validation-policy normal; # accept any valid signature and pqc-validation-policy require-if-present; #require PQC signature to validate without fallback to e.g. ECDSA ? -Carlos On 14/08/2026 11:03, Joe Abley wrote: > On 14 Aug 2026, at 10:17, Philip Homburg <[email protected]> > wrote: > >> An issue that may need to be addressed is the desire to strictly prefer >> PQC algorithms over traditional ones. That may conflict with the concepts >> used in this draft. It would be nice to deal with that in this draft >> though it could be addressed later when we create standards for PQC. > > This seems like a reasonable moment to mention that I wrote up > something about this the other day. > > Changing the fundamental architecture for algorithm agility in DNSSEC > from "any valid path is acceptable" to "some valid paths are mandatory > and some are optional" depending on algorithms seems controversial. > Which is not to say that I am suggesting it shouldn't happen. I think > change will be necessary but I think it will be complicated to find > consensus. > > In the mean time, early implementers can use the remaining local > policy provision to gain operational experience. This draft describes > such a policy and includes guidance for how to communicate the local > policy to those affected by it. > > Perhaps this approach would give us some more breathing room to be > able to make more informed changes in the future. > > https://datatracker.ietf.org/doc/draft-jabley-dnsop-local-signing-algorithm-policy/ > > > Joe > > > _______________________________________________ > DNSOP mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]