[openpgp] Re: I-D Action: draft-ietf-openpgp-pqc-09.txt

Daniel Huigens <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <NfzVm_y6Yh3tikUzJ5DOvmzmi4GVn1w9WZFhTnASg72Jtihl-4k9xZcpWrlj4fG4NJ_BYh4corAGiwNzEf85smRcoHWgR1Wt5L51Y3nVbKY=@protonmail.com>
Hi all,

I've updated the PQC test vectors [1], and also added a new test
for verification of the signed+encrypted messages in the draft [2].

It's also interesting to look at the behavior of existing
implementations for keys with both classical and PQ subkeys [3],
to gauge the backwards compatibility of that migration path.

(I hope to also compare this with the path of creating an entirely
new cert, using the replacement key mechanism. If someone wants to
help by providing test vectors for that, please let me know.)

Best,
Daniel

[1]: https://tests.sequoia-pgp.org/?impls=16420&q=pqc
[2]: https://tests.sequoia-pgp.org/?impls=16420&q=pqc#PQC_signed_encrypted_messages
[3]: https://tests.sequoia-pgp.org/?impls=499419&q=%2FX25519%7C%2FECDH


On Thursday, May 15th, 2025 at 16:08, Aron Wussler <[email protected]> wrote:

> Hey everyone,
> 
> This revision includes all the comments gathered during WGLC.
> 
> Thanks to everyone providing feedback and PRs!
> 
> Changelog:
> * Removed subkey semantics related guidance
> * Updated test vectors
> * Added non-normative algorithm explanation
> 
> 
> Cheers,
> Aron
> 
> 
> 
> --
> Aron Wussler
> Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930
> 
> 
> 
> On Thursday, 15 May 2025 at 15:49, [email protected] [email protected] wrote:
> 
> > Internet-Draft draft-ietf-openpgp-pqc-09.txt is now available. It is a work
> > item of the Open Specification for Pretty Good Privacy (OPENPGP) WG of the
> > IETF.
> 
> > Title: Post-Quantum Cryptography in OpenPGP
> > Authors: Stavros Kousidis
> > Johannes Roth
> > Falko Strenzke
> > Aron Wussler
> > Name: draft-ietf-openpgp-pqc-09.txt
> > Pages: 267
> > Dates: 2025-05-15
> 
> > Abstract:
> 
> > This document defines a post-quantum public-key algorithm extension
> > for the OpenPGP protocol. Given the generally assumed threat of a
> > cryptographically relevant quantum computer, this extension provides
> > a basis for long-term secure OpenPGP signatures and ciphertexts.
> > Specifically, it defines composite public-key encryption based on ML-
> > KEM (formerly CRYSTALS-Kyber), composite public-key signatures based
> > on ML-DSA (formerly CRYSTALS-Dilithium), both in combination with
> > elliptic curve cryptography, and SLH-DSA (formerly SPHINCS+) as a
> > standalone public key signature scheme.
> 
> > The IETF datatracker status page for this Internet-Draft is:
> > https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/
> 
> > There is also an HTML version available at:
> > https://www.ietf.org/archive/id/draft-ietf-openpgp-pqc-09.html
> 
> > A diff from the previous version is available at:
> > https://author-tools.ietf.org/iddiff?url2=draft-ietf-openpgp-pqc-09
> 
> > Internet-Drafts are also available by rsync at:
> > rsync.ietf.org::internet-drafts
> 
> > _______________________________________________
> > openpgp mailing list -- [email protected]
> > To unsubscribe send an email to [email protected]_______________________________________________
> 
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.