[openpgp] Re: WGLC for draft-ietf-openpgp-pqc [was: Re : I-D Action: draft-ietf-openpgp-pqc-08.txt]
Heiko Schäfer <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hello dkg, list, On 4/15/25 6:41 PM, Daniel Kahn Gillmor wrote: > If you are implementing this draft, please report back here! Apologies as well from me for the late reply. rPGP implements draft-ietf-openpgp-pqc-08. The implementation can be observed in the interoperability test suite: An experimental version of rsop with pqc support is currently listed as "rpgpie 0.6.0+pqc". I found the draft pleasantly clear, concise and well-structured (however, I'll note that I'm not a cryptographer, and can't judge the draft's finer points from that angle). The paragraph that outlines the structure of OpenPGP certificates didn't seem ideal to me. I try to offer a clarification in #182, but fear I didn't succeed in improving the text overall. If others feel that improving this paragraph is a worthwhile goal, I'd be happy to collaborate and iterate until we find a change that is both easy to read and clarifies the structure of certificates. As Daniel Huigens pointed out yesterday, I also think that section 8.3 should mention the possibility of adding a PQC encryption subkey to a v4 key. Finally, regarding encryption subkey selection, of course rpgpie's current approach (encrypting to all valid subkeys) is not achieving PQ security when valid pre-PQC encryption subkeys are present. It would be nice if we could agree on good guidance for encryption subkey selection in this draft. However, I worry that attempting to clarify this point might delay publication for an excessive amount of time. Thus, my current (weak) preference would be to keep encryption subkey selection out of draft-ietf-openpgp-pqc and handle it separately. I'll note that while this is not ideal for all scenarios, migrating to post quantum encryption is possible without further clarifying subkey selection, as follows: 1. Adding a PQC subkey 2. Observing that this subkey is being (either exclusively or additionally) encrypted to by all relevant peers, and then 3. Decomissioning any pre-PQC encryption subkeys (by expiration or revocation). To be clear, if consensus for concrete guidance (e.g. Daniel Huigen's suggestion from ~21 hours ago) emerges, I'd be happy to see it integrated into draft-ietf-openpgp-pqc. But I'd much prefer to see this document completed without such guidance than to see it stuck for an indefinite period. Thanks, :) Heiko _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]