[openpgp] Re: Encryption subkey selection
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <Ef6BOqB4sJojhX8zVFA6lCxASrnsV1rG_bF85V4_YHy1SutHgh3BW5f2hTNppvMcUOpmjtcMCiEYVVkAxcMLDMYAiUm2v-MN6qHRvqYYS-M=@protonmail.com> |
Hi Falko, On Tuesday, May 6th, 2025 at 08:22, Falko Strenzke wrote: >> > > Preferring the higher algorithm ID doesn't work for a simple reason: there are different security levels for each algorithm stacked one after another as code points (2 for ML-KEM currently). This means that the suggested selection mechanism might result in the preference of strictly weaker keys. Saying that the proposal "doesn't work" is a very strong statement but what I think you mean is: it might lead to suboptimal outcomes in certain cases, namely if someone has a certificate with two encryption subkeys, one of which is 1. weaker and 2a. has a later creation timestamp or 2b. an equal creation timestamp and a higher algorithm ID. My question would be: why would the certificate holder want to create such a certificate? Do such certificates already exist in the wild? If we all agree on this encryption subkey selection algorithm, we can just agree to not do that, and give the stronger subkey a higher creation timestamp. Or, for future algorithms we can tweak the algorithm, if needed. I would also like to note that we don't achieve optimal outcomes in all cases in the current implementations. For example, two out of three implementations don't achieve post-quantum security for the PQC test vectors with multiple subkeys, as noted in the parallel thread. With this proposal, that would be fixed. So, I think it's strictly an improvement over the status quo :) Best, Daniel _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]