[DNSOP] Re: Local validation policy to require valid PQ path where available

Joe Abley <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Hi Carlos,

On 14 Aug 2026, at 16:21, Carlos Horowicz <[email protected]> wrote:

> do you imagine that implementations would eventually expose this local policy via directives like
> 
> pqc-validation-policy normal; # accept any valid signature
> 
> and
> 
> pqc-validation-policy require-if-present; #require PQC signature to validate without fallback to e.g. ECDSA
> 
> ?

The idea is that resolver operators could use the filtering transparency mechanism to describe whatever policy they thought was worth communicating. 

The example keys in the document are just that, examples.

Browsers or other clients that understand the filtering transparency mechanism could use it to communicate the policy so that (e.g., again) if something is blocked unexpectedly the user has a clue about what is happening. 


Joe

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.