[openpgp] Re: Size of ML-DSA Secret key in draft-ietf-openpg p-pqc and other considerations
Simo Sorce <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
On Tue, 2025-02-11 at 09:10 +0000, Andrew Gallagher wrote: > On 11 Feb 2025, at 08:52, Daniel Huigens <[email protected]> wrote: > > > > Yeah, I would even say something like; we SHOULD use SHA3 to match > > the security of the signing algorithm, but MAY use SHA2 if needed > > for CNSA compliance. > > Won’t CNSA also require sha2 for the signing algorithm? In which case just saying that the algorithms SHOULD match might be sufficient? CNSA allows SHA3/SHAKE for "internal" use by signing algorithms and only require SHA2 for other uses, including content digesting, don't ask me why this makes sense. Simo. -- Simo Sorce Distinguished Engineer RHEL Crypto Team Red Hat, Inc _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]