[DNSOP] Re: Call for adoption: draft-huque-dnsop-multi-alg -rules-08 (Ends 2026-08-31)

Shumon Huque <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <CAHPuVdW4mkBfHefsB-5RQx6mBQxHBc6khQ4CF3seQy5zcZXqug@mail.gmail.com>
On Fri, Aug 14, 2026 at 1:59 PM Roy Arends <[email protected]> wrote:

>
>
> On 14 Aug 2026, at 18:35, Philip Homburg <[email protected]>
> wrote:
>
> I therefore dont think we should introduce a generic preference
> for PQC algorithms in this draft. We have a process in RFC9904 for
> introducing new and deprecating old algorithms.
>
>
> It was not my intention to express a preference for PQC or whether we
> should use pure or hybrid, or whether validators should prefer PQC. That
> is all a discussion for later. And, as in Joe's draft, a local preference.
>
> What I wanted to bring up is that the multi-alg draft may interfere with
> with the ability to have a preference at all. So I think we should study
> that
> and figure out a way forward.
>
>
> Ack, thanks for the clarification, Philip!
>
> Roy
>

Assuming the draft gets adopted, the working group can then decide how to
tackle this
additional issue (e.g. roll in a solution into the draft, or make sure it
doesn't block
a solution introduced in a new draft, etc.).

I do agree with Roy's earlier point that in general we don't know at this
stage whether a
PQC algorithm is necessarily more secure than a classical one. The
conservative stance
would be to require both classical and PQC signatures to validate, or use a
hybrid signature
scheme. Those have message size cost implications of course.

Shumon.

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.