[openpgp] Re: OpenPGP PQC nit-picking (plus, SHA2-224 su bkey binding signatures and PKESK wire format)
Aron Wussler <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <XFfFfJHrW_lVdnxeQfFmZiBxMHU8j0ELnnC35uZBDAn6QLPlRA4l2Vj6QbswLGzWKCv_i-Gq4YFkvctNE6MBB8RyUdW46Z5dQxzv4aCsEm0=@wussler.it> |
Hi dkg, thanks for the feedback! We'll merge the last PRs and release a new version of the draft to move forward. I'll send an update with the changelog once done. Cheers, Aron -- Aron Wussler Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930 On Saturday, 7 June 2025 at 00:32, Daniel Kahn Gillmor <[email protected]> wrote: > On Sat 2025-05-31 18:46:14 +0000, Aron Wussler wrote: > > > We'll take care next week of fixing/addressing them. Most of the > > issues seem to have a fairly straightforward way out, and we'll most > > likely go for it. > > > It looks to me like all of the issues i had raised have been resolved in > git, without any substantive changes to the document that i can see. > Thanks to the editors for all the nit-picky cleanup! > > For the record, with regard the two potentially substantive points i > raised: > > > > digest algorithms usable with PQ(/T) > > > The cleanup here just took the most reasonable explanation: primary key > binding sigs from PQ(/T) subkeys inherit the ≥256-bit constraint from ay > other PQ(/T) signature. And subkey binding signatures from a T primary > key keep the separate "no MD5, SHA1, or RIPEMD160" constraint. > > > > unnecessary length octet in PKESK > > > This extra octet remains in the draft, to avoid changing the wire format > now that we have many already interoperable implementations (and staying > "aligned" with the X25519 and X448 PKESK data formats). > > Beyond this, all of the minor internal discrepancies in the tables and > the text appear to me to have been resolved in favor of the ways that > the existing implementations agree with, from what i can tell. > > I have no objections to releasing a new draft and treating that draft as > the basis for moving forward with the IETF last call. If people notice > any additional cleanup, that can happen during this next phase. > > --dkg > _______________________________________________ > openpgp mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE----- Version: ProtonMail wrsEARYKAG0FgmhHyhUJkH5nYVY+/jkwRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmf+C4SQIKs6wAiyHV9F55wBzkKyfMSkelRtCKJL 6cv5gRYhBIuVslFfa7tqthSdVX5nYVY+/jkwAACQJwD/ULTAzPUnBPUGONPm 3jztt8Spmx2SDZPXX755dBtLa64BAMqZfc83D11xKL7tL2plMoVA0WmPAEzE xxE8GgKTEmYD =iOU3 -----END PGP SIGNATURE-----