[DNSOP] Re: DNSOPDELEXT: Proposed Delegation Type Ranges

Paul Wouters <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
On Mon, 24 Aug 2026, Philip Homburg wrote:

> A problem with DELEG is that if a nameserver that is not DELEG-aware serves
> a DNSSEC signed zone with DELEG records then this will cause failures.
>
> So DELEXT is supposed to provide a solution to this problem for future
> types (after DELEG), we cannot fix the current situation.

We could decide DELEG is not the solution we were looking for, and look
at a better redesign of DNS transport and child-parent information
authentication and fold in native encryption and packet/signature sizes
for PQ etc.

It feels to me DELEG / DELEXT is adding a lot of complexity for what is
ultimately a small use case (let DNS hosters update DNSSEC KSKs) to the
point where perhaps a DNS v2.0 from scratch would be better.

To me if feels the DELEG path is becoming more and more a stack of nifty
hacks.

Paul

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.