[DNSOP] Re: [Ext] Call for adoption: draft-huque-dnsop -multi-alg-rules-08 (Ends 2026-08-31)
Philip Homburg <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
> I think it is very early to make architectural decisions about > PQ algorithms and DNSSEC. To me, it makes more sense to provide > transparency for operators as they try out different local > validation policies and gain experience. Once we have a better > handle on what makes sense we can revisit. > > This was the thinking behind the draft I mentioned a week or > two ago. Perhaps this approach could help avoid complicating > multi-alg-rules with too much handwaving about stuff we don't > have much experience with. As far as I can tell, the local validation policies and the multi-signer drafts conflict when they are applied to the same algorithm. Imagine an algorithm PQ1 that is considered UNIVERSAL and a validator that has a local policy that strictly prefers PQ1 over ECDSA (which is also UNIVERSAL). The zone owner has two KSKs, one of each algorithm and has DS records for each of the two KSK. The zone is signed with ECDSA. This is allowed by the multi-algorithm draft. However, according to the local policy of the validator, the zone is now bogus, becase there a PQ1 KSK, but the zone is not signed with PQ1. _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]