[DNSOP] Re: PQ DNSSEC?
Sophie Schmieg <sschmieg@google.com> Fri, 24 July 2026 09:48 UTC
Return-Path: <sschmieg@google.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8025911E071BD for <dnsop@mail2.ietf.org>; Fri, 24 Jul 2026 02:48:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784886497; bh=9JYRMOTXFcG14p0CHIRqQKtYOLno34pai70U6ThKpTQ=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=ellcy8dH8XVwN0jnKl1/peCLXknez7TwTHW/Q48gAPriHIWv3vhf4jTSusElSu1bQ 1dIjaRhuW/kp7L3PhOweuN9m3UviSf6ABI2AhJdewnAs0WtK8C4QU1UDVvakd/Pydb 7F35Dm04z1z7YaGmCI5Eo91Yn05i2IqZh3FWxBHk=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -17.6
X-Spam-Level:
X-Spam-Status: No, score=-17.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id M0yal0i9y_E5 for <dnsop@mail2.ietf.org>; Fri, 24 Jul 2026 02:48:16 -0700 (PDT)
Received: from mail-wm1-x32c.google.com (mail-wm1-x32c.google.com [IPv6:2a00:1450:4864:20::32c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 0168011E071A7 for <dnsop@ietf.org>; Fri, 24 Jul 2026 02:48:16 -0700 (PDT)
Received: by mail-wm1-x32c.google.com with SMTP id 5b1f17b1804b1-495509b08ebso22145e9.1 for <dnsop@ietf.org>; Fri, 24 Jul 2026 02:48:15 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784886495; cv=none; d=google.com; s=arc-20260327; b=OaWAiH/VaxaepJK6g/4gO/TEqO3E/72kB2TemwD0EXNSpVObhrU9HXpuPGAIUl1c4b o15IzWRsq3+UHNGSytG8/uxQnWrxQNPXTgHVr7cu77WBp3K+VCUSub2ljOWbCr2SmtOF 6HUi44lwM7VurNHmGwa5uIYEisz66d8CWYrS8gpwxhn7t4PqPlboE8FxZn33yMMY9DnP ijLVXzwOTJAKBPUMkhpmWMNuXAcTuRLWuhq5S0c6w3Q/8bBZfNQLaq1Zs51H61/cxSaq EkYo9JAoNAUbk1O1NA8/AiL0EiHsTZeTTND60dtItZuBB9XwN+xcqBU7KlDYgwn2wv/G z5tg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=X5qI1NpQCsTl3lNnmekCJ3lZSsTKa6A5Nhw8Tdcuxxw=; fh=qhX3zZSX0qtw6ecMRKUqjZ2wDBmGQ5Mw6cTm8OlYne4=; b=a0AMzk8FaK+jdThNzWJw8nDzwmrFOae5Qmfw8zB1wIrjCuJ8eJJxD02UoCAgf5qqnZ sbXXitS2xFhPUwiqom/iJrYzduRXSYOlwmKFDaq6oCqnRHPgxzQdyDT7tCW57Xyvqp+4 N9MBVmELj6bnpKlsoF/fV7wzfDL15AJESNiYSnUS7BMLhbMYGpQF/XUtGpvlCbHzu+FZ bfLuAm1FgjprjZc8C7cRzpfRzFe00TQWQGQBbj0EpS87T5AfO4In1IIxlltBHkQGjvfq bpn6fPN1s30XOE1iGTRMR0AslxAVZw359GP5SbaK+JGzWpSZkiGXwRQCfgxTMDmyvmTS 69Pg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784886495; x=1785491295; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=X5qI1NpQCsTl3lNnmekCJ3lZSsTKa6A5Nhw8Tdcuxxw=; b=IICaxuYc5Qd0U5NYvmiO8vL9klXXZ2t/OlG4DDukRHbs6ApuJldmPVPuMiYmNNHoHn d7HnZ+lLrWbIBPQMBzXOL5iUmHFy9gn7S6QNrzLMp3oMlTM7MXYs9mwBLvBfjSBqA3iL 4cgaxC3A5FltY1yzPyqDEhsfiE8eobAXutRaXEYRgklYu8oerovxrg1XiC3Z9Ngcjt8B SoGBAlvWC+aaMlBK3ICHoTPDBVaeK0q5la0JzQ3bOHXJEm4QGCBSs2Jlr0KWs6MzQhhB tKSOdsFpgkGrtyxZtSrsYEHwkhZEYuZ68+l43JAF9qhoSHAmSla5k2M2Iz/5zYq/uTmF j6ew==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784886495; x=1785491295; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=X5qI1NpQCsTl3lNnmekCJ3lZSsTKa6A5Nhw8Tdcuxxw=; b=DiJklz3Rqybm9+qKDQIvQeM8UfAHFx+aMnoT8JeN/P+cMgP6k+N2MuM1qAC3poa5al Yu7IccUOR/Y1aeemfpWwKWNURSTexn3FH27MhqukFXPB38VLonQD7kRQ3Zbu+pBNQs0L cF3bANWgYSUQTdXG002ajIxbYva0JS8QxhAL6vT9igkSRgjTTTs+I/TjFeH1zbj91cs7 svz8uyklATvqRaMYmyUZiarcYI9oITVsuHmZxYKB2G0G9+Sd/CroCBo2VYF2ELqNKScP kIx3nV2ts32E2mh8ivxAD4EZban5oQF+vqbwnQ3HUq0Lzk1OE98hQOrZFolUJuDvHaZr DQ4w==
X-Forwarded-Encrypted: i=1; AHgh+Rq4OXPHI0dp7EDay+BQcl7UlP+ls0iMPIbBeZK+Z0jW+DxrqxUFtmU356NyIvzBAKnfQyV8wQ==@ietf.org
X-Gm-Message-State: AOJu0YyOloEY8t2fU+2R2s5X2rzikqI9dd9/niXPfpDNclNOi6llG25L XAbQ6GtWycIo1bJwxp21NXgKBNXOrRStJeWl+oaYr7+rcSDJwXlvGQ+tV9QQemnYfety9Gtf9zR 0TcnCoBVBhp2S7YwSnC6DC/fIuB5Rlu0Jb1ClZ1WKPr8j+9HeyGWInsjS
X-Gm-Gg: AR+sD13JEtY4EDjBYA4VYQRWY4Iv47nDkSB8Nca1InvmY4GFA5yBLcRNTVp/BkISy/+ O5B4C9r25MZwGdNZIRQkvjeWQeBdrxtTyBuV7LfdgCBm0BCdQbSBBiaQX4Zp40qYAwaOBf3ZIHo lfygQ/niN3sxhcUCYodXO1YpwtoGzrkFHqAkqaWWRLNxElkknFz/UXec3/nkbdtUyN9SUXLmKsN yoAgqwhldwPxHIGc6QvWRdwZ1a9ta4NpO3Kozs/MlGhChjKpuBw2seL/G6yMuuUY1uJJf5Haq+m Q8ItyVW1oZwoAUpc8Tzw6AmlTiavlz5JuKELIrW0Xy75ZHeLvw==
X-Received: by 2002:a7b:c7d0:0:b0:495:4747:548b with SMTP id 5b1f17b1804b1-4957bc5f6ffmr1058375e9.0.1784886493890; Fri, 24 Jul 2026 02:48:13 -0700 (PDT)
MIME-Version: 1.0
References: <CAMjbhoWSTwExS1+gJkijLQxD+9koO7dtO=Cdf6DCem=MqKhK6g@mail.gmail.com> <CACsn0cn7=2cms=mx5VkTQiUWEsF7P5SHfAtEeX2a=zEqV0biDw@mail.gmail.com> <CAMjbhoV+tC1Mbfm=VjcRuz7g771mUoPpFgCNRsKrDMv1SPP4WA@mail.gmail.com>
In-Reply-To: <CAMjbhoV+tC1Mbfm=VjcRuz7g771mUoPpFgCNRsKrDMv1SPP4WA@mail.gmail.com>
From: Sophie Schmieg <sschmieg@google.com>
Date: Fri, 24 Jul 2026 11:48:02 +0200
X-Gm-Features: AUfX_mztTCizomALdDFpyJnUJn25452hDoRUU8mXepHW9paL8jfuieYBid9ao-c
Message-ID: <CAEEbLAY9v0-DgtvYCMXeyfECrrjzZUeQVGxB7mzJ9mb94-3R8Q@mail.gmail.com>
To: Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="0000000000006fee76065758452b"
Message-ID-Hash: CQLINKVKKSXQ2CPSZLLSXA2TZQNWXYSB
X-Message-ID-Hash: CQLINKVKKSXQ2CPSZLLSXA2TZQNWXYSB
X-MailFrom: sschmieg@google.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Watson Ladd <watsonbladd@gmail.com>, dnsop@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: PQ DNSSEC?
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/rczbGcPwu8a1af9zoHjZe6OxJDc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
In particular, it is hard to overstate the confidence gap cryptographers have between the lattice based schemes (sans HAWK) and the rest of PQ signature schemes (including HAWK). Pretty much any path to PQC DNSSEC before 2030 requires the use of ML-DSA in order to be secure, and any hope of having a solution before 2035 requires ML-DSA or FN-DSA, assuming SLH-DSA or FAEST are out of the question. Code based cryptography arguably comes somewhat close in confidence, but that family does not currently have any signature candidates. Unfortunately, this confidence is based on decades of existing research, and while the other schemes currently evaluated by NIST are interesting, we are at least a decade out from being able to trust them. On Fri, Jul 24, 2026 at 5:08 AM Bas Westerbaan <bas= 40cloudflare.com@dmarc.ietf.org> wrote: > > > On Mon, Jul 20, 2026 at 2:52 AM Watson Ladd <watsonbladd@gmail.com> wrote: > >> Since singing is designed to be offline, and verification doesn't >> actually matter, and size does, SQISign is the obvious choice. We know >> verification doesn't matter given people regularly turn it off rather >> than fail closed when verification is failing. >> > > Yesterday a new attack against SQIsign was published [1], and it was > acknowledged by the SQIsign designers [2]. It doesn't break SQIsign > completely, but it looks like they'll have to change parameters. It'll take > some time to figure out by how much. This attack is not a surprise: SQIsign > and the other appealing signature schemes in the on-ramp competition just > need more time for proper evaluation. > > Best, > > Bas > > > [1] https://eprint.iacr.org/2026/1486 > [2] > https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_etUqkBwAJ > _______________________________________________ > DNSOP mailing list -- dnsop@ietf.org > To unsubscribe send an email to dnsop-leave@ietf.org > -- Sophie Schmieg | Information Security Engineer | ISE Crypto | sschmieg@google.com
- [DNSOP] PQ DNSSEC? Bas Westerbaan
- [DNSOP] Re: PQ DNSSEC? Shumon Huque
- [DNSOP] Re: PQ DNSSEC? Sheth, Swapneel
- [DNSOP] Re: PQ DNSSEC? Shane Kerr
- [DNSOP] Re: PQ DNSSEC? Watson Ladd
- [DNSOP] Re: PQ DNSSEC? Paul Wouters
- [DNSOP] Re: PQ DNSSEC? Mukund Sivaraman
- [DNSOP] Re: PQ DNSSEC? Carlos Horowicz
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Mukund Sivaraman
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Frederico A C Neves
- [DNSOP] Re: PQ DNSSEC? Jim Reid
- [DNSOP] Re: PQ DNSSEC? Joe Abley
- [DNSOP] Re: PQ DNSSEC? Bas Westerbaan
- [DNSOP] Re: PQ DNSSEC? Sophie Schmieg
- [DNSOP] Re: PQ DNSSEC? Loganaden Velvindron
- [DNSOP] Re: PQ DNSSEC? Libor Peltan
- [DNSOP] Re: PQ DNSSEC? Joe Abley
- [DNSOP] Re: PQ DNSSEC? John Heidemann
- [DNSOP] Re: PQ DNSSEC? Havard Eidnes
- [DNSOP] Re: PQ DNSSEC? Shumon Huque
- [DNSOP] Re: PQ DNSSEC? Warren Kumari
- [DNSOP] Re: PQ DNSSEC? Wessels, Duane
- [DNSOP] Re: PQ DNSSEC? Tommy Jensen
- [DNSOP] Re: PQ DNSSEC? Stefan Ubbink
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Vicky Shrestha
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Philip Homburg
- [DNSOP] Re: PQ DNSSEC? Peter Thomassen
- [DNSOP] Re: PQ DNSSEC? Michael Richardson
- [DNSOP] Re: PQ DNSSEC? Vaibhav Bajpai