Cloudflare Enables Post‑Quantum DNSSEC Validation on 1.1.1.1 Resolver
What Happened — Cloudflare announced that its public DNS resolver 1.1.1.1 now validates DNSSEC signatures generated with the NIST‑standardized post‑quantum algorithm ML‑DSA‑44 (2,420‑byte signatures). This is the first large‑scale deployment of a post‑quantum signature scheme for DNSSEC, intended to test transport of oversized responses and to prevent fallback to legacy algorithms.
Why It Matters for Trust & Control Assurance
- Demonstrates a concrete implementation of the cryptographic algorithm agility control objective—organizations can now evidence that they are preparing for future quantum threats.
- Provides continuous, observable proof that DNSSEC can be hardened without breaking compatibility, supporting audit‑ready documentation of a resilient cryptographic posture.
- Aligns with the Control Mapping capability: mapping emerging algorithm requirements to existing framework controls and collecting verifiable evidence for regulators or auditors.
Who Is Affected
- ISPs, enterprises, and SaaS providers that rely on DNSSEC for authenticating DNS responses.
- Any organization that includes DNSSEC in its security architecture or compliance evidence (e.g., NIST CSF, ISO 27001).
Recommended Actions
- Review your DNSSEC deployment and verify support for algorithm agility controls.
- Document a migration roadmap that includes testing of post‑quantum signatures and fallback handling.
- Capture evidence of DNSSEC validation (e.g., resolver logs) for inclusion in your continuous control‑assurance repository.
Source: Cloudflare Security Blog
Technical Notes
- Algorithm: ML‑DSA‑44, a lattice‑based signature scheme with 2,420‑byte signatures.
- Challenge: DNS‑over‑UDP size limits; Cloudflare’s resolver now carries larger responses and enforces no downgrade to legacy signatures.
- Timeline: Full post‑quantum DNSSEC support targeted for 2029.
Source: Cloudflare Security Blog