[DNSOP] Re: Call for adoption: draft-huque-dnsop-multi-alg-rules-08 (Ends 2026-08-31)
Mark Andrews <marka@isc.org> Sat, 15 August 2026 02:47 UTC
Return-Path: <marka@isc.org>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1AF2C12A2B8E7; Fri, 14 Aug 2026 19:47:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786762072; bh=gSfL/tUyTTz1KgFzmihSz5+9TEWR18rMZmxaHoQJFD0=; h=From:Subject:Date:References:Cc:In-Reply-To:To; b=tNs6N/464wXtKjObMukK0t4f3qKYZV/cUMYC2cZVohwDWfLN4jYLGjAR4jCCIylSo xlGi21wnHufphcCu0/uJmZvxrqeCIV6mi0VmN4NE0mInjGjhgMLGx/DawPuT0s4WJB n9cDoc9YrxjsnFYuBwxGOJaJYxAVLyoJ0/iF7VrA=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.399
X-Spam-Level:
X-Spam-Status: No, score=-4.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=isc.org header.b="h+uzeYG4"; dkim=pass (1024-bit key) header.d=isc.org header.b="FERcGp46"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hY-cZQPHgTAV; Fri, 14 Aug 2026 19:47:51 -0700 (PDT)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [149.20.2.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 7066212A2B8E2; Fri, 14 Aug 2026 19:47:51 -0700 (PDT)
Received: from zimbra10.isc.org (zimbra10.isc.org [149.20.2.90]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx.pao1.isc.org (Postfix) with ESMTPS id 18B2E4E408E; Sat, 15 Aug 2026 02:47:44 +0000 (UTC)
ARC-Filter: OpenARC Filter v1.0.0 mx.pao1.isc.org 18B2E4E408E
Authentication-Results: mx.pao1.isc.org; arc=none smtp.remote-ip=149.20.2.90
ARC-Seal: i=1; a=rsa-sha256; d=isc.org; s=ostpay; t=1786762064; cv=none; b=Sl9FIwHUPzAL7OIzuKgBzXx5HEyHJtIzZzXvAH8J/sps4mpuO2P+z0P/7zIvR7O8PWPMp/eWQbZV/YU86YmsvXAuYdBlyd3EzzpbAocXfozviBdr6L8wRyhQxGzaQDsOHLcmvpweJbcKxVgyiNXlI4Wi4TDPz22OuBinh1vtelM=
ARC-Message-Signature: i=1; a=rsa-sha256; d=isc.org; s=ostpay; t=1786762064; c=relaxed/relaxed; bh=2e0QYP3AD0IcD3OomcTaIOmrM1KiIEZsotuq3H1XTP8=; h=DKIM-Signature:DKIM-Signature:From:Mime-Version:Subject:Date: Message-Id:To; b=p2vkPXhJ8iQo77GTOaULTfdTJTt+n2UXTmPOl/S8wfjtemSPu1mcEalFF/6uqiYnzqds340X3RBYKMFJ2N75wpHmIHidUborfC/IMMvgN3r4IkeJdlx9CJVXtzv3b4RLVXZRvzWJT9LAMHSEA55livEMTC/fyX1qgkP/yY4+cSc=
ARC-Authentication-Results: i=1; mx.pao1.isc.org
DKIM-Filter: OpenDKIM Filter v2.10.3 mx.pao1.isc.org 18B2E4E408E
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=isc.org; s=ostpay; t=1786762064; bh=gSfL/tUyTTz1KgFzmihSz5+9TEWR18rMZmxaHoQJFD0=; h=From:Subject:Date:References:Cc:In-Reply-To:To; b=h+uzeYG4rtD/nnz8bt9j8R3ZDb23lFbiiglgnujkQDimAqJfGSHUgwk/tYad8Azss AAylTk47anSRLXV0PNENIpy5jVv/kWryx51ARiB/jYAEukLULFMSyqPSlefNFaH6dQ rugiA7OQuEim3doMIeZSzUwH6d0k1RSdc4oIpje0=
Received: from zimbra10.isc.org (localhost [127.0.0.1]) by zimbra10.isc.org (Postfix) with ESMTPS id 11A0B2E602B7; Sat, 15 Aug 2026 02:47:44 +0000 (UTC)
Received: from zimbra10.isc.org (localhost [127.0.0.1]) by zimbra10.isc.org (Postfix) with ESMTPS id 0295D2E602D9; Sat, 15 Aug 2026 02:47:44 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 zimbra10.isc.org 0295D2E602D9
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isc.org; s=05DFB016-56A2-11EB-AEC0-15368D323330; t=1786762064; bh=2e0QYP3AD0IcD3OomcTaIOmrM1KiIEZsotuq3H1XTP8=; h=From:Mime-Version:Date:Message-Id:To; b=FERcGp465cXi3LzNx6BeH9UJJa7a9RQGN2mPrTAnKmpi+f1iaJL1xNQOQo+3rCKmv PsJUr7EC5OM3ISkGswSG4qXolt03mI4mKPTJ/+ADeFFzeuqhuvM+e7UNsYdFP2xkXS H4cf/CIPYLyJccmJ4IwdzpYiBXUs2HATKCCLYvBs=
Received: from smtpclient.apple (unknown [49.187.18.238]) by zimbra10.isc.org (Postfix) with ESMTPSA id 9D1E42E602B7; Sat, 15 Aug 2026 02:47:41 +0000 (UTC)
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: Mark Andrews <marka@isc.org>
Mime-Version: 1.0 (1.0)
Date: Sat, 15 Aug 2026 12:47:22 +1000
Message-Id: <4E45148B-E055-4BED-A658-7080B182F1A3@isc.org>
References: <178662874440.76825.3626833739189514877@dt-datatracker-559c48c7fb-b8xm6>
In-Reply-To: <178662874440.76825.3626833739189514877@dt-datatracker-559c48c7fb-b8xm6>
To: Benno Overeinder <benno@nlnetlabs.nl>
X-Mailer: iPhone Mail (23G71)
Message-ID-Hash: CH4DW6V6JZCBFAD2JAY23PHDGRP5M7H7
X-Message-ID-Hash: CH4DW6V6JZCBFAD2JAY23PHDGRP5M7H7
X-MailFrom: marka@isc.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dnsop@ietf.org, dnsop-chairs@ietf.org, draft-huque-dnsop-multi-alg-rules@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Call for adoption: draft-huque-dnsop-multi-alg-rules-08 (Ends 2026-08-31)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/O_5N91Q88VMyA2hU407JOPxu9G4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
This is fundamentally flawed. It assumes that EVERY validator in the world supports ALL of the algorithms a zone is signed with. This is a “I want a pony” draft. It will not work for every validator. Validator operators shouldn’t have to add NTAs, assuming that there implementation supports them, because people are to lazy to do due diligence when moving operators. -- Mark Andrews > On 13 Aug 2026, at 23:46, Benno Overeinder via Datatracker <noreply@ietf.org> wrote: > > This message starts a dnsop WG Call for Adoption of: > draft-huque-dnsop-multi-alg-rules-08 > > This Working Group Call for Adoption ends on 2026-08-31 > > Abstract: > This document restates the requirements on DNSSEC signing and > validation and makes small adjustments in order to allow for more > flexible handling of configurations that advertise multiple Secure > Entry Points (SEP) with different signing algorithms via their DS > record or trust anchor set. The adjusted rules allow both for multi- > signer operation and for the transfer of signed DNS zones between > providers, where the providers support disjoint DNSSEC algorithm > sets. In addition, the proposal enables pre-publication of a trust > anchor in preparation for an algorithm rollover, such as of the root > zone. > > This document updates RFCs 4035 and 6840. > > Please reply to this message and indicate whether or not you support adoption > of this Internet-Draft by the dnsop WG. Comments to explain your preference > are greatly appreciated. Please reply to all recipients of this message and > include this message in your response. > > Authors, and WG participants in general, are reminded of the Intellectual > Property Rights (IPR) disclosure obligations described in BCP 79 [2]. > Appropriate IPR disclosures required for full conformance with the provisions > of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. > Sanctions available for application to violators of IETF IPR Policy can be > found at [3]. > > Thank you. > [1] https://datatracker.ietf.org/doc/bcp78/ > [2] https://datatracker.ietf.org/doc/bcp79/ > [3] https://datatracker.ietf.org/doc/rfc6701/ > > The IETF datatracker status page for this Internet-Draft is: > https://datatracker.ietf.org/doc/draft-huque-dnsop-multi-alg-rules/ > > There is also an HTML version available at: > https://www.ietf.org/archive/id/draft-huque-dnsop-multi-alg-rules-08.html > > A diff from the previous version is available at: > https://author-tools.ietf.org/iddiff?url2=draft-huque-dnsop-multi-alg-rules-08 > > _______________________________________________ > DNSOP mailing list -- dnsop@ietf.org > To unsubscribe send an email to dnsop-leave@ietf.org
- [DNSOP] Call for adoption: draft-huque-dnsop-mult… Benno Overeinder via Datatracker
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Shumon Huque
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Paul Wouters
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Loganaden Velvindron
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Ralf Weber
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Philip Homburg
- [DNSOP] Local validation policy to require valid … Joe Abley
- [DNSOP] Re: Local validation policy to require va… Carlos Horowicz
- [DNSOP] Re: Local validation policy to require va… Joe Abley
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Christian Elmerot
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Roy Arends
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Philip Homburg
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Roy Arends
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Shumon Huque
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Roy Arends
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Mark Andrews
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Philip Homburg
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Michael Richardson
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Philip Homburg
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Libor Peltan
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Paul Hoffman
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Philip Homburg
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Joe Abley
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Philip Homburg
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Joe Abley
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Johan Stenstam
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Stefan Ubbink
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Russ Housley
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Benno Overeinder