[dns-at-ietf] Re: DNSSEC: (was: Community consensus report on DNS WG structures at IETF)

Paul Hoffman <phoffman@proper.com> Fri, 13 February 2026 15:44 UTC

Return-Path: <phoffman@proper.com>
X-Original-To: dns-at-ietf@mail2.ietf.org
Delivered-To: dns-at-ietf@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8E334B6FF88C for <dns-at-ietf@mail2.ietf.org>; Fri, 13 Feb 2026 07:44:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7aHLhPE-O5cz for <dns-at-ietf@mail2.ietf.org>; Fri, 13 Feb 2026 07:44:57 -0800 (PST)
Received: from mail.proper.com (Opus1.Proper.COM [207.182.41.91]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 21D40B6FF887 for <dns-at-ietf@ietf.org>; Fri, 13 Feb 2026 07:44:57 -0800 (PST)
Received: from [10.106.148.22] (76-209-242-70.lightspeed.mtryca.sbcglobal.net [76.209.242.70]) (authenticated bits=0) by mail.proper.com (8.15.2/8.15.2) with ESMTPSA id 61DFitaY072082 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for <dns-at-ietf@ietf.org>; Fri, 13 Feb 2026 08:44:56 -0700 (MST) (envelope-from phoffman@proper.com)
X-Authentication-Warning: mail.proper.com: Host 76-209-242-70.lightspeed.mtryca.sbcglobal.net [76.209.242.70] claimed to be [10.106.148.22]
From: Paul Hoffman <phoffman@proper.com>
To: dns-at-ietf@ietf.org
Date: Fri, 13 Feb 2026 07:44:54 -0800
X-Mailer: MailMate (2.0r6272)
Message-ID: <7DB0D06F-5C9A-4A22-8812-3DCE27FFFABD@proper.com>
In-Reply-To: <m1vqoRm-0000MtC@stereo.hq.phicoh.net>
References: <ybl4inoe1is.fsf@wx.hardakers.net> <1C7E2939-52C2-4069-91A8-3C27665D5F5B@proper.com> <m1vqoRm-0000MtC@stereo.hq.phicoh.net>
MIME-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: TVBHK6R75LEIK6HMOWOKL52RBIXTQRP6
X-Message-ID-Hash: TVBHK6R75LEIK6HMOWOKL52RBIXTQRP6
X-MailFrom: phoffman@proper.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [dns-at-ietf] Re: DNSSEC: (was: Community consensus report on DNS WG structures at IETF)
List-Id: "This list is to discuss the structure of DNS work in the IETF, and DNSOP in particular." <dns-at-ietf.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-at-ietf/i1-Xhd1cuRKgEcRPJnrp20cAnX4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-at-ietf>
List-Help: <mailto:dns-at-ietf-request@ietf.org?subject=help>
List-Owner: <mailto:dns-at-ietf-owner@ietf.org>
List-Post: <mailto:dns-at-ietf@ietf.org>
List-Subscribe: <mailto:dns-at-ietf-join@ietf.org>
List-Unsubscribe: <mailto:dns-at-ietf-leave@ietf.org>

On 13 Feb 2026, at 0:22, Philip Homburg wrote:

>> A simple solution to this would be to add a third WG to DNSPROT
>> and DNSDEP: the DNSSEC WG. This would absorb all the current and
>> future DNSSEC-related work, leaving DNSPROT to focus on work that
>> is for the core of the DNS protocols, and leaving DNSDEP to focus
>> on the operational issues with the DNS that are unrelated (or just
>> mildly adjacent) to DNSSEC. The text about DNSDISPATCH would be
>> mostly left alone, but adding in the ability to send things to
>> DNSSEC.
>
> Can you explain a bit more how this would work?

Some have suggested that there be a separate way to go fetch large keys for algorithms with particularly large keys that have long lifetimes. (I happen to dislike this idea, but it has come up more than once.)

> Though there might be enough 'pure' DNSSEC work to warrant a separate
> WG. We did have some pure DNSSEC work, the well-known algorithms draft,
> the lifecycle draft, the new hash algorithms for private algorithms draft.

Looking at the work list for the current DNSOP WG, I believe that there is. I also believe that the people involved in it have specific talents and understandings, honed over a few decades, that many others do not.

--Paul Hoffman