[openpgp] Re: I-D Action: draft-ietf-openpgp-pqc-09.txt
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <IilTwnY3wGtlBwFqS2pXrCTfuk58J21wbTYqBS0Gc1r10L-kBwkAAI_tH9SFhEZUKfr44AzaJcF2kXCBNV5KWXd4J520tCd6t6pbTz2c7vc=@protonmail.com> |
Hi all, As part of updating OpenPGP.js to the latest PQC draft, Lara Bruseghini and I noticed the following in the test suite results: Two of the implementations use SHA256 when signing with an ML-DSA-87 key [1] or SLH-DSA-256s key [2]. We're aware that the requirement to use SHA3 was dropped in draft-08, to allow the use of SHA2, but surely it would be better to at least use SHA512 in these cases, rather than SHA256. Should we add back some guidance to recommend, or even require, using a hash algorithm of a size that matches the security level of the signing algorithm, similarly to the requirements in RFC 9580 (e.g. [3])? And, apologies for the post-WGLC suggestion! Hopefully this doesn't delay the RFC too much, but it seemed better to flag this now rather than ignore it. Best, Daniel [1]: https://tests.sequoia-pgp.org/?impls=16420&q=pqc#Detached_Sign-Verify_roundtrip_with_v6_ML-DSA-87_Ed448_ML-KEM-768_X25519_key [2]: https://tests.sequoia-pgp.org/?impls=16420&q=pqc#Detached_Sign-Verify_roundtrip_with_v6_SLH-DSA-256s_ML-KEM-1024_X448_key [3]: https://www.rfc-editor.org/rfc/rfc9580.html#section-5.2.3.5-4 _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]