[openpgp] Re: I-D Action: draft-ietf-openpgp-pqc-09.txt

Heiko Schäfer <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hello Daniel, list,

> Should we add back some guidance to recommend, or even require, using a
> hash algorithm of a size that matches the security level of the signing
> algorithm, similarly to the requirements in RFC 9580 (e.g. [3])?

I would find it a worthwhile improvement to have guidance for hash 
algorithm selection in draft-ietf-openpgp-pqc (using similar language as 
in RFC 9580 5.2.3.5 sounds like a natural and good approach to me).

*Requiring* a sufficiently large digest size would be my strong 
preference, to enable recipients to reject insufficiently strong hashes 
without potentially sacrificing interoperability.

Thanks,
Heiko

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.