[openpgp] Re: Size of ML-DSA Secret key in draft-ietf-openpg p-pqc and other considerations

Aron Wussler <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <JkepzmzcmQkQG27FTCvZmK01mF5uCfVcT-ZW3s-G3JeFi9q8RwULq7jO0URpSnMT2ibD_E-QOmVJOV_VKxC0K3NwZEdXVmvGa9BkJBZH4xs=@wussler.it>
Hello,

I personally believe that it's either a hard failure or it doesn't really matter.

We can have some recommended hashes, but if on the verifying end all get accepted, then it's not a security improvement.

Regarding the table I proposed in the PR, I am not really a fan of it, and believe we could just remove it and replace it with a guidance sentence:

```
In order not to extend the attack surface, composite ML-DSA + EdDSA signatures SHOULD use SHA3 for the signature data digest because ML-DSA internally uses a SHAKE256 digest.
Implementations MAY allow use of SHA2 for CNSA 2.0 compliance.
```

(Added this as a comment in the PR too)

Cheers,
Aron

--
Aron Wussler
Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930



On Tuesday, 11 February 2025 at 09:52, Daniel Huigens <[email protected]> wrote:

> On Tuesday, February 11th, 2025 at 09:11, Johannes Roth wrote:
> 

> > can't we keep SHA3 as well, meaning we allow both a SHA3 and a SHA2
> > variant? The user / policy can then decide what to use.
> 

> 

> Yeah, I would even say something like; we SHOULD use SHA3 to match
> the security of the signing algorithm, but MAY use SHA2 if needed
> for CNSA compliance.
> 

> Maybe this can be accomplished by keeping the existing text and
> table and just changing the MUST to a SHOULD, and then either
> adding some text or an additional column for the fallback option?
> 

> Best,
> Daniel
> 

> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wrsEARYKAG0FgmersEgJkH5nYVY+/jkwRRQAAAAAABwAIHNhbHRAbm90YXRp
b25zLm9wZW5wZ3Bqcy5vcmcJA3PzhP7TM7Po2Z+FUkMTjP0NX6rjU8ZS7lkd
rbQN5xYhBIuVslFfa7tqthSdVX5nYVY+/jkwAACkrQEAgKUoyWwuGbsf1Sea
OSjjeDhPc5RmgHRO6a9VtD3NitUA/AjbnklcPWhluJjG5eQUQ4VMONxJel1c
R/c1LnHnS2wI
=Jexl
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.