[DNSOP] Re: PQ DNSSEC?
Shumon Huque <shuque@gmail.com> Sun, 19 July 2026 13:04 UTC
Return-Path: <shuque@gmail.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id B994311992EA9 for <dnsop@mail2.ietf.org>; Sun, 19 Jul 2026 06:04:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784466297; bh=qh0KIQ6/CQYH864VowkHvgD+2jsDbnfxlrDJ2G/+qag=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=xmivtdCCt1qcYNOTMpxGbHPi1gd2lsTQasLZUj1i3ctiNDPWhI4PGKJvirFKVt31N LbnTkKYi82L6uPmhj6R0PLHe+kfR/jlMcPbPE7fJ1XzVyE05IUHRJHV0fMZbpDLEcy Dw1mC9MZLtf1RuBX1aowoVhVx1QuUKmGh54GxYoY=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.588
X-Spam-Level:
X-Spam-Status: No, score=-1.588 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, SUBJ_ALL_CAPS=0.5, T_KAM_HTML_FONT_INVALID=0.01] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r-G24nS8CqsB for <dnsop@mail2.ietf.org>; Sun, 19 Jul 2026 06:04:57 -0700 (PDT)
Received: from mail-wm1-x32a.google.com (mail-wm1-x32a.google.com [IPv6:2a00:1450:4864:20::32a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 851B011992053 for <dnsop@ietf.org>; Sun, 19 Jul 2026 06:03:42 -0700 (PDT)
Received: by mail-wm1-x32a.google.com with SMTP id 5b1f17b1804b1-4954c0833b4so11072555e9.1 for <dnsop@ietf.org>; Sun, 19 Jul 2026 06:03:42 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784466221; cv=none; d=google.com; s=arc-20260327; b=NT6UBT/EuYuSml6QfGkq6/o/wIegUrWiULpKfdn6L5veEbKTPQR5AND89sZpz4+q42 1ExsnPd8nr+Rli52Ii4bfD9JspyZYkO+2r09ymo5z9l5ohvIsXu5gDodnv1hltkpZdjx pmotczYNsalFdytCcGO/ihDV4k+HGQJXTrccMAztS86emrFYF9WJ8N2uln2G9DMgEMRe CfACv0G9uLaWJwd55+qJ4p8zScNkQD/d0HinkrSIU3WzSnkL6+0cegFCcEDpVxzUSyzw JZ4zlXjTmaHqOsx5LKYZNBACsjtg4fYI1pXxHDDuMchDdsieguUOOH0hlGfpDaEBQx8W +5wQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=qh0KIQ6/CQYH864VowkHvgD+2jsDbnfxlrDJ2G/+qag=; fh=Z92PMR0TOBDO4YnHKCxk94CELLhFcobnanAVuErZx4w=; b=hNSCmkgGROrGb4x5VtW2YkaiAcNRJVS0NSWXsMqAQh8ZR/kDsPjUIVPtsiEgh3Bh3k kj3TnlmuPAKgdsUG9Cm2yfa129lIRT0cENkBxL6w+WkiUbSXRxOZibN/fd/Md0csf9D4 FZQz0xqYDmTz5mCTWYA0fivB1un9S3ABQwXVkQrDLagjlGduS1ySlwtzuBcSM6oV3qAe bcftvidGavE+hM8QU+fr6XxF5y87sd4fjb7mbs8yzRJVHc74TeKRCol6EA5AIuR2aG7a IQiQSR31x8KRSppnm6ChdVYStK5rt5pPXKfqoAY7odCKn5KmAu29zf/8mKOKZQhfL3Ev fQZA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784466221; x=1785071021; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=qh0KIQ6/CQYH864VowkHvgD+2jsDbnfxlrDJ2G/+qag=; b=Sjn4WgK94JlnWE7WXy68wstSzb6FZRxUJI11gsIuAsYREWWgXBlqiYp2kOVgXCQoez iiADquZckaPpSSVgrPd3hbFG8yys7DTU2wDCQmOuZTpyR2DeDE0kVi0zYXwkIT3BgkK/ ZqmWGqjR5VZ9xe/0qpWd6q+77wL2unaipKiDaU8tE9le+lcEvveMvd7R5ENOdNAD0txt NXDjsvQfcq6HLmPA8f9fZFT6YZwA065HtzngN4E0TBmaHjdDcURLdCHx2pA+kCcSJkMr 4eEsJhyEY7zSwuy1bGdYMGIo4+VU75LDsDPw6lniOa1Fq3mfrgFz0WG3Gou8cMHJqxte 8HdA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784466221; x=1785071021; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=qh0KIQ6/CQYH864VowkHvgD+2jsDbnfxlrDJ2G/+qag=; b=F8/y73fZqwO5wewl8Wk6ZuoRd/DSHGdfnyolLOQUAvMKSkMcGcMIqau9po6Ww9+uHN tPapauugHOgrg4r8Xztrjx9qZ4pQANt7zmNIbO+um4bEEtRi2cie59xP1R9NTDmrZ/R0 1z3FqVwhEe2Wo7ABeCcMvmwnavZx4Fg943K00qk9IpeJUrvmWzC+dDTDd+nPtw0DCyz4 l4GSL4nEYuu8SaWaIhhWsYR9kJmDTWp4/MW9cnTjsnHiIgz3lIsveXYIB6JkPlWk9yIJ DZiB9SN2ydmDQChWQWR+pY1CQXBTMlS1pYHwl1++CM00AX8d3VO/ny53zgsBe4Ycjavs edvg==
X-Gm-Message-State: AOJu0YyMyAdcv+zxuSOK1unvUMHa5GVtz76OehYXkCCJzsnkl5ZBQwe2 SuKuj1JUhSOTjtudxvGMDmFhybBWng83Lod01ZwhFiyGwW/pgLKYWeG1Zv4JbE25VfpDSsEFp11 jbGwIH1LiMxNkUOmUTBl/oNNBh6n0UdM=
X-Gm-Gg: AfdE7cm6rrJPloW8l+53BBhF33kzcKy9Okoz7wI7pGK7YSc/XxTzVwPuqcA+qqqghtv FjwA3DsUJUeVN109oIADYZ91FcUu7C4RSj2Oh2y0TEBP4rlIM0WRDXEfK3bx+B6jGFdQnfi94rm WDCv3SP5yidytdDwefoSATNsA24RHm5ORvG36/yfQooC3iTbzP9LeaRSN+KCyuXjJOlcCQjU0KD hqDTFjiX1S3Dq/m6WMmwBp+hFeKxUWzaMqrCX/lsYXWMZckhhSY9C3As7jLLw==
X-Received: by 2002:a05:6000:1844:b0:47f:722a:f599 with SMTP id ffacd0b85a97d-47f722af86amr3041289f8f.31.1784466221225; Sun, 19 Jul 2026 06:03:41 -0700 (PDT)
MIME-Version: 1.0
References: <CAMjbhoWSTwExS1+gJkijLQxD+9koO7dtO=Cdf6DCem=MqKhK6g@mail.gmail.com>
In-Reply-To: <CAMjbhoWSTwExS1+gJkijLQxD+9koO7dtO=Cdf6DCem=MqKhK6g@mail.gmail.com>
From: Shumon Huque <shuque@gmail.com>
Date: Sun, 19 Jul 2026 09:03:30 -0400
X-Gm-Features: AUfX_my1Nwh7UNzUYdXV0YB1Y-VsgpXxUxkH4BBdpR7uWDdRghnB4ig90CyJyPc
Message-ID: <CAHPuVdUQGcrMz74SD=oSUaC6mxP+3SshrkpAvtMNHngTO-+yGg@mail.gmail.com>
To: Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="0000000000003adc200656f66be7"
Message-ID-Hash: FMEGEJ4IBHAPAZBLESMHZMZCKI2ZTZHK
X-Message-ID-Hash: FMEGEJ4IBHAPAZBLESMHZMZCKI2ZTZHK
X-MailFrom: shuque@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dnsop@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: PQ DNSSEC?
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/2kZwfhHjk9L0v6C9VAIoP4sSWaI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
On Sun, Jul 19, 2026 at 1:16 PM Bas Westerbaan <bas= 40cloudflare.com@dmarc.ietf.org> wrote: > Hey all, > > With various new regulatory timelines for valuable systems to be PQ by > 2031, we're getting questions what we're looking at with DNSSEC. Looking > from afar (and please forgive me my ignorance) it doesn't look good. There's a > lot of academic investigation and experimentation (great), IETF > side-meetings, but no thrust or plans to any deployment; no adopted drafts > or BoFs. > I agree that it's probably time to get PQ DNSSEC work officially into an IETF working group's charter. If we care for PQ DNSSEC by 2031, what would be the most practical path? We > can't be too ambitious. > > So what are we looking at? The only practical [1] signature scheme > available on this timeframe is ML-DSA-44 with 2,420 byte signatures and > 1,322 byte public keys. We can't have authoritatives include these by > default: it'll break clients that can't fall back to TCP, or are buggy in > other ways. > > Instead I suppose we have the client signal if it supports ML-DSA-44 [2], > and only in that case return those large RRSIGs. This allows for gradual > demployment, and only impacts those that care for PQ DNSSEC. While we wait > for the root to sign with ML-DSA-44, resolver can anchor on TLDs ML-DSA-44 > keys. > Selectively returning PQC signatures was in fact one of the use cases envisioned by that draft. It could be revived if there is renewed interest. (Link: https://datatracker.ietf.org/doc/html/draft-huque-dnssec-alg-nego-03 ) Shumon.
- [DNSOP] PQ DNSSEC? Bas Westerbaan
- [DNSOP] Re: PQ DNSSEC? Shumon Huque
- [DNSOP] Re: PQ DNSSEC? Sheth, Swapneel
- [DNSOP] Re: PQ DNSSEC? Shane Kerr
- [DNSOP] Re: PQ DNSSEC? Watson Ladd
- [DNSOP] Re: PQ DNSSEC? Paul Wouters
- [DNSOP] Re: PQ DNSSEC? Mukund Sivaraman
- [DNSOP] Re: PQ DNSSEC? Carlos Horowicz
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Mukund Sivaraman
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Frederico A C Neves
- [DNSOP] Re: PQ DNSSEC? Jim Reid
- [DNSOP] Re: PQ DNSSEC? Joe Abley
- [DNSOP] Re: PQ DNSSEC? Bas Westerbaan
- [DNSOP] Re: PQ DNSSEC? Sophie Schmieg
- [DNSOP] Re: PQ DNSSEC? Loganaden Velvindron
- [DNSOP] Re: PQ DNSSEC? Libor Peltan
- [DNSOP] Re: PQ DNSSEC? Joe Abley
- [DNSOP] Re: PQ DNSSEC? John Heidemann
- [DNSOP] Re: PQ DNSSEC? Havard Eidnes
- [DNSOP] Re: PQ DNSSEC? Shumon Huque
- [DNSOP] Re: PQ DNSSEC? Warren Kumari
- [DNSOP] Re: PQ DNSSEC? Wessels, Duane
- [DNSOP] Re: PQ DNSSEC? Tommy Jensen
- [DNSOP] Re: PQ DNSSEC? Stefan Ubbink
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Vicky Shrestha
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Michael Richardson
- [DNSOP] Re: PQ DNSSEC? Vaibhav Bajpai