Post Quantum for DNSSEC
Today’s widely used DNSSEC signatures rely on mathematics that a sufficiently capable quantum computer could break. The timing of that capability remains uncertain, but changing the cryptography of a global, interconnected service takes preparation. Post Quantum DNSSEC applies signature algorithms designed to resist both classical and quantum attacks while retaining DNSSEC’s signing and validation model.
In 2024, we published a Post Quantum Crypto in PowerDNS field study, for which we are grateful to our guest posters and researchers. That research compared several Post Quantum Crypto algorithms for use in DNSSEC, with PowerDNS. One of those algorithms, Dilithium, was standardised by FIPS as FIPS 204, Module-Lattice-Based Digital Signature Standard (ML-DSA in short) in 2024. ML-DSA uses mathematical problems involving lattices that are believed to remain difficult for quantum computers. It runs on conventional hardware, which means no quantum technology is required to use it. Earlier this year, engineers from Cloudflare and Google wrote down how to apply ML-DSA (specifically, ML-DSA-44) to DNSSEC signing and validation.
In August, IANA assigned algorithm number 18 to the proposal, allowing deployment on the public Internet, and not just in labs. PowerDNS now supports ML-DSA-44 and ships an implementation, based on OpenSSL 3.5 or newer. OpenSSL 3.5 is present in a surprising number of Linux distribution releases already, which means ML-DSA-44 can be used on Enterprise Linux distributions 9 or higher, Ubuntu 26.04, and Debian 13.
This means that if and when the Quantum Apocalypse comes, PowerDNS users have a path forward by switching their signers over to ML-DSA-44. Meanwhile their validators already support it. (ML-DSA-44 signing support will be released with PowerDNS Authoritative Server 5.2, and validation with Recursor 5.5, both expected later this year. Development snapshots have supported ML-DSA-44 since the middle of August.)
Users need not fear ending up alone on a Post Quantum safe island. Cloudflare already deployed validation support for ML-DSA-44 and we trust Google and Quad9 (which, in part, runs on PowerDNS Recursor and DNSdist) will not be far behind.
Post Quantum for encrypted transports
DNSdist is the encrypted DNS frontend of choice for many deployments around the world, using DoT, DoH, DoH/3, and DoQ . These transports currently tend to rely on Elliptic Curve cryptography for protection, which is not safe against the presumed crypto breaking capabilities of quantum computers in years to come.
The good news is that on those systems where we were able to ship ML-DSA-44 for DNSSEC (i.e. systems that have OpenSSL 3.5 or higher), Post Quantum key exchange based on the same cryptographic primitives (ML-KEM) just works, as do ML-DSA-44 certificates (after being generated by the administrator).
Further development
The bigger signatures that ML-DSA-44 brings will put some additional TCP pressure on our software and your deployments. We continue to invest in improving performance for this new world where UDP may no longer be the norm for most of your DNS traffic.
ML-DSA-44 may only be the first step towards Post Quantum readiness in DNSSEC. Verisign's Merkle Tree Ladder proposal aims to significantly reduce the number of signatures that need to be generated, stored, transferred and verified, but it comes with some complexity. Other algorithms than ML-DSA-44, with different tradeoffs in size, speed, and security, may still become viable. Cloudflare has written a great overview of why ML-DSA is the right choice today, and what may yet come. If a fixed-point version of FN-DSA with good security guarantees comes out at some point, that might reduce our newfound reliance on TCP.
PowerDNS is giving DNS operators a practical way to prepare for Post Quantum cryptography. With ML-DSA-44 integrated into PowerDNS Authoritative Server and PowerDNS Recursor, and DNSdist providing encrypted DNS frontends, customers and community users can begin evaluating the DNSSEC signing and validation transition across their DNS infrastructure. We are also following further developments with great interest, and we we are committed to implementing what makes sense for the Internet and our users. Reach out to us if you would like to learn more about Post Quantum DNSSEC in our products.
