[openpgp] Re: ML-KEM and ML-DSA secret key format
Aron Wussler <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <oa-f1kLfj5SY47NIE1x6kqQxWfe-oQZUOsKevSWMfmafdVuLPL06GEWJR9wIjny9tb6FuaGd98pTESiVGrHP2tzWTCYgg_chitIqcGF2Eks=@wussler.it> |
Hi Stephen, I personally think OpenPGP has a different usage and public than LAMPS, and while factoring their decisions does make a lot of sense, I would like to know if there is any strong usage requirement here. Many online tutorials explain how to import an existing OpenPGP key into an HSM, but haven't found much about exporting one, thus why I think that the "always being able to import" brings more value than "always being able to export". Said this, I might be living in my own bubble, know little about OpenPGP for software signing, and would like to explore the requirements on the list! Cheers, Aron -- Aron Wussler Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930 On Wednesday, 26 February 2025 at 14:31, Stephen Farrell <[email protected]> wrote: > Hi Aron, > > I've been watching the LAMPS discussion on this, but not reading > it in detail (too many mails/options;-). Shouldn't we wait until > LAMPS has reached a rough consensus on the topic before we make > a change? We might or might not want to land in the same place, > but it'd seem odd if we don't factor their conclusions into our > discussion, and they don't yet seem to have reached a conclusion. > (Or did I miss that?) > > Thanks, > S. > > On 26/02/2025 11:51, Aron Wussler wrote: > > > Hi everyone, > > > > At the interim meeting on February 10 we discussed the ML-KEM and ML-DSA secret key format, stating we'd prefer to keep the seed format even though LAMPS is reconsidering this choice because of HSM manufacturers. > > We gave it another thought, and we'd like to collect more explicit consensus on this point, also considered Simo's thread on the list [1] that opened right after the interim. > > > > We would like to consider the following two options: > > > > ## Keeping the seed format only > > This is the status quo in the specification. > > - It makes it very hard to introduce a different SK format in the future, because we only use fixed length. It could be somehow inferred from the packet length, but it would be astonishingly hacky. > > - Importing keys into HSMs will always be possible (no matter if expanded or seed, if tooling is available) > > - Exporting keys from HSMs that support only expanded format will not produce a valid OpenPGP key (the key can't be rendered as the standard seed wire format, but they could be copied to a similar HSM) > > > > ## Allowing both seed and expanded format explicitly > > Proposed text: https://github.com/openpgp-pqc/draft-openpgp-pqc/pull/171 > > - It makes both formats possible, preferring seed format > > - Adds complexity and failure cases > > - Importing keys into HSMs will sometimes fail (HSM supports only seed, but key is expanded) > > - Exporting keys from HSMs will always result in a valid wire format > > - Not all current crypto libraries accept the expanded format (one of the reasons why it's optional in the proposed spec) > > > > We have considered the option of adding a "version" or "type" byte that leaves the door open for a future standardization of another secret key format without doing it directly now, but I see only disadvantages in this: > > - If we never use it, it's a useless byte and additional failure case (unknown value) > > - If anyone ends up using it, it will bring all the complexity as defining two formats now, plus the chance of having little to no specification or guidance > > > > For reference, this is tracked in this issue: https://github.com/openpgp-pqc/draft-openpgp-pqc/issues/169 > > > > Please provide feedback in the next two weeks (until the start of IETF 122 on Sat 15.03). > > > > Cheers, > > Aron > > > > [1] https://mailarchive.ietf.org/arch/msg/openpgp/wborm6DvCotyZPzs-kPdyXPtoS0/ > > > > -- > > Aron Wussler > > Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930 > > > > _______________________________________________ > > openpgp mailing list -- [email protected] > > To unsubscribe send an email to [email protected] > > > _______________________________________________ > openpgp mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE----- Version: ProtonMail wrsEARYKAG0Fgme/Gk8JkH5nYVY+/jkwRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmd4ruq+pgfmZ710FNkIh31zMMlB4ikT20cQOhn4 C4GHsBYhBIuVslFfa7tqthSdVX5nYVY+/jkwAAANVAEA6di0XBGOxuU/3y7K JYbhpRCBgUrV3Lc3scQglbAUst0A/3WH7IhWqw+9Wr6juCeyGLiH/eKwGFDQ lg3QNIr14B4C =vhek -----END PGP SIGNATURE-----