[openpgp] Re: PQC: ML-DSA only (non-composite) signatu re
Roberto Hueso Gomez <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Falko, Thank you for your feedback! Other than what Simo said: 1. On top of the CNSA 2.0 compliance reasoning, there is also the section 3.3 which says "Newer implementations with PQ(/T) support MAY ignore the traditional signature(s) during validation." so, as an user, I would expect that, in the future, I would be able to also generate ML-DSA-only signature instead of generating an additional signature that is going to be ignored. 2. As I got involved very late, I was certainly unaware about the early trade-offs you had to make with other national standards. So this is something I will try to learn more about but is probably a different issue. 3. Having Ed448 in software is not ideal but probably acceptable for this use case. It will definitely mean code challenges, some headaches to manage and performing extra signing and verification operations each time, but it keeps us technically compliant with CNSA 2.0. 4. Is this WG open to add more code points for pure ML-DSA-only in a future RFC? Are you aware of anyone working on this already? Regards, Roberto. _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]