Domain Name System Operations B. E. Westerbaan Internet-Draft Cloudflare Intended status: Standards Track S. Schmieg Expires: 23 January 2027 Google 22 July 2026 Module-Lattice Digital Signature Algorithm for DNSSEC draft-westerbaan-dnssec-mldsa-02 Abstract This document describes how to specify Module-Lattice-Based Digital Signature Algorithm (ML-DSA) keys and signatures in DNS Security (DNSSEC). It uses the ML-DSA-44 parameter set defined in FIPS 204. ML-DSA-44 is believed to be secure even against adversaries in possession of a cryptographically relevant quantum computer. About This Document This note is to be removed before publishing as an RFC. The latest revision of this draft can be found at https://bwesterb.github.io/draft-westerbaan-dnssec-mldsa/draft- westerbaan-dnssec-mldsa.html. Status information for this document may be found at https://datatracker.ietf.org/doc/draft-westerbaan- dnssec-mldsa/. Discussion of this document takes place on the Domain Name System Operations Working Group mailing list (mailto:dnsop@ietf.org), which is archived at https://mailarchive.ietf.org/arch/browse/dnsop/. Subscribe at https://www.ietf.org/mailman/listinfo/dnsop/. Source for this draft and an issue tracker can be found at https://github.com/bwesterb/draft-westerbaan-dnssec-mldsa. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Westerbaan & Schmieg Expires 23 January 2027 [Page 1] Internet-Draft ML-DSA for DNSSEC July 2026 Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 23 January 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2 2. Conventions and Definitions . . . . . . . . . . . . . . . . . 3 3. DNSKEY Resource Records . . . . . . . . . . . . . . . . . . . 3 4. RRSIG Resource Records . . . . . . . . . . . . . . . . . . . 3 5. Algorithm Number for DS, DNSKEY, and RRSIG Resource Records . . . . . . . . . . . . . . . . . . . . . . . . . 4 6. Examples . . . . . . . . . . . . . . . . . . . . . . . . . . 4 7. Security Considerations . . . . . . . . . . . . . . . . . . . 6 7.1. ML-DSA . . . . . . . . . . . . . . . . . . . . . . . . . 6 7.2. Downgrades . . . . . . . . . . . . . . . . . . . . . . . 7 8. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 7 9. References . . . . . . . . . . . . . . . . . . . . . . . . . 8 9.1. Normative References . . . . . . . . . . . . . . . . . . 8 9.2. Informative References . . . . . . . . . . . . . . . . . 8 Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . . . 9 Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . 9 1. Introduction DNSSEC, which is broadly defined in [RFC4033], [RFC4034], and [RFC4035], uses cryptographic keys and digital signatures to provide authentication of DNS data. Currently the most popular signature algorithms in use are RSA and the NIST-specified elliptic curve signature algorithm ECDSA [RFC6605]. Westerbaan & Schmieg Expires 23 January 2027 [Page 2] Internet-Draft ML-DSA for DNSSEC July 2026 All currently specified algorithms rely for their security on the hardness of the integer factorization problem or the (elliptic curve) discrete logarithm problem. A cryptographically relevant quantum computer when built would be able to solve both of these problems efficiently, and would therefore be able to forge DNSSEC signatures created with any of these algorithms. [FIPS204] specifies the Module-Lattice-Based Digital Signature Algorithm (ML-DSA), a signature scheme whose security is based on the hardness of lattice problems over module lattices. ML-DSA is believed to be secure even against adversaries in possession of a cryptographically relevant quantum computer. [FIPS204] defines three parameter sets: ML-DSA-44, ML-DSA-65, and ML-DSA-87. This document defines the use of DNSSEC's DS, DNSKEY, and RRSIG resource records (RRs) with the ML-DSA-44 parameter set. ML-DSA-44 targets NIST security category 2, which equates to 160 bits of security classical and post-quantum security. ML-DSA-44 has the smallest keys and signatures of the three ML-DSA parameter sets, which makes it the most suitable for use in the DNS. 2. Conventions and Definitions The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. 3. DNSKEY Resource Records An ML-DSA-44 public key consists of a 1312-octet value as produced by the key generation algorithm ML-DSA.KeyGen defined in Section 5.1 of [FIPS204]. It is encoded into the Public Key field of a DNSKEY resource record as a simple bit string, using the byte encoding of the public key described in Section 7.2 of [FIPS204]. 4. RRSIG Resource Records An ML-DSA-44 signature consists of a 2420-octet value as produced by the signing algorithm ML-DSA.Sign defined in Section 5.2 of [FIPS204]. It is encoded into the Signature field of an RRSIG resource record as a simple bit string, using the byte encoding of the signature described in Section 7.2 of [FIPS204]. Westerbaan & Schmieg Expires 23 January 2027 [Page 3] Internet-Draft ML-DSA for DNSSEC July 2026 Signatures are generated and verified using the "pure" ML-DSA variant (i.e., not the pre-hash variant HashML-DSA) with an empty context string (ctx of zero length), as described in Sections 5.2 and 5.3 of [FIPS204]. The message signed is the data to be signed as described in Section 3.1.8.1 of [RFC4034]. 5. Algorithm Number for DS, DNSKEY, and RRSIG Resource Records The algorithm number associated with the use of ML-DSA-44 in DS, DNSKEY, and RRSIG resource records is TBD1. This registration is fully defined in the IANA Considerations section. 6. Examples The following example, in the style of Section 6 of [RFC6605], shows an ML-DSA-44 DNSKEY, its corresponding DS record, and an RRSIG over an MX RRset. The key was generated deterministically from the 32-octet seed shown in the PrivateKey field, and the signature was produced using the deterministic variant of ML-DSA (rnd set to all zeroes) so that the example is byte-for-byte reproducible. Because of the size of ML-DSA-44 keys and signatures, the base64-encoded values are wrapped. | _Warning_: Test vectors provisionally use 18 for the algorithm | number. Will be updated with the number IANA allocates. Private-key-format: v1.3 Algorithm: 18 (MLDSA44) PrivateKey: AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8= example.com. 3600 IN DNSKEY 257 3 18 ( 17K0clSq4NtF55MNSpjSyX2PE5fReJ2voXAksxbpvslPyZRtQvGbeadBO7qj PnFJy0LtURVpOsBB+suYit61/g4dhjEYSZW1ksOX0ilOLhT5CqQUujgmiZrE P0zMrLwm6agyuVEY1ctDPL75ZgsAE44IF/YediyidMNq1VTrIqrBFi5KsBrL oeOMTv2PgLZbMz0PcuVd/nHOnB67mInnxWEGwP1zgDoq7P6v3teqPLLO2lTR K9jNNqeM+XWUO0er0l6ICsRS5XQu0ejRqCr6huWQx1jBWuTShA2SvKGlCQ9A SWWX/KfYuVE/GhvabpUKqpjeRnUH1KT1pPBZkhZYLDVy9i7aiQWrNYFnDEoC d3oz4Mpylf2PT/bRoKOnaD1l9fX3/GDaAj6CbF+SFEwC99G6EHWYdVPqk2f8 122ZC3+pnNRa/biDbUPkWfUYffBYR5cJoB6mg1k1+nBGCZDNPcG6QBupS6sd 3kGsZ6szGdysoGBI1MTu8n7hOpwX0FOPQw8tZC3CQVZg3niHfY2KvHJSOXjA QuQoX0MZhGxEEmJCl2hEwQ5Va6IVtacZ5Z0MayqW05hZBx/cws3nUkp77a5U 6FsxjoVOj+Ky8+36yXGRKCcKr9HlBEw6T9r9n/MfkHhLjo5FlhRKDa9YZRHT 2ZYrnqla8Ze05fxg8rHtFd46W+9fib3HnZEFHZsoFudPpUUx79wcvnTUSIV/ R2vNWPIcC2U7O3ak4HamVZowJxhVXMY/dIWaq6uSXwI4YcqM0Pe62yhx9n1V Mm10URNa1F9KG6aRGPuyyKMO7JOS7z+XcGbJrdXHEMxkexUU0hfZWMcBfD6Q /SDATmdLkEhuk3CjGgAdMvRzl55JBnSefkd/oLdFCPil8jeDErg8Jb04jKCw //dHi69CtxZn7arJfEaxKWQ+WG5bBVoMIRlG1PNuZ1vtWGD6BCoxXZgmFk1q kjfDWl+/SVSQpb1N8ki5XEqud4S2BWcxZqxCRbW0sIKgnpMj5i8geMW3Z4NE Westerbaan & Schmieg Expires 23 January 2027 [Page 4] Internet-Draft ML-DSA for DNSSEC July 2026 be/XNq06NwLUmwiYRJAKYYMzl7xEGbMNepegs4fBkRR0xNQbU+Mql3rLbw6n XbZbs55Z5wHnaVfe9vLURVnDGncSK1IE47XCGfFoixTtC8C4AbPm6C3NQ+nA 6fQXRM2YFb0byIINi7Ej8E+s0bG2hd1aKxuNu/PtkzZw8JWhgLTxktCLELj6 u9/MKyRRjjLuoKXgyQTKhEeACD87DNLQuLavZ7w1W5SUAl3HsKePqA46Lb/r UTKIUdYHgZjpSTZRrnh+wCUfkiujDp9R32Km1yeEzz3SBTkxdt+jJKUSvZSX CjbdNKUUqGeR8Os28BRbCatkZRtKAxOymWEaKhxIiRYnWYdooxFAYLpEQ0ht 9RUioc6IswmFwhb45u0XjdVnswSg1Mr7qIKig0LxepqiauWNtjAIPSw1j99W bD9dYqQoVnvJ6ozpXKoPNUdLC/qPM5olCrTfzyCDvo7vvBBV4Y/hU3DuyyYF Ztg/8GshGq7EPKKbVMzQD4gVokZe8LRlFcx+QfMSTwnv/3OTCatYspoUWaAL zlA46TjJZ49y6w5O5f2q5m2fhXP8l/xCtJWfS/i2HXhDPoawM11ukZHE2L9I ezkFwQjP1qwksM633LfPUfhNDtaHuV6uscUzwG8NlwI9kqcIJYN7Wbpst9Tl awqHwgOGKujzFbpZJejt76Z5NpoiAnZhUfFqll+fgeznbMBwtVhp5NuXhM8F yDCzJCyDEg== ) example.com. 3600 IN DS 59829 18 2 ( 812cb1a22af04380e2f72d91c06c14eb1a918cf30037a8a9c67497e9264b 4bfa ) example.com. 3600 IN MX 10 mail.example.com. example.com. 3600 IN RRSIG MX 18 2 3600 ( 1440021600 1438207200 59829 example.com. kdySHzwB7NftjQSAF7snCeKau3NoqpLNg16h/eHZV8L3Zpi30lkRyiS4FLMM ZqTjzbf1A/bShg4qZpYlnfqXN8uqFWF9GEEJOgte1CFdF4GC05gEBU88Kryf nGAcpXKafw9htDxZrqmqVSWN+1guW7HyUUFo1IuWTnZKuhZptDJkq+Ml+5ZH y4p+2Tdwk8MH7tJlTYk/UVaM1wIXPB2YgJ++kD0zhys5c38rztcaOmMXt6ej yAEY37Dc1Z/KsrRQZWv+XZ/CTliuh+dGJHoGuTm5KwS0us884ukWNC/wIU/S dlGoBDVXsT163Tr6lTf8pJ4xixcKIN8nsKSFxP9j+AbaN5SofIAvp4LGIFLg MKsRV/cqeYo8PegVD2EhAQ2/HVTO3uO8vlqLK7nWVVK2+2aYKIL2EqzjhRYK U5DhMwS9ZgbG0niszGXpvZcNcOyABXysdVuaDjnUuamYVACOUrV786LNmt8I WDnXWoPPMErPk5vNyHq6+ZHg79UeZpSzx0Ae/1aIfi2WEta9Or5sGItBn6vF Wi9kJRuhuoMIXf9CLBV/LHL/PIenBxXSnr2Owg54AuSN2tmk2lDy8BfKzzvx TOoKXx4edo96Xv6QWASAxO9JmyEvhnF3SBI6HG3fn2+k8rgJLIHpsr4pZhMh 4/SQWaojxt51nEIFi1bl7P6sAmCdMP81LSNx05hIkKcPeO33hA2VSDO7GzOE snBOzbhUX9gbFr3aNV/Wrbs/cZMAL1I0IKG20jkmEfZ9PeKN0hXCxHJo4hPF L2mm9ciGpuXS7oN8f7YublNTwRY8b4plScVICpyBT5UDOgezR9/+DnklL0fz IORMTRnpD1hq4BqZMgNMwvczFg3DrSLQP/cBiKLn3toJrkSuU9aXodEqW3lh RdMvDUqTtHgMKas5velmabpENAbixiB8n5zoENnMLV6w/13a+yOTT2WUvESg HqF92FfQMdQl36noyewmjUFZopirCGV6AkebdVsTY27DtYkGWamLXcm3w2d6 AYV/LssvyK/Jlnw/E7YRJWkO+8PvHA2tvfQSr8fNC4ll/KHdwr8d0Q8spPcO HMMui20XDYeprPmp64hSt4IBuiQusdm3SQsWjQvaUsg8sykZd24S/wNQiGsw XaoG6oWYYCZupfvGc0sgb+9qxZU5fSAYKwx5LjYajruvQ5flebAtrUdLuPbG Mb2I7Z8c4IvDmbA6ljqMK60w1XI+wU7jSWzoEaiIeAUR1aT925KFMEhmFG3k Tr5ZPI57wM7pEI9jBME80lu7D3f4z++icSHSJ5YNa/+kp7eSIT94m4Tj7nel mN0WnKFgzGZKnuiDGJew5FFnfB0qfvqUNUPt1rVaIr7rzBBL4j8WQHqOo17A +0pnIqKTe1Z8MxFnPwP1eWHa3T/7JeEPSD5JFOpEWxs12twxTC42BrTCckSm rfmksfxmJa0mfflaOPHkjahTprrItJzG1efHYCu5nP5rsclZF0hDOR1OZrgK 2IhnG1VotIPB4+/+70+uD0qcqY3L2yonxFlQS8sEmMcXi9xQTxdFG4NOk/TQ Westerbaan & Schmieg Expires 23 January 2027 [Page 5] Internet-Draft ML-DSA for DNSSEC July 2026 G50Oly1tRp9UoLjwTDtlIjh71Lz9lajbAabV4WtIvd7cwaREO0kFAtzIgfJR VMasWvUo6e93qQBThzvkCNs8ngsa0jXJL1HrERP+qkiULCDMr19FVimWmIzL CkR9pg9WWjruY5krgdVbINUqjsyyGriPEhy2JneNWdOdFoAwkWtGbIpQhHs2 bLHpG9xPPF+ElqLmjNa76BhXv4caurHYn7K0m4NMVgDywGXoh0OGe/PoXQ4g Ht7EbHgbCQO9V8+/1+MWw9ZrU6btOGJ2JVXeyRXYyJarn+cnPL1nWOlq7bMD 3mazOTNZPc5UENSvDL51hmd3WD71i2u9btqIzjnmSxggPHRsVcOaGXHM3aUJ nrDtwi1EY7THlJatS+ItjWQMCDh8g/4LF9S2UWGFc21MimswWvgh1jB/4hYI 9C8PSCpAeV26dXoANntR/lLms42488dVJ1wyNGjaNNX1itiqFYsNUn3LyT3T dVUgBwkfzO1I4UnhDIbsHJWbs7Dl/52Ei4MbpPJXnL1gMNc6SD1EkT1CeY9f esHF20wr8tb7V+qPO2TCE26syB9lZ41OSOYgqPYK/OHyoLedQmTOFls0QMj2 F0bks3pJm/TDDMEuUdhulPatnZBNIXexqNImQUFyipcJ9W5KnD6Wr5+jyULy VBQRpWPzipfPFACb5d5lWPtrvh4kurYt3sSdUy+WJKuYb1roxXTZJqP0QDgn VEYL5nJnxqSRD9fx7HMRHXODkVioBFmSUgwP5XBljn/YpIgG8Ix42hyKMCti yv1gIY3/m8cfHyj5I6xcDHUTZHyM9+KSZeipf6wUnngoZuYzP9N3Nozo8LI+ w3Mo6s/VjhmsALOYcus720s0MQY5prhkcZYUvgv9YL9R+1Fm7Kxy3cjpnGqy WwxN6YmNw/f6C+21Dlex7+09o2ygi0M1NEZZ0FhdaBmxVxtSjbBm3uKu9taW 0zO534HXlifFkxf6GhboxbGdm1yekVIjDLnC+iodQyLwIi0vvc435Xk4GRBs 8D5Pxf3vT3tgPy5sDXbJ3lT58MekKdT/HobugDOdu0ltGenFjnKFhdJudvQ/ FFjqJk1HYnjxxdP3QYKlSHOv2ADtRqgI0VHLJmECOifYr90uWml1uzaUzK0X Tulm8fn6lfpF3EWJYSsq1iXQWuiRw9u6dxiS02+c4Z8Nzumoh48W+z0GFy+q ClyhqdedA6k3WZIJi919e5b24mj5rqzcgrA6KMqnTJDKh2cuoKC1fI88w774 co0XPDyg+v/RD2ET1fquDGHjeVyVBsknNZQ5lwvLeAy/uH+Ql5qECQ9WCIJP ydZZhB906hkHZ+vch1fG+vhgMtoXhtZ4UXzQwbJBL/4wxtOau3IgWGkJEImJ PK3KE+7phfn5YmGSjVCp8o1t2QxpwJ1ZPBuTrUWy15gruIP8e415f0UPUZjF G+p6JqsUzaBzgZvAg9nY/vHEC0sXuC7lnqmDxr8LU9JMD77XrBccXMP199d/ 10bJW8TH+yzqE4syjdUPEalQnwP/fh9us92eSdv50vr0/KPhzfWzcRwWFxof S15zlJe3xNj+BAURHCApKjBkh5emuLy+w9zn6vn6/QsbXWp6hZWcoLO6ytLf 6/H+DhguNzs/VFVbg5SXo62wztPoAAAAAAAAAAAAAA0jNEY= ) 7. Security Considerations 7.1. ML-DSA The security considerations of [FIPS204] apply. In particular sections 3.4 and 3.6 of [FIPS204] discuss additional considerations for implementing ML-DSA, including guidance on the choice of hedged vs deterministic variants. These considerations apply when ML-DSA is used for DNSSEC and especially during online signing. Westerbaan & Schmieg Expires 23 January 2027 [Page 6] Internet-Draft ML-DSA for DNSSEC July 2026 7.2. Downgrades Section 5.11 of [RFC6840] recommends validators to accept any single valid path. Such lenient validators are vulnerable to a downgrade attack: if a zone is signed by ML-DSA-44 and a quantum-vulnerable algorithm, then a quantum attacker can strip the ML-DSA-44 signatures, and have the lenient validator accept the forged quantum- vulnerable signature. This does not apply if the validator does not accept any quantum- vulnerable algorithms or if the zone is only signed by ML-DSA-44. | _Note to editor_: remove this remark before publication. | Remark: Ideally we update RFC6840 in a different document to | recommend validators to insist on PQ RRSIGs if there there is a | DS that indicated they should be available. 8. IANA Considerations This document updates the IANA registry "Domain Name System Security (DNSSEC) Algorithm Numbers". The following entry is to be added to the registry: +=================================+=================+ | Field | Value | +=================================+=================+ | Number | TBD1 | +---------------------------------+-----------------+ | Description | ML-DSA-44 | +---------------------------------+-----------------+ | Mnemonic | MLDSA44 | +---------------------------------+-----------------+ | Zone Signing | Y | +---------------------------------+-----------------+ | Trans. Sec. | * | +---------------------------------+-----------------+ | Use for DNSSEC Signing | MAY | +---------------------------------+-----------------+ | Use for DNSSEC Validation | MAY | +---------------------------------+-----------------+ | Implement for DNSSEC Signing | MAY | +---------------------------------+-----------------+ | Implement for DNSSEC Validation | MAY | +---------------------------------+-----------------+ | Reference | (this document) | +---------------------------------+-----------------+ Table 1: New DNSSEC Algorithm Number entry Westerbaan & Schmieg Expires 23 January 2027 [Page 7] Internet-Draft ML-DSA for DNSSEC July 2026 * There has been no determination of standardization of the use of this algorithm with Transaction Security. 9. References 9.1. Normative References [FIPS204] National Institute of Standards and Technology (NIST), "Module-Lattice-Based Digital Signature Standard", FIPS PUB 204, August 2024, . [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, . [RFC4033] Arends, R., Austein, R., Larson, M., Massey, D., and S. Rose, "DNS Security Introduction and Requirements", RFC 4033, DOI 10.17487/RFC4033, March 2005, . [RFC4034] Arends, R., Austein, R., Larson, M., Massey, D., and S. Rose, "Resource Records for the DNS Security Extensions", RFC 4034, DOI 10.17487/RFC4034, March 2005, . [RFC4035] Arends, R., Austein, R., Larson, M., Massey, D., and S. Rose, "Protocol Modifications for the DNS Security Extensions", RFC 4035, DOI 10.17487/RFC4035, March 2005, . [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, . 9.2. Informative References [RFC6605] Hoffman, P. and W.C.A. Wijngaards, "Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC", RFC 6605, DOI 10.17487/RFC6605, April 2012, . [RFC6840] Weiler, S., Ed. and D. Blacka, Ed., "Clarifications and Implementation Notes for DNS Security (DNSSEC)", RFC 6840, DOI 10.17487/RFC6840, February 2013, . Westerbaan & Schmieg Expires 23 January 2027 [Page 8] Internet-Draft ML-DSA for DNSSEC July 2026 Acknowledgments TODO Authors' Addresses Bas Westerbaan Cloudflare Email: bas@cloudflare.com Sophie Schmieg Google Email: sschmieg@google.com Westerbaan & Schmieg Expires 23 January 2027 [Page 9]