It appears that Stephen Farrell  <[email protected]> said:
>-=-=-=-=-=-
>-=-=-=-=-=-
>
>Hiya,
>
>I don't think the DKIM WG really needs to ask this question. ISTM,
>the answer is relatively obvious: recommend signing with both a
>current alg (e.g. RSA/eddsa) and ML-DSA.

Is ML-DSA-44 good enough or do we need ML-DSA-65?

Even ML-DSA-44 has a 1312 octet key which is 1750 base64 characters.
That will force TCP DNS queries and will cause provisioning pain since
a lot of the DNS provisioning crudware deals poorly with TXT records
that have more than one 255 byte string.

IIN put both the key and the signature in the message, with a hash of the key in
the DNS record.  Would that still work for a PQ scheme?  I gather Cisco had a
patent on that but I belive it's expired or will expire shortly.

>Perhaps the more interesting question is how to convince the many
>domains that haven't changed their DKIM signing key in years, to
>start using DKIM2 and adding a 2nd ML-DSA sig.

I expect it'll be when they get orders from above to use it.  We
are designing it so you can put two signatures in a single DKIM2-Signature
header so if people can publish the keys, dual signing is OK.

R's,
John

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to