[DNSOP] Re: [Ext] Call for adoption: draft-huque-dnsop -multi-alg-rules-08 (Ends 2026-08-31)

Philip Homburg <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
>    I think it is very early to make architectural decisions about
>    PQ algorithms and DNSSEC. To me, it makes more sense to provide
>    transparency for operators as they try out different local
>    validation policies and gain experience. Once we have a better
>    handle on what makes sense we can revisit.
> 
>    This was the thinking behind the draft I mentioned a week or
>    two ago.  Perhaps this approach could help avoid complicating
>    multi-alg-rules with too much handwaving about stuff we don't
>    have much experience with.

As far as I can tell, the local validation policies and the multi-signer
drafts conflict when they are applied to the same algorithm.

Imagine an algorithm PQ1 that is considered UNIVERSAL and a validator that
has a local policy that strictly prefers PQ1 over ECDSA (which is also
UNIVERSAL).

The zone owner has two KSKs, one of each algorithm and has DS records
for each of the two KSK. The zone is signed with ECDSA. This is allowed
by the multi-algorithm draft.

However, according to the local policy of the validator, the zone is now
bogus, becase there a PQ1 KSK, but the zone is not signed with PQ1.




_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.