[DNSOP] Re: PQ DNSSEC?
Watson Ladd <watsonbladd@gmail.com> Mon, 20 July 2026 00:52 UTC
Return-Path: <watsonbladd@gmail.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8DA04119E72D0 for <dnsop@mail2.ietf.org>; Sun, 19 Jul 2026 17:52:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784508758; bh=wquQ9YT6ha7UCdB2FtWN8AwrGVi/76DLpb9dcFEYRIA=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=bbp2NwDHTR1wieMg7VKwxkV6n18M/DNiDYmZDEYw/ThCHkokxOAw/Uq5gxCK9FqOj 8R5JuOY7GvRHcLqPIDL7hvcN7KjYJqKU8RPSmHCSiUPdvbEh5m3f19+IpwSlRG/S2K X+vfqROsRYOQHC/Y6aBmLFMDQGmq5lweGpOhR3h4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.599
X-Spam-Level:
X-Spam-Status: No, score=-1.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, SUBJ_ALL_CAPS=0.5] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fiJ6NJIws2v9 for <dnsop@mail2.ietf.org>; Sun, 19 Jul 2026 17:52:38 -0700 (PDT)
Received: from mail-wm1-x332.google.com (mail-wm1-x332.google.com [IPv6:2a00:1450:4864:20::332]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 25692119E72C8 for <dnsop@ietf.org>; Sun, 19 Jul 2026 17:52:38 -0700 (PDT)
Received: by mail-wm1-x332.google.com with SMTP id 5b1f17b1804b1-49548aebcd8so15623085e9.3 for <dnsop@ietf.org>; Sun, 19 Jul 2026 17:52:38 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784508757; cv=none; d=google.com; s=arc-20260327; b=VFHZXjuZPG2LWOy5fbywkWbUymp6Iq43aT7EyEr3MI8I+jR31/vuwjecmKPNyO0Vqn dXFJOJrKpDwmGwKqZ5TCbh0LIV9soz34ILeiW7cthd5uA3mNAqQ8HRhpUAM5QzAck5VR 7R1m3BLffPQKKNOA3/MDZZ02kKgacRZ6HYVdGrIaz1K3AU85xAVWbpORw0CvN19k+Rnf pvhiGj6lJIMwUgNGx5U6dsc1ti9MkJN6uuNPUacjhyPnpz9anVv3g9LU+xzM6m835nbM Yom6vMfjBVVVWtwBpuRm/miWJQC8JEszOnMiKjLf+opVibl5fxw2NObXp4l2BHCbavBr UwNA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=GrxHR0qLX6jCxbIEjeHyHDo2eFvN2U615ZRqyYAqqIU=; fh=Z92PMR0TOBDO4YnHKCxk94CELLhFcobnanAVuErZx4w=; b=XoY2jiEOhAwqyFrEStTDZqcBn6Kf1WDjUxQs/aTwcgtK9RNKkD/IlJg82BxC1YVoOl HHrYHDXeJzUE4+dHS/RWEW8rLAY4NH5MpkSIagdFKqRkhcXbwADJcCgW+qysSkOuNvrd R4hrwYTLn8rUia8/Iu6hi0UhAz8xsoTg32RAbwkU2bknveRN82nBc4CveCB+tcI+ov2N zdTO7KdFKUdUTPCdYqApmxd4kWZxvgJa5CdaRwFzQs7aIcSMjY4VTEMrrDzmM4KxeXHm +x/e/0FMrnDSTbcXBB5BLcMu3zhurJm1TuxwJ/t+snCvJVHqvUfvCn7TncOxygNzg3/j UPVA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784508757; x=1785113557; darn=ietf.org; h=content-transfer-encoding:content-type:cc:to:subject:message-id :date:from:in-reply-to:references:mime-version:from:to:cc:subject :date:message-id:reply-to:content-type; bh=GrxHR0qLX6jCxbIEjeHyHDo2eFvN2U615ZRqyYAqqIU=; b=TUk4Y1cHmfUb3lJ6oTavAG3ww1BcA7nBJVASCKxWkNfgJcOvLjIBIjgLBHNnrBMxzO pbrjOGWu8091c/arC3gkQfg9XsjioK8vdtkFK1w5TtD5Y6GrULaL2boLaKw/MCe+xnsT ApOeM6epvNPcaXrgIJ/Tjccn9POyoguK4bD2jcgw0GgMf2Urn5NbAXADNXsPRHidxsbp Je9i8Eo8eMSIE8urdCMjWwbpkQGe0qPtTwIQO4ULtplIxOxa+NMzhy/81UoTs2YJ4SXx 0CGNnQmAt4ULcRS4cP6DyxMma2c1CW2lFYFm2eCkTJi3Z8GITo0aMkyRzzO8qk7iH36W 19iw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784508757; x=1785113557; h=content-transfer-encoding:content-type:cc:to:subject:message-id :date:from:in-reply-to:references:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=GrxHR0qLX6jCxbIEjeHyHDo2eFvN2U615ZRqyYAqqIU=; b=avnHophe03kLzBYt0xowiVtJJluo5GUq27Gk3OPa6vs4TzJaP66pfsCMso5ejsYXCz EKLRJVzkGPsNvu/n15WJamIevANSomzzYTteDV4UcoNMgix80aimACOsY63PYpH/IawY B51RgEOKV5mpaKGcgnx5t0vTc7qOhDhzosH7rkFO8StmR2XNG25cDCg6N6uk8Zb+RkV2 SkP4j5pZzXoCg1Up0Rb89PMy3zr6IHSx74jB8fgB9xrcPO9Q17AHPNP9HVhWaZWYpXVP Z5coXDJLFKk0dHBpBebxdJygP+9GkZCYX06VjzVp3tyMNHEpQkkw9aKTMRLdqoc0wZea kWQg==
X-Gm-Message-State: AOJu0YxhE+sibe5sD1at2Dx3oAb04GTpfxev+VElbfI7XhNUy0hmqfPM XvdMORYYh9RBVfnavjh8X1QDBVXzJ0n/HQkDw6pkeoI4I5nJ7Dtqm33O77FbJMqzttS1e3rfgxW 0MoTzkj9AlwJIGbo3uefmGQA5Pwza+YISdw==
X-Gm-Gg: AfdE7clpQhWKXHqtKcnw+rd9A8pMN4z0t/4S6qlPlbUfl0M0BahTbjsm723Jmr7mqfs kdVhBeuxKAU8xLqsZ1Wx3zUsVZubaEVzsPsc1mxOshOzbDYXXVYG/QVJUKqQ63mfBkTbs9c9x2u gvdOtSKlDHNvw74lYi/zVcrdbYK+86ga/qNZ5zRl3k002Z9atIv1YuH+IOer2sceKx1Ppv5Q4VW HWEwQbveWiRLDXhSkgM/kaqSD3dmVSyZxTVWk+OCPJul0RJlm6IbVyEV/GiYek59M71Rd+2WmSW 1NnKcO36XLUqOdPLyF4DgSYTMrSWzvx/Y2iC4dzlToyX/RGL1vXg9RUTR+kWq1oteYvPIYlMHZG bs8+QxKZDn9K4fIwQVscVIdiZtUHAX4iQxA==
X-Received: by 2002:a05:600c:3b19:b0:495:48d7:f178 with SMTP id 5b1f17b1804b1-4954a3db76amr132588715e9.11.1784508756801; Sun, 19 Jul 2026 17:52:36 -0700 (PDT)
MIME-Version: 1.0
References: <CAMjbhoWSTwExS1+gJkijLQxD+9koO7dtO=Cdf6DCem=MqKhK6g@mail.gmail.com>
In-Reply-To: <CAMjbhoWSTwExS1+gJkijLQxD+9koO7dtO=Cdf6DCem=MqKhK6g@mail.gmail.com>
From: Watson Ladd <watsonbladd@gmail.com>
Date: Sun, 19 Jul 2026 17:52:25 -0700
X-Gm-Features: AUfX_mwhYS0xqmsolEG5XUzINCHVKx9iDs2W2KF6jJCZp2xU1EDvU_yce6Wej90
Message-ID: <CACsn0cn7=2cms=mx5VkTQiUWEsF7P5SHfAtEeX2a=zEqV0biDw@mail.gmail.com>
To: Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: 6T6I7BUVZDN2UWPFXUY3I2MONWD33XY4
X-Message-ID-Hash: 6T6I7BUVZDN2UWPFXUY3I2MONWD33XY4
X-MailFrom: watsonbladd@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dnsop@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: PQ DNSSEC?
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/P01x1OC4FpVlwvGVNJML8dbrtjs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
On Sun, Jul 19, 2026 at 4:17 AM Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org> wrote: > > Hey all, > > With various new regulatory timelines for valuable systems to be PQ by 2031, we're getting questions what we're looking at with DNSSEC. Looking from afar (and please forgive me my ignorance) it doesn't look good. There's a lot of academic investigation and experimentation (great), IETF side-meetings, but no thrust or plans to any deployment; no adopted drafts or BoFs. > > If we care for PQ DNSSEC by 2031, what would be the most practical path? We can't be too ambitious. > > So what are we looking at? The only practical [1] signature scheme available on this timeframe is ML-DSA-44 with 2,420 byte signatures and 1,322 byte public keys. We can't have authoritatives include these by default: it'll break clients that can't fall back to TCP, or are buggy in other ways. > > Instead I suppose we have the client signal if it supports ML-DSA-44 [2], and only in that case return those large RRSIGs. This allows for gradual demployment, and only impacts those that care for PQ DNSSEC. While we wait for the root to sign with ML-DSA-44, resolver can anchor on TLDs ML-DSA-44 keys. > > In the right ballpark? Since singing is designed to be offline, and verification doesn't actually matter, and size does, SQISign is the obvious choice. We know verification doesn't matter given people regularly turn it off rather than fail closed when verification is failing. Sincerely, Watson > > Best, > > Bas > > > [1] https://blog.cloudflare.com/ml-dsa-will-have-to-do/ > [2] Should we repurpose draft-huque-dnssec-alg-nego? > > _______________________________________________ > DNSOP mailing list -- dnsop@ietf.org > To unsubscribe send an email to dnsop-leave@ietf.org -- Astra mortemque praestare gradatim
- [DNSOP] PQ DNSSEC? Bas Westerbaan
- [DNSOP] Re: PQ DNSSEC? Shumon Huque
- [DNSOP] Re: PQ DNSSEC? Sheth, Swapneel
- [DNSOP] Re: PQ DNSSEC? Shane Kerr
- [DNSOP] Re: PQ DNSSEC? Watson Ladd
- [DNSOP] Re: PQ DNSSEC? Paul Wouters
- [DNSOP] Re: PQ DNSSEC? Mukund Sivaraman
- [DNSOP] Re: PQ DNSSEC? Carlos Horowicz
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Mukund Sivaraman
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Frederico A C Neves
- [DNSOP] Re: PQ DNSSEC? Jim Reid
- [DNSOP] Re: PQ DNSSEC? Joe Abley
- [DNSOP] Re: PQ DNSSEC? Bas Westerbaan
- [DNSOP] Re: PQ DNSSEC? Sophie Schmieg
- [DNSOP] Re: PQ DNSSEC? Loganaden Velvindron
- [DNSOP] Re: PQ DNSSEC? Libor Peltan
- [DNSOP] Re: PQ DNSSEC? Joe Abley
- [DNSOP] Re: PQ DNSSEC? John Heidemann
- [DNSOP] Re: PQ DNSSEC? Havard Eidnes
- [DNSOP] Re: PQ DNSSEC? Shumon Huque
- [DNSOP] Re: PQ DNSSEC? Warren Kumari
- [DNSOP] Re: PQ DNSSEC? Wessels, Duane
- [DNSOP] Re: PQ DNSSEC? Tommy Jensen
- [DNSOP] Re: PQ DNSSEC? Stefan Ubbink
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Vicky Shrestha
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Michael Richardson
- [DNSOP] Re: PQ DNSSEC? Vaibhav Bajpai