[DNSOP] Re: Local validation policy to require valid PQ path where available
Joe Abley <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
Hi Carlos, On 14 Aug 2026, at 16:21, Carlos Horowicz <[email protected]> wrote: > do you imagine that implementations would eventually expose this local policy via directives like > > pqc-validation-policy normal; # accept any valid signature > > and > > pqc-validation-policy require-if-present; #require PQC signature to validate without fallback to e.g. ECDSA > > ? The idea is that resolver operators could use the filtering transparency mechanism to describe whatever policy they thought was worth communicating. The example keys in the document are just that, examples. Browsers or other clients that understand the filtering transparency mechanism could use it to communicate the policy so that (e.g., again) if something is blocked unexpectedly the user has a clue about what is happening. Joe _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]