[openpgp] Re: PQC: ML-DSA only (non-composite) signatu re

Roberto Hueso Gomez <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Falko,

Thank you for your feedback!

Other than what Simo said:

1. On top of the CNSA 2.0 compliance reasoning, there is also the 
section 3.3 which says "Newer implementations with PQ(/T) support MAY 
ignore the traditional signature(s) during validation." so, as an user, 
I would expect that, in the future, I would be able to also generate 
ML-DSA-only signature instead of generating an additional signature that 
is going to be ignored.

2. As I got involved very late, I was certainly unaware about the early 
trade-offs you had to make with other national standards. So this is 
something I will try to learn more about but is probably a different issue.

3. Having Ed448 in software is not ideal but probably acceptable for 
this use case. It will definitely mean code challenges, some headaches 
to manage and performing extra signing and verification operations each 
time, but it keeps us technically compliant with CNSA 2.0.

4. Is this WG open to add more code points for pure ML-DSA-only in a 
future RFC? Are you aware of anyone working on this already?

Regards,
Roberto.

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.