Hi, How about including the PQC public key as another info in the header and only store its SHA3 in a TXT record? SHA3 is, as of now, quantum-safe.
Regards Alex ---------------------------------------- Von: John Levine <[email protected]> An: [email protected] Kopie: [email protected] Datum: 21.06.2026 03:41:42 Betreff: [Ietf-dkim] Re: PQC Threat Model statement > It appears that Stephen Farrell <[email protected]> said: >> -=-=-=-=-=- >> -=-=-=-=-=- >> >> Hiya, >> >> I don't think the DKIM WG really needs to ask this question. ISTM, >> the answer is relatively obvious: recommend signing with both a >> current alg (e.g. RSA/eddsa) and ML-DSA. > > Is ML-DSA-44 good enough or do we need ML-DSA-65? > > Even ML-DSA-44 has a 1312 octet key which is 1750 base64 characters. > That will force TCP DNS queries and will cause provisioning pain since > a lot of the DNS provisioning crudware deals poorly with TXT records > that have more than one 255 byte string. > > IIN put both the key and the signature in the message, with a hash of the key > in > the DNS record. Would that still work for a PQ scheme? I gather Cisco had a > patent on that but I belive it's expired or will expire shortly. > >> Perhaps the more interesting question is how to convince the many >> domains that haven't changed their DKIM signing key in years, to >> start using DKIM2 and adding a 2nd ML-DSA sig. > > I expect it'll be when they get orders from above to use it. We > are designing it so you can put two signatures in a single DKIM2-Signature > header so if people can publish the keys, dual signing is OK. > > R's, > John > > _______________________________________________ > Ietf-dkim mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
