[DNSOP] Re: Local validation policy to require valid PQ path where available

Carlos Horowicz <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Joe

do you imagine that implementations would eventually expose this local 
policy via directives like

pqc-validation-policy normal; # accept any valid signature

and

pqc-validation-policy require-if-present; #require PQC signature to 
validate without fallback to e.g. ECDSA

?

-Carlos

On 14/08/2026 11:03, Joe Abley wrote:
> On 14 Aug 2026, at 10:17, Philip Homburg <[email protected]> 
> wrote:
>
>> An issue that may need to be addressed is the desire to strictly prefer
>> PQC algorithms over traditional ones. That may conflict with the concepts
>> used in this draft. It would be nice to deal with that in this draft
>> though it could be addressed later when we create standards for PQC.
>
> This seems like a reasonable moment to mention that I wrote up 
> something about this the other day.
>
> Changing the fundamental architecture for algorithm agility in DNSSEC 
> from "any valid path is acceptable" to "some valid paths are mandatory 
> and some are optional" depending on algorithms seems controversial. 
> Which is not to say that I am suggesting it shouldn't happen. I think 
> change will be necessary but I think it will be complicated to find 
> consensus.
>
> In the mean time, early implementers can use the remaining local 
> policy provision to gain operational experience. This draft describes 
> such a policy and includes guidance for how to communicate the local 
> policy to those affected by it.
>
> Perhaps this approach would give us some more breathing room to be 
> able to make more informed changes in the future.
>
> https://datatracker.ietf.org/doc/draft-jabley-dnsop-local-signing-algorithm-policy/
>
>
> Joe
>
>
> _______________________________________________
> DNSOP mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.