[DNSOP] Re: PQ DNSSEC?
Philip Homburg <pch-dnsop-7@u-1.phicoh.com> Tue, 21 July 2026 13:50 UTC
Return-Path: <pch-b55F8B228@u-1.phicoh.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 51A5511B6C869 for <dnsop@mail2.ietf.org>; Tue, 21 Jul 2026 06:50:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784641846; bh=8Rtdj083IogmQ3paufI/4JGljZDqEdzPGNy4SZa3YUc=; h=To:Cc:Subject:From:References:In-reply-to:Date; b=agI7A5uf9ZFa8w56H7UJzbUPvJcwksOVwucz7zxPeo3TuXQ8G5t2X+cHE5LsQji2F ndmCfdzK0lh981M9AylYoJlK/wy+Kw7f80I8Zctc48iRvtOloAfogeQzmfSNdBe0V/ 3P3qOWnKjw4AhglAOdM9nNI4xRPdtHWYxhyGq7nA=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gMP7NSt3gRVK for <dnsop@mail2.ietf.org>; Tue, 21 Jul 2026 06:50:44 -0700 (PDT)
Received: from stereo.hq.phicoh.net (stereo.hq.phicoh.net [45.83.6.19]) (using TLSv1.2 with cipher ECDHE-ECDSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EDC5211B6C7EB for <dnsop@ietf.org>; Tue, 21 Jul 2026 06:50:43 -0700 (PDT)
Received: from stereo.hq.phicoh.net (localhost [::ffff:127.0.0.1]) by stereo.hq.phicoh.net with esmtp (TLS version=TLSv1.2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305) (Smail #158) id m1wmArh-0000QQC; Tue, 21 Jul 2026 15:50:33 +0200
Message-Id: <m1wmArh-0000QQC@stereo.hq.phicoh.net>
To: dnsop@ietf.org
From: Philip Homburg <pch-dnsop-7@u-1.phicoh.com>
Sender: pch-b55F8B228@u-1.phicoh.com
References: <CAMjbhoWSTwExS1+gJkijLQxD+9koO7dtO=Cdf6DCem=MqKhK6g@mail.gmail.com> <CAHPuVdXFfagALrdDf+i9J+FuFQKtij0C46qkMnkow62ghZM7sg@mail.gmail.com> <CAHw9_iJ1HM_59jiTv7qSuMmWXFhqz7JX+rkLTB_zcm5xoJdexQ@mail.gmail.com> <E8D0CA62-8E8E-4EEA-AA09-F2ED09B50CD9@verisign.com> <20260721072634.7a3b8cab@860-09-011.sidn.nl> <m1wm9mQ-0000O2C@stereo.hq.phicoh.net> <715a29b9-d542-42a0-a713-ce7c8ec173ff@desec.io>
In-reply-to: Your message of "Tue, 21 Jul 2026 15:28:01 +0200 ." <715a29b9-d542-42a0-a713-ce7c8ec173ff@desec.io>
Date: Tue, 21 Jul 2026 15:50:33 +0200
Message-ID-Hash: 7YCCMLZ7PPVYA2WC2BDUDLLKYKMBQ4GB
X-Message-ID-Hash: 7YCCMLZ7PPVYA2WC2BDUDLLKYKMBQ4GB
X-MailFrom: pch-b55F8B228@u-1.phicoh.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Peter Thomassen <peter@desec.io>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: PQ DNSSEC?
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Sqcmn0bWGLY9HOAjfcecLzkv0F8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
> For Dilithium2, we used algorithm number 18. Our BIND setup has > separate KSK and ZSK keys, and pdns setup uses just one CSK. We > found failure rates between 10% and 40% (slide numbers from [1]): > > Query for an existing record: - Slide 6: BIND auth, UDP failure > rate 29-33%, TCP failure rate 21-22% - Slide 7: pdns auth, UDP > failure rate 10-11%, TCP failure rate ~7% I'm a bit confused by these results. I would expect a zone such as ML-DSA-44.example.com and then in that zone www.ML-DSA-44.example.com IN AAAA 2001:db8::1 and a RIPE Atlas measurement asking all proves to resolve www.ML-DSA-44.example.com/AAAA. The atlas probes should not do TCP or set DO because that's not what a normal stub resolver would do (I'm ignoring systemd-resolver and other proxies) >From the graphs it is not clear to me which one corresponds to this measurement.
- [DNSOP] PQ DNSSEC? Bas Westerbaan
- [DNSOP] Re: PQ DNSSEC? Shumon Huque
- [DNSOP] Re: PQ DNSSEC? Sheth, Swapneel
- [DNSOP] Re: PQ DNSSEC? Shane Kerr
- [DNSOP] Re: PQ DNSSEC? Watson Ladd
- [DNSOP] Re: PQ DNSSEC? Paul Wouters
- [DNSOP] Re: PQ DNSSEC? Mukund Sivaraman
- [DNSOP] Re: PQ DNSSEC? Carlos Horowicz
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Mukund Sivaraman
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Frederico A C Neves
- [DNSOP] Re: PQ DNSSEC? Jim Reid
- [DNSOP] Re: PQ DNSSEC? Joe Abley
- [DNSOP] Re: PQ DNSSEC? Bas Westerbaan
- [DNSOP] Re: PQ DNSSEC? Sophie Schmieg
- [DNSOP] Re: PQ DNSSEC? Loganaden Velvindron
- [DNSOP] Re: PQ DNSSEC? Libor Peltan
- [DNSOP] Re: PQ DNSSEC? Joe Abley
- [DNSOP] Re: PQ DNSSEC? John Heidemann
- [DNSOP] Re: PQ DNSSEC? Havard Eidnes
- [DNSOP] Re: PQ DNSSEC? Shumon Huque
- [DNSOP] Re: PQ DNSSEC? Warren Kumari
- [DNSOP] Re: PQ DNSSEC? Wessels, Duane
- [DNSOP] Re: PQ DNSSEC? Tommy Jensen
- [DNSOP] Re: PQ DNSSEC? Stefan Ubbink
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Vicky Shrestha
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Michael Richardson
- [DNSOP] Re: PQ DNSSEC? Vaibhav Bajpai