Just following up here.  At the DKIM interim -05, PQC was discussed; the
direction is to use a composite aka hybrid: ML-DSA-44 / Ed25519 to support
PQC.  This would apply only to DKIM2, skipping DKIM1.  The belief is that
the update could be done as small text additions to existing drafts rather
than requiring a new internet-draft.  Assuming that, we'll need new text
for the draft-ietf-dkim-dkim2-spec and draft-ietf-dkim-dkim2-dns.
-Wei

On Tue, Sep 15, 2026 at 12:13 PM John Levine <[email protected]> wrote:

> It appears that Hannah Stern  <[email protected]> said:
> >-=-=-=-=-=-
> >
> >Hi!
> >
> >On 9/12/26 17:08, Wei Chuang wrote:
> >> It sounds like the algorithm advice is to use ML-DSA-44/65.  At this
> >> point, should someone just create an Internet-Draft to specify the PQC
> >> algorithm for use with DKIM and DKIM2 and post it to the list?
> >> -Wei
> >
> >I'd be strongly for standardizing only a hybrid, not a "pure" pqc
> >signature algorithm.
>
> I think that is a reasonable idea but if you've followed the s* show in the
> TLS working group, I also think we should wait a little while before doing
> so.
>
> Technically it's not hard, the keys and signatures are just concatenated
> copies
> of the key and signature for the two methods.
>
> R's,
> John
> _______________________________________________
> Ietf-dkim mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to