[openpgp] Re: OpenPGP PQC nit-picking (plus, SHA2-224 su bkey binding signatures and PKESK wire format)
Daniel Kahn Gillmor <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On Sat 2025-05-31 18:46:14 +0000, Aron Wussler wrote:
> We'll take care next week of fixing/addressing them. Most of the
> issues seem to have a fairly straightforward way out, and we'll most
> likely go for it.
It looks to me like all of the issues i had raised have been resolved in
git, without any substantive changes to the document that i can see.
Thanks to the editors for all the nit-picky cleanup!
For the record, with regard the two potentially substantive points i
raised:
>> digest algorithms usable with PQ(/T)
The cleanup here just took the most reasonable explanation: primary key
binding sigs from PQ(/T) subkeys inherit the ≥256-bit constraint from ay
other PQ(/T) signature. And subkey binding signatures from a T primary
key keep the separate "no MD5, SHA1, or RIPEMD160" constraint.
>> unnecessary length octet in PKESK
This extra octet remains in the draft, to avoid changing the wire format
now that we have many already interoperable implementations (and staying
"aligned" with the X25519 and X448 PKESK data formats).
Beyond this, all of the minor internal discrepancies in the tables and
the text appear to me to have been resolved in favor of the ways that
the existing implementations agree with, from what i can tell.
I have no objections to releasing a new draft and treating that draft as
the basis for moving forward with the IETF last call. If people notice
any additional cleanup, that can happen during this next phase.
--dkg
_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]