[openpgp] Re: WGLC for draft-ietf-openpgp-pqc

Stephen Farrell <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hiya,

On 12/05/2025 18:20, Daniel Kahn Gillmor wrote:
> Hey folks--
> 
> On Tue 2025-04-15 12:41:01 -0400, Daniel Kahn Gillmor wrote:
>> With these changes, Stephen and I are announcing Working Group Last Call
>> on draft-ietf-openpgp-pqc.
>>
>> We expect the WGLC to last four weeks, which means we will look for
>> consensus (or the lack thereof) based on on-list discusson through
>> Tuesday, 2025-05-13.
> 
> Just a gentle reminder that the deadline for this WGLC is coming up
> tomorrow.  If you have thoughts or reviews you've been holding back, now
> is a good time to share them on the list.

Thanks to my co-chair for the gentle reminder:-) (TBH, I did need
it as I just emerging from exam-marking frenzy:-)

I have a few personal comments below, none of which should delay us
in publication. (Unless they resonate much more widely than I expect.)

It looks to me (and dkg, based on off-list mail) like we do have
consensus to proceed with this, but in chair-mode, we should look back
over the  WGLC comments and send a mail to the list to confirm that etc.
I think we may want a -09 draft too based on the earlier comments, but
should then be good to push ahead.

My non-blocking personal comments/queries are below - it is ok to ignore
'em, honest:-)

Cheers,
S.

- I think (but am not 100% sure) we want it to be true that
   no implementation makes unexpected multiple uses of any
secret or private value at any time. For example, KEM
private values when sending a mail to multiple recipients
or signature private keys when signing twice with algs
32/33. Is that the case?  If so, should we say it (more)
explicitly? We almost do say this in a few places, some of
which RECOMMEND not re-using, others of which call for
"independent" generation. Is this something we could
tighten up on without breaking any use-cases? If we do have
some real use-case that needs to re-use a secret or private
value, (basically other than multiple alg-specific signing
private key use), can we describe that as the
counter-example to just saying RECOMMENDED rather than MUST
NOT?

- 2.1: Five is IMO too many signature options. Can we not
   reduce that number?  If not (as I suspect, I always lose
this argument;-) then it'll help with later document
processing if we can document why we need five in e.g. an
email, in case someone asks, which they probably will.  (I
forget if we covered this specifically in earlier debates
sorry, if a reference provides a good answer, that's just
fine.)

- I didn't check the appendices/examples, but I know others
   have (thanks!).  We should also get somoene to confirm on
the list that the set of examples in the version we forward
for publication are (still) ok, again in an email to the
list so we can point to that later.

- nit: We use ":=" without definition, and I'd say just
"=" would be just as good?

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCaCPDlgUDAAAAAAAKCRDk2On5l6gz3Rv9
AP42Uim2DKMZ7a8UGWnKS2VfUr2QMVU13ZRnrUO8DihFwgEA4mGmSvsjmgEpzpIRqBYMJUKox2Gx
ATtydcQojQf0wwQ=
=x5HH
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.