Hi,

How about including the PQC public key as another info in the header and only 
store its SHA3 in a TXT record? SHA3 is, as of now, quantum-safe.

Regards
Alex
----------------------------------------

Von: John Levine <[email protected]>
An: [email protected]
Kopie: [email protected]
Datum: 21.06.2026 03:41:42
Betreff: [Ietf-dkim] Re: PQC Threat Model statement

> It appears that Stephen Farrell  <[email protected]> said:
>> -=-=-=-=-=-
>> -=-=-=-=-=-
>> 
>> Hiya,
>> 
>> I don't think the DKIM WG really needs to ask this question. ISTM,
>> the answer is relatively obvious: recommend signing with both a
>> current alg (e.g. RSA/eddsa) and ML-DSA.
> 
> Is ML-DSA-44 good enough or do we need ML-DSA-65?
> 
> Even ML-DSA-44 has a 1312 octet key which is 1750 base64 characters.
> That will force TCP DNS queries and will cause provisioning pain since
> a lot of the DNS provisioning crudware deals poorly with TXT records
> that have more than one 255 byte string.
> 
> IIN put both the key and the signature in the message, with a hash of the key 
> in
> the DNS record.  Would that still work for a PQ scheme?  I gather Cisco had a
> patent on that but I belive it's expired or will expire shortly.
> 
>> Perhaps the more interesting question is how to convince the many
>> domains that haven't changed their DKIM signing key in years, to
>> start using DKIM2 and adding a 2nd ML-DSA sig.
> 
> I expect it'll be when they get orders from above to use it.  We
> are designing it so you can put two signatures in a single DKIM2-Signature
> header so if people can publish the keys, dual signing is OK.
> 
> R's,
> John
> 
> _______________________________________________
> Ietf-dkim mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to