[openpgp] Re: WGLC for draft-ietf-openpgp-pqc [was: Re : I-D Action: draft-ietf-openpgp-pqc-08.txt]

Heiko Schäfer <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hello dkg, list,

On 4/15/25 6:41 PM, Daniel Kahn Gillmor wrote:
> If you are implementing this draft, please report back here!

Apologies as well from me for the late reply.

rPGP implements draft-ietf-openpgp-pqc-08. The implementation can be 
observed in the interoperability test suite: An experimental version of 
rsop with pqc support is currently listed as "rpgpie 0.6.0+pqc".

I found the draft pleasantly clear, concise and well-structured 
(however, I'll note that I'm not a cryptographer, and can't judge the 
draft's finer points from that angle).


The paragraph that outlines the structure of OpenPGP certificates didn't 
seem ideal to me. I try to offer a clarification in #182, but fear I 
didn't succeed in improving the text overall. If others feel that 
improving this paragraph is a worthwhile goal, I'd be happy to 
collaborate and iterate until we find a change that is both easy to read 
and clarifies the structure of certificates.

As Daniel Huigens pointed out yesterday, I also think that section 8.3 
should mention the possibility of adding a PQC encryption subkey to a v4 
key.


Finally, regarding encryption subkey selection, of course rpgpie's 
current approach (encrypting to all valid subkeys) is not achieving PQ 
security when valid pre-PQC encryption subkeys are present.

It would be nice if we could agree on good guidance for encryption 
subkey selection in this draft. However, I worry that attempting to 
clarify this point might delay publication for an excessive amount of time.
Thus, my current (weak) preference would be to keep encryption subkey 
selection out of draft-ietf-openpgp-pqc and handle it separately.

I'll note that while this is not ideal for all scenarios, migrating to 
post quantum encryption is possible without further clarifying subkey 
selection, as follows:

1. Adding a PQC subkey
2. Observing that this subkey is being (either exclusively or 
additionally) encrypted to by all relevant peers, and then
3. Decomissioning any pre-PQC encryption subkeys (by expiration or 
revocation).


To be clear, if consensus for concrete guidance (e.g. Daniel Huigen's 
suggestion from ~21 hours ago) emerges, I'd be happy to see it 
integrated into draft-ietf-openpgp-pqc. But I'd much prefer to see this 
document completed without such guidance than to see it stuck for an 
indefinite period.

Thanks,
:) Heiko

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.