ML-DSA-44 DNSSEC test zones
These zones test resolver support for DNSSEC signatures with
ML-DSA-44, the post-quantum signature scheme, using
DNSSEC algorithm number 18, as specified in
draft-westerbaan-dnssec-mldsa.
- only.alg18.westerbaan.name
- Signed only with ML-DSA-44 (alg 18). Secure for resolvers that support
it; insecure (unknown algorithm) for the rest.
- dual.alg18.westerbaan.name
- Dual-signed with ML-DSA-44 (alg 18) and ECDSAP256SHA256 (alg 13).
Validates everywhere.
- downgrade.alg18.westerbaan.name
- DS and DNSKEY records announce algorithms 18 and 13, but the alg 18
RRSIGs are deliberately stripped: only alg 13 signatures are served. Tests
whether ML-DSA-44-capable validators implement the
algorithm-downgrade
protection suggested in the draft (if they do, this zone is bogus for
them).
Try, e.g.: dig +dnssec only.alg18.westerbaan.name A