[openpgp] Re: ML-KEM and ML-DSA secret key format

Daniel Huigens <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <dyqPyn1cRMvwM3rEiTJjgrPDFCQYaiJx9j9cP4NCpUB-9SxCXLvx2hMP3qOI4BkC-fAJVYp7BRBquo2so7eNkuj-nPcBpKdBNba31Oy9YqE=@protonmail.com>
Hi Michael,

I agree with most of what you wrote, but I don't think any of it
implies that we need to wait for the decision in LAMPS or base
our own decision (for the OpenPGP wire format) on it (if you even
meant to imply that, perhaps you didn't).

If we mainly care about importing an OpenPGP key to an HSM, then
storing the key as a seed up until that point is most convenient
as you can go from a seed to an expanded key but not the other way
around. So even if the HSM vendor decides not to support seeds in
any way, we could convert the seed to an expanded key in software
and then import that in whichever format the HSM vendors like
(without specifying an OpenPGP-specific wire format for it).

If we care about moving keys between HSMs, that can happen again
in some format decided on by the HSM vendors and doesn't need to be
specified by OpenPGP, specifically.

It's only if we care about exporting an HSM key to a "software-backed"
OpenPGP key that supporting an expanded key wire format could make
sense, but IMHO this is not a use case that we should want to support.

Best,
Daniel


On Friday, February 28th, 2025 at 20:08, Michael Richardson wrote:
> The reason why the PKCS8 discussion in LAMPS is relevant to OPENPGP is
> because one can hope that there will be support in OPENPGP products for
> smaller/personal HSMs (USB tokens). The tokens might get used with a variety
> of protocols.
> 
> Today, signing of software is largely a PGP thing not an S/MIME thing.
> (It's different in the MS-MSI space)
> Particularly when it comes to signing git commits.
> 
> My opinion is that there are very few situations where it's better to move a
> private key rather than just have two or more signing keys be validated.
> At least -- in an PKIX situation with a certification authority.
> I think that YUM, and APT based systems can now specify a PGP keyring for
> each source, and a signature from any key in that keyring is valid.
> (And we've finally moved beyond mixing all the keys up for the different
> sources)
> 
> Having a way to backup a private key from one token to another one seems
> (rather than generating a new key) might be operationally important for in
> the software signing space.
> I don't think the same considerations apply to individual use personal keys.
> 
> I also think that OPENPGP key format allows us to have multiple private keys
> attached to a single identity, and for those keys to reside on distinct
> tokens. I admit that I've never tried this, but I ought to already.
> 
> 
> --
> Michael Richardson [email protected] . o O ( IPv6 IøT consulting )
> 
> Sandelman Software Works Inc, Ottawa and Worldwide
> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.