[openpgp] Re: I-D Action: draft-ietf-openpgp-pqc-09.txt

Daniel Huigens <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <IilTwnY3wGtlBwFqS2pXrCTfuk58J21wbTYqBS0Gc1r10L-kBwkAAI_tH9SFhEZUKfr44AzaJcF2kXCBNV5KWXd4J520tCd6t6pbTz2c7vc=@protonmail.com>
Hi all,

As part of updating OpenPGP.js to the latest PQC draft, Lara Bruseghini
and I noticed the following in the test suite results:

Two of the implementations use SHA256 when signing with an ML-DSA-87
key [1] or SLH-DSA-256s key [2]. We're aware that the requirement to use
SHA3 was dropped in draft-08, to allow the use of SHA2, but surely it
would be better to at least use SHA512 in these cases, rather than
SHA256.

Should we add back some guidance to recommend, or even require, using a
hash algorithm of a size that matches the security level of the signing
algorithm, similarly to the requirements in RFC 9580 (e.g. [3])?

And, apologies for the post-WGLC suggestion! Hopefully this doesn't
delay the RFC too much, but it seemed better to flag this now rather
than ignore it.

Best,
Daniel


[1]: https://tests.sequoia-pgp.org/?impls=16420&q=pqc#Detached_Sign-Verify_roundtrip_with_v6_ML-DSA-87_Ed448_ML-KEM-768_X25519_key
[2]: https://tests.sequoia-pgp.org/?impls=16420&q=pqc#Detached_Sign-Verify_roundtrip_with_v6_SLH-DSA-256s_ML-KEM-1024_X448_key
[3]: https://www.rfc-editor.org/rfc/rfc9580.html#section-5.2.3.5-4

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.