[openpgp] Re: Size of ML-DSA Secret key in draft-ietf-openpg p-pqc and other considerations
Aron Wussler <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <JkepzmzcmQkQG27FTCvZmK01mF5uCfVcT-ZW3s-G3JeFi9q8RwULq7jO0URpSnMT2ibD_E-QOmVJOV_VKxC0K3NwZEdXVmvGa9BkJBZH4xs=@wussler.it> |
Hello, I personally believe that it's either a hard failure or it doesn't really matter. We can have some recommended hashes, but if on the verifying end all get accepted, then it's not a security improvement. Regarding the table I proposed in the PR, I am not really a fan of it, and believe we could just remove it and replace it with a guidance sentence: ``` In order not to extend the attack surface, composite ML-DSA + EdDSA signatures SHOULD use SHA3 for the signature data digest because ML-DSA internally uses a SHAKE256 digest. Implementations MAY allow use of SHA2 for CNSA 2.0 compliance. ``` (Added this as a comment in the PR too) Cheers, Aron -- Aron Wussler Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930 On Tuesday, 11 February 2025 at 09:52, Daniel Huigens <[email protected]> wrote: > On Tuesday, February 11th, 2025 at 09:11, Johannes Roth wrote: > > > can't we keep SHA3 as well, meaning we allow both a SHA3 and a SHA2 > > variant? The user / policy can then decide what to use. > > > Yeah, I would even say something like; we SHOULD use SHA3 to match > the security of the signing algorithm, but MAY use SHA2 if needed > for CNSA compliance. > > Maybe this can be accomplished by keeping the existing text and > table and just changing the MUST to a SHOULD, and then either > adding some text or an additional column for the fallback option? > > Best, > Daniel > > _______________________________________________ > openpgp mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE----- Version: ProtonMail wrsEARYKAG0FgmersEgJkH5nYVY+/jkwRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmcJA3PzhP7TM7Po2Z+FUkMTjP0NX6rjU8ZS7lkd rbQN5xYhBIuVslFfa7tqthSdVX5nYVY+/jkwAACkrQEAgKUoyWwuGbsf1Sea OSjjeDhPc5RmgHRO6a9VtD3NitUA/AjbnklcPWhluJjG5eQUQ4VMONxJel1c R/c1LnHnS2wI =Jexl -----END PGP SIGNATURE-----