[openpgp] Re: I-D Action: draft-ietf-openpgp-pqc-08.txt

Aron Wussler <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <LSicuu3DyGQdz5FlANti-HGJ6GuAucc5BKufbsCa603EsSZ0q1XMXYvt_OubLd0UQkg0gh2F--9y9WpoqWfQu5XU-KEcJ15GG66cSFk9ByU=@wussler.it>
Hi everyone,

At the OpenPGP Email Summit we discussed the PQC draft, and noticed that many are waiting on us to publish the latest state.

We took action, and here's the latest version with all the changes we discussed at the recent meetings:
- Assigned code points 35 and 36 for ML-KEM + ECDH algorithms: as discussed at the interim meeting and IETF 122
- Removed hash binding for ML-DSA + EdDSA and SLH-DSA algorithms: as discussed on the list, we allow signatures to offer a SHA-2 prehash to remove a blocker for CNSA 2.0 compliance
- Allowed usage of ML-KEM-768 + X25519 with v4 keys: as discussed at the OpenPGP summit, we decided to allow for a pq-upgrade path without rotating the primary key
- Aligned KEM combiner to X-Wing and switched to suffix-free encoding of the domain separator: as presented at IETF 122 to further align with LAMPS

Cheers,
Aron

--
Aron Wussler
Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930



On Tuesday, 15 April 2025 at 10:42, [email protected] <[email protected]> wrote:

> Internet-Draft draft-ietf-openpgp-pqc-08.txt is now available. It is a work
> item of the Open Specification for Pretty Good Privacy (OPENPGP) WG of the
> IETF.
> 

> Title: Post-Quantum Cryptography in OpenPGP
> Authors: Stavros Kousidis
> Johannes Roth
> Falko Strenzke
> Aron Wussler
> Name: draft-ietf-openpgp-pqc-08.txt
> Pages: 268
> Dates: 2025-04-15
> 

> Abstract:
> 

> This document defines a post-quantum public-key algorithm extension
> for the OpenPGP protocol. Given the generally assumed threat of a
> cryptographically relevant quantum computer, this extension provides
> a basis for long-term secure OpenPGP signatures and ciphertexts.
> Specifically, it defines composite public-key encryption based on ML-
> KEM (formerly CRYSTALS-Kyber), composite public-key signatures based
> on ML-DSA (formerly CRYSTALS-Dilithium), both in combination with
> elliptic curve cryptography, and SLH-DSA (formerly SPHINCS+) as a
> standalone public key signature scheme.
> 

> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/
> 

> There is also an HTML version available at:
> https://www.ietf.org/archive/id/draft-ietf-openpgp-pqc-08.html
> 

> A diff from the previous version is available at:
> https://author-tools.ietf.org/iddiff?url2=draft-ietf-openpgp-pqc-08
> 

> Internet-Drafts are also available by rsync at:
> rsync.ietf.org::internet-drafts
> 

> 

> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wrsEARYKAG0Fgmf+H5IJkH5nYVY+/jkwRRQAAAAAABwAIHNhbHRAbm90YXRp
b25zLm9wZW5wZ3Bqcy5vcmceM1D4a4QumYxSZIQ/QkMv7ZVUrxuKqyy7KxVD
6RfykRYhBIuVslFfa7tqthSdVX5nYVY+/jkwAAAv6wEA3QonlVJIbgo7n0pn
/ckPk1vl0N2LFrUb8cyL1U3AMoQBANnJamVewcRCc9NU6kTrU0GDFe789Cr8
78Ua06q3uK4K
=2Eer
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.