Mahdi RajaeeJournal
Back to the journalSecurity

1.1.1.1 now validates post-quantum DNSSEC

1.1.1.1 enabled DNSSEC validation for ML-DSA-44 (IANA algorithm 18).

The change

Previously

Resolvers validated only classical signature algorithms such as ECDSA and RSA.

With this change

ML-DSA-44 signatures are accepted, and a post-quantum DS record forces a post-quantum validation path.

What it means

Operators can publish ML-DSA-44 DS records to require a post-quantum validation path.

My take

Post-quantum DNSSEC is now a transport problem, not a cryptography problem.

At the source

1.1.1.1 now validates DNSSEC signatures created with ML-DSA-44

Cloudflareblog.cloudflare.com