[DNSOP] Re: PQ DNSSEC?

Libor Peltan <libor.peltan@nic.cz> Mon, 20 July 2026 10:13 UTC

Return-Path: <libor.peltan@nic.cz>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 03DA511A3D1A9 for <dnsop@mail2.ietf.org>; Mon, 20 Jul 2026 03:13:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784542435; bh=cBeb3moRZO+DX+2L4XPJnpAg1i/LGsSBXqWnE/rNeLs=; h=Date:Subject:To:References:From:In-Reply-To; b=Oih6WwzUOMjJycRlhxYaozgOdW8v6jO1t4uWSD7wEI5tkzaDBhOIMZGHWaHHPkc0c jTPo5HK73zq8qCnx9FfQ6y9zlpFKybA+IPV+wE3cstFOZ3v9GdRA3t0R9StYQKZvyz 8RGeMi6YjCDY4FJNMxqSW90+5wbNI1NehUcRNQRs=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -3.899
X-Spam-Level:
X-Spam-Status: No, score=-3.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001, SUBJ_ALL_CAPS=0.5] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=nic.cz
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vrObCYmvjD_f for <dnsop@mail2.ietf.org>; Mon, 20 Jul 2026 03:13:53 -0700 (PDT)
Received: from mail.nic.cz (mail.nic.cz [217.31.204.67]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id E9D8E11A3D19A for <dnsop@ietf.org>; Mon, 20 Jul 2026 03:13:52 -0700 (PDT)
Received: from [IPV6:2a00:1028:8384:7a:9aae:779d:2dcf:6230] (dynamic-2a00-1028-8384-007a-9aae-779d-2dcf-6230.ipv6.o2.cz [IPv6:2a00:1028:8384:7a:9aae:779d:2dcf:6230]) by mail.nic.cz (Postfix) with ESMTPSA id 645741C0C26; Mon, 20 Jul 2026 12:13:45 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nic.cz; s=default; t=1784542425; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fjjeDzR0aDyfN2BtbCjurTRIIVtN1iIsN+aimHC198A=; b=PpodP1uFO1o7ugxOzQUM/C5Hg9ASD5WaUpx/Zj2ybAEE8mOLvSKvMpVq9y8gtm6ZEllLsZ QJu8IsKnrEvKfMm9lmdEKuBO4/5TOTHkTIqFaTxtNiNK3d1G/BgDfZTso8ZMV5SfNMd6Ht nO9Ri0vZDyDkZJ2Z7bcTH9ZrhAeXpS4=
Authentication-Results: mail.nic.cz; auth=pass smtp.auth=libor.peltan@nic.cz smtp.mailfrom=libor.peltan@nic.cz
Message-ID: <2b6f540b-7f37-4483-bed1-679fc362f06e@nic.cz>
Date: Mon, 20 Jul 2026 12:13:42 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>, dnsop@ietf.org
References: <CAMjbhoWSTwExS1+gJkijLQxD+9koO7dtO=Cdf6DCem=MqKhK6g@mail.gmail.com>
Content-Language: en-US
From: Libor Peltan <libor.peltan@nic.cz>
In-Reply-To: <CAMjbhoWSTwExS1+gJkijLQxD+9koO7dtO=Cdf6DCem=MqKhK6g@mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-Rspamd-Action: no action
X-Spamd-Result: default: False [2.25 / 16.00]; SUBJ_ALL_CAPS(1.35)[18]; SUBJECT_ENDS_QUESTION(1.00)[]; MIME_GOOD(-0.10)[text/plain]; BAYES_HAM(-0.00)[13.71%]; FUZZY_RATELIMITED(0.00)[rspamd.com]; FROM_HAS_DN(0.00)[]; ARC_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:5610, ipnet:2a00:1028::/32, country:CZ]; RCVD_COUNT_ZERO(0.00)[0]; RCPT_COUNT_TWO(0.00)[2]; TO_DN_SOME(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; LOCAL_OUTBOUND(0.00)[]; DKIM_SIGNED(0.00)[nic.cz:s=default]; TO_MATCH_ENVRCPT_ALL(0.00)[]; NEURAL_SPAM(0.00)[1.000]
X-Rspamd-Server: mail
X-Rspamd-Queue-Id: 645741C0C26
X-Spamd-Bar: ++
Message-ID-Hash: QNPY5WIIXRMPDGKLLS3PTWKGZCPCHKAY
X-Message-ID-Hash: QNPY5WIIXRMPDGKLLS3PTWKGZCPCHKAY
X-MailFrom: libor.peltan@nic.cz
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: PQ DNSSEC?
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/C888FileKd_rICHIEvMOZnI9zb4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

On 19. 07. 26 13:16, Bas Westerbaan wrote:
>
>
>  We can't have authoritatives include these by default: it'll break 
> clients that can't fall back to TCP, or are buggy in other ways.
>
I vote against complicating the protocol with thoughts about TCP-unable 
clients or buggy in other ways. Let's finally throw them overboard.

Some people think that substantial switch to TCP would be too expensive 
for root or TLD operations. But it is still unavoidable.

Libor