On Mon, 5 Oct 2026, Wei Chuang wrote:
Just following up here. At the DKIM interim -05, PQC was discussed; the direction is to use a composite aka hybrid: ML-DSA-44 / Ed25519 to support PQC. This would apply only to DKIM2, skipping DKIM1. The belief is that the update could be done as small text additions to existing drafts rather than requiring a new internet-draft. Assuming that, we'll need new text for the draft-ietf-dkim-dkim2-spec and draft-ietf-dkim-dkim2-dns.
We heard that while that combo is the best guess at the moment for a PQ algorithm, it may not be in the future. So what's important is that we have at least two algorithms specified so we can test out key and algorithm rotation.
That reminds me, are we including RSA keys? The argument against was that ed25519 keys are better in every way, argument for was that there are a lot of published RSA keys people might want to keep using.
Regards, John Levine, [email protected], Taughannock Networks, Trumansburg NY Please consider the environment before reading this e-mail. https://jl.ly _______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
