[openpgp] Re: I-D Action: draft-ietf-openpgp-pqc-09.txt
Heiko Schäfer <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hello Daniel, list, > Should we add back some guidance to recommend, or even require, using a > hash algorithm of a size that matches the security level of the signing > algorithm, similarly to the requirements in RFC 9580 (e.g. [3])? I would find it a worthwhile improvement to have guidance for hash algorithm selection in draft-ietf-openpgp-pqc (using similar language as in RFC 9580 5.2.3.5 sounds like a natural and good approach to me). *Requiring* a sufficiently large digest size would be my strong preference, to enable recipients to reject insufficiently strong hashes without potentially sacrificing interoperability. Thanks, Heiko _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]