[DNSOP] Re: Call for adoption: draft-huque-dnsop-multi-alg-rules-08 (Ends 2026-08-31)
Roy Arends <roy@dnss.ec> Fri, 14 August 2026 16:36 UTC
Return-Path: <roy@dnss.ec>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 65B0F129E7AD3 for <dnsop@mail2.ietf.org>; Fri, 14 Aug 2026 09:36:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786725378; bh=BHU3lsr92oL9UyK3W8IWi6kd3gWB2GLpWzrpkya+Pgk=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=NmmaFDR3YpVBVc310wQ+KWtIMTIRMQ4NW0LYgGL7n73jEvB7OS2w1odNRSz1OUf1+ GxpALOoyXYRL6B3w/OKfe72PlOMA+MleKBlhHzihrLZmqWSDGjj6v9lT3PoQC7zVE2 yP/NOst9fx39FziOca2wFmqbYhtJLvz7HC7Qc16c=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=dnss.ec
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VIRHr0i5QMaZ for <dnsop@mail2.ietf.org>; Fri, 14 Aug 2026 09:36:17 -0700 (PDT)
Received: from mail-qt1-x829.google.com (mail-qt1-x829.google.com [IPv6:2607:f8b0:4864:20::829]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9ABF7129E7AC4 for <dnsop@ietf.org>; Fri, 14 Aug 2026 09:36:17 -0700 (PDT)
Received: by mail-qt1-x829.google.com with SMTP id d75a77b69052e-52d8679c149so6773431cf.2 for <dnsop@ietf.org>; Fri, 14 Aug 2026 09:36:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dnss.ec; s=google; t=1786725377; x=1787330177; darn=ietf.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=Ao9sytMYbCFy8UlICM6NhoDcj2otnE50hMxmLeSIaDM=; b=LCl1QdSKcPH61EN5LxLKp8yYWcu0vyqlG2ZPjzgm+/q9Vvh/Nu2pXF7HnNAiJyJOsl E31MuXTXxGjblak2p4PkCWL+00b712uzHj9Oeq+dC1e8gB/9pS/jxVCHlXqbL7EMVFOr SQ6YuSPkF0t0W/kXMgqApsSozxeJqZQVfuB7E=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786725377; x=1787330177; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Ao9sytMYbCFy8UlICM6NhoDcj2otnE50hMxmLeSIaDM=; b=oMoBD5TlHRbHkHLUeyL4+2Uo9mZxWICRSn+KjAy8Mr4/GjiW468ABsnGne4VFL6nMO dNwf3ckOuH4V1hpTyuO4gyUD6Xqs9DJNEIQGSlzcfmjAIlRD0nbC0JffCwsr0ySNBFvm JYHrEt11hiXd2/CyqpF8P6vyYLkZ+9enwi5bAU2IQcoID6mnJsi7D0uXxXnt5KCqnKvN OJz+27V8V8YdBdD1hwMW4qfzZc3HXZfHOH4C8idWYarqeMGwMV3UcbrlPlBsggbjHUeO 7qXEz9GTRxQbFeZXSOkDumZHUiIyNdgjuv4U2ehdP9hQXHbQ6WrXHgH13erQiX36T2NR E7aQ==
X-Gm-Message-State: AOJu0YwpdXwnGhYcXY7Sdj63lhDnRx9oJQOfm3QlMPlB8Z+ZOAs5qKev y2PepjBE7Sgfn9CFSfU3ccpXMqn28Euv4zW/kBQR1CYm8Ig3JSojc9BYGHtl3KH+0jZlZ/oHy3A TSxezU8s=
X-Gm-Gg: AR+sD12LoPQq8WytgNSj3N9lSzigj0XTz25t6A73QOw0Ai8XQQREiD1mR47ZPRn2/Xq 1N4rv6HIpzOImrp1VdUggSYA9cJ/oKzsSJ4N9IG67J44D65FGyP+BCDFk/+4kYJ0tS4Yj7PLwtQ wdJeeRvTSmNVu+uO7Y6GrjP7JRw95bHIKCUjj23/DRZCyClV8J2d5Azp8Ej+d4PoW4+alQHDs+I gKhxTV4lTuf5tDj3xgvbJcTQ8JPoze0v6vDDpVatmoXFnQeectYs8jJrnvdHZbKl+su2gHPzxCn FW37UuIYYFbnOXUhADFcLBzwxUPIMPchd8B2DAEUBRKCLoEZ5BkXipRZDwqrJk6ZfCXrunMkJsa dknwFKcUE6b0YpwiK3f7J6fab8ofBuoh0tdIXiXqlFf6ZHojoIVYtlZcKK3PlfrVcHUnZBsm903 VlSXc/qWRGgyw/NaY0SjhRyZQGcD1I/WUeheWv/Bk2qhq+dT2mlMe+zXOsJ6YM+HZitdH5m5mFH vaSyNctkw==
X-Received: by 2002:a05:622a:1445:b0:528:3471:9390 with SMTP id d75a77b69052e-52d8535dc23mr69189591cf.10.1786725376628; Fri, 14 Aug 2026 09:36:16 -0700 (PDT)
Received: from smtpclient.apple ([130.41.36.144]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d8406f4e8sm25281511cf.22.2026.08.14.09.36.15 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 14 Aug 2026 09:36:16 -0700 (PDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.700.51.1.1\))
From: Roy Arends <roy@dnss.ec>
In-Reply-To: <m1wun5n-0000MtC@stereo.hq.phicoh.net>
Date: Fri, 14 Aug 2026 17:35:51 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <3BB93087-2B8C-4CCC-8432-0E9653F8BA0D@dnss.ec>
References: <m1wun5n-0000MtC@stereo.hq.phicoh.net>
To: Philip Homburg <pch-dnsop-7@u-1.phicoh.com>
X-Mailer: Apple Mail (2.3864.700.51.1.1)
Message-ID-Hash: T7Y4ZKTJOHHSUVNCBFSGG25U3B3F4XCB
X-Message-ID-Hash: T7Y4ZKTJOHHSUVNCBFSGG25U3B3F4XCB
X-MailFrom: roy@dnss.ec
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dnsop@ietf.org, dnsop-chairs@ietf.org, draft-huque-dnsop-multi-alg-rules@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Call for adoption: draft-huque-dnsop-multi-alg-rules-08 (Ends 2026-08-31)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/TCGiCfpvzJR-ijP_dXRbBSUiFdw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
> On 14 Aug 2026, at 09:16, Philip Homburg <pch-dnsop-7@u-1.phicoh.com> wrote: > >> This message starts a >> dnsop WG Call for Adoption of: draft-huque-dnsop-multi-alg-rules-08 >> >> This Working Group Call for Adoption ends on 2026-08-31 >> >> Abstract: >> This document restates the requirements on DNSSEC signing and >> validation and makes small adjustments in order to allow for >> more flexible handling of configurations that advertise multiple >> Secure Entry Points (SEP) with different signing algorithms via >> their DS record or trust anchor set. The adjusted rules allow >> both for multi- signer operation and for the transfer of signed >> DNS zones between providers, where the providers support disjoint >> DNSSEC algorithm sets. In addition, the proposal enables >> pre-publication of a trust anchor in preparation for an algorithm >> rollover, such as of the root zone. >> >> This document updates RFCs 4035 and 6840. >> >> Please reply to this message and indicate whether or not you support >> adoption of this Internet-Draft by the dnsop WG. Comments to explain >> your preference are greatly appreciated. Please reply to all >> recipients of this message and include this message in your response. > > I support adoption. As the abstract outlines, this is important to simplify > DNSSEC operation in quite a few cases. > > An issue that may need to be addressed is the desire to strictly prefer > PQC algorithms over traditional ones. That may conflict with the concepts > used in this draft. It would be nice to deal with that in this draft > though it could be addressed later when we create standards for PQC. I’m a bit wary of the desire to strictly require one algorithm over another when both are present, and I’d like to point to the issues we have had when a set of DS records is present and one uses SHA-256. This has led to a number of problems. Another issue is that while PQC algorithms are designed to address the threat posed by quantum computers, they are not necessarily better or more secure in other respects. PQC algorithms are relatively new. Rainbow, for example, was one of three digital-signature finalists in the third round of the NIST PQC process, but was subsequently subject to a classical attack that allowed private-key recovery for its category-1 parameters in a little over two days on a single laptop. GeMSS, a third-round alternate signature candidate, similarly suffered an attack that dramatically reduced its security and led to its elimination from consideration. There was SIKE as well, with a pretty novel kind of classical attack. I therefore don’t think we should introduce a generic preference for PQC algorithms in this draft. We have a process in RFC9904 for introducing new and deprecating old algorithms. Warmly, Roy
- [DNSOP] Call for adoption: draft-huque-dnsop-mult… Benno Overeinder via Datatracker
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Shumon Huque
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Paul Wouters
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Loganaden Velvindron
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Ralf Weber
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Philip Homburg
- [DNSOP] Local validation policy to require valid … Joe Abley
- [DNSOP] Re: Local validation policy to require va… Carlos Horowicz
- [DNSOP] Re: Local validation policy to require va… Joe Abley
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Christian Elmerot
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Roy Arends
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Philip Homburg
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Roy Arends
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Shumon Huque
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Roy Arends
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Mark Andrews
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Philip Homburg
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Michael Richardson
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Philip Homburg
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Libor Peltan
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Paul Hoffman
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Philip Homburg
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Joe Abley
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Philip Homburg
- [DNSOP] Re: [Ext] Call for adoption: draft-huque-… Joe Abley
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Johan Stenstam
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Stefan Ubbink
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Russ Housley
- [DNSOP] Re: Call for adoption: draft-huque-dnsop-… Benno Overeinder