[openpgp] Re: WGLC for draft-ietf-openpgp-pqc [was: Re : I-D Action: draft-ietf-openpgp-pqc-08.txt]
Aron Wussler <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <wdglinnIS2eRgDtdqE1SyvQDF76uTvkA6lPxPqU9xb7WhCUJBygr_4U_HjMjlWRX5441i47SmB1jByKhDonRG1nBpGqt0wzlHnmPlA3wSvQ=@wussler.it> |
Hi Heiko, > But I do wonder idly if it would be possible and useful to add some kind of informational text that clarifies that senders can consider encrypting only to PQ(/T) keys to achieve post-quantum security, when a sender encounters a case where it finds this possible. For now, we opted to just leave the following statement As explained in Section 1.4.2, the OpenPGP protocol inherently supports parallel encryption to different keys. Note that the confidentiality of a message is not post-quantum secure when encrypting to different keys if at least one key does not support PQ(/T) encryption schemes. While this provides no guidance, it is a straight fact about PQ(/T) encryption, and can be used to justify an implementation-specific policy decision (such as: if PQ is available for recipient X, then prefer PQ). After all the discussion among authors and the community, we decided that this was the only un-objectable statement we could include. > While this is somewhat arbitrary I don't think it's that arbitrary. If you generate PQ keys, it's because you want PQ-encrypted traffic. If not, stick to 32-byte ECC keys, faster and smaller ;) Cheers, Aron -- Aron Wussler Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930 On Friday, 9 May 2025 at 13:49, Heiko Schäfer <[email protected]> wrote: > Hello Aron, all, > > > > After gathering all the feedback, we decided to simplify the guidance, and consistently remove the remaining statements regarding sub-key selection. > > This is reflected in the editor copy [1]. > > > I agree with removing guidance, while consensus is clearly not in immediate reach. > > Thank you for diligently working towards getting this draft out the door soon! I look forward to seeing it finalized. > > > We thank the people involved in this discussion and ask them to review this change. > > > I'm happy with the draft, as is. But I do wonder idly if it would be possible and useful to add some kind of informational text that clarifies that senders can consider encrypting only to PQ(/T) keys to achieve post-quantum security, when a sender encounters a case where it finds this possible. > > Just to state, in the most general of terms, that senders *can* apply such policy decisions, and might want to. > But without prescribing any particular approach. > > Thanks, > Heiko > > > PS: FWIW, in the experimental "rsop-pqc" implementation, I have decided to adjust key selection for encryption as follows: > > For each recipient certificate, if any valid PQC encryption keys exist, rsop now encrypts only to the set of valid PQC subkeys, while ignoring any non-PQC subkeys. > > While this is somewhat arbitrary, and I look forward to one day implementing official guidance instead, this seems like a reasonable interim solution. I assume most recipients will want this kind of approach to be taken. > > _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE----- Version: ProtonMail wrsEARYKAG0FgmgeTEAJkH5nYVY+/jkwRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmeBynGxN61IeCXy5cCCuXtrSNSnfSncJUaj6X3R 4eb29hYhBIuVslFfa7tqthSdVX5nYVY+/jkwAACScAD8DT2ciffXd8QeJxAU 1nyY0ca0BHoQnpYRgI/GToC4NswBAI7fgUi54QqMM6ZzgFmeol9hs7barJc8 7kBUWRIg/AYC =ZEjc -----END PGP SIGNATURE-----