[openpgp] Re: PQC composite sig context string? [was: Re: Re: AD review of draft-ietf-openpgp-pqc-12]

Jakub Jelen <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <CAHrFiA9LeAF=wXp1VHXN5PL2fEMnL0uMCDssN2wJjUnyjcowGQ@mail.gmail.com>
Hi,
we, Red Hat, are on the same boat, quite close to the shipping the current
version and rehashing everything from scratch would make it quite a hassle.

My understanding is the same key reuse in different contexts is generally
discouraged. While I agree that adding the context would make it another
layer of defense, I think doing it now is quite late, especially with the
CNSA 2 requirements vendors need to go through.

Jakub

On Thu, Sep 25, 2025 at 10:07 AM Daniel Huigens <d.huigens=
[email protected]> wrote:

> Hi dkg & all,
>
> We (Proton) would strongly prefer option A.
>
> We are close to shipping PQC and would prefer not to delay this :)
>
> Best,
> Daniel
>
>
> On Wednesday, September 24th, 2025 at 19:10, Daniel Kahn Gillmor wrote:
>
> > Thanks for this cleanup work, Aron and the rest of the authors. The
> > draft is better for Paul's review and for your responses to it.
> >
> > I just wanted to draw the WG's attention to this open question which has
> > the potential to invalidate existing implementations and test vectors:
> >
> > On Tue 2025-09-23 15:08:17 +0000, Aron Wussler wrote:
> >
> > > > Section 5.1.2. ML-DSA Signatures
> > >
> > > > Why is the context string empty and not set to "OpenPGP" or
> something? Wouldn't
> > > > this strengthen against cross protocol attacks?
> > >
> > > This was decided because of library support, that has since partly
> changed.
> > > Full discussion here:
> https://github.com/openpgp-pqc/draft-openpgp-pqc/issues/231
> > >
> > > I personally oppose wire format changes at this stage if not
> > > necessary, especially given this would still give implementation
> > > headaches with Botan and delay adoption by months.
> >
> >
> > Paul, the consensus of the WG was OK with the decision to omit the
> > context string in the past, but that was due in part to limitations in
> > underlying crypto libraries, some of which now do support the context
> > string for ML-DSA and SLH-DSA.
> >
> > WG, we need to make a decision between these two choices:
> >
> > A) Retain the old consensus (and move forward with the draft and test
> >     vectors as planned, perhaps noting in the draft the historical
> >     reason for the empty context string), or
> >
> > B) Select a context string (invalidating existing test vectors and
> >      implementation branches)
> >
> > Please give feedback on the list here about whether you prefer A or B.
> >
> > If you prefer B, please also indicate whether you are OK with the fixed
> > context string "OpenPGP", or if you prefer some other context string.
> >
> > We can see from Aron's message that he prefers A.
> >
> > Please respond in the coming week so we can move this draft along.
> >
> > Regards,
> >
> >         --dkg
> > _______________________________________________
> > openpgp mailing list -- [email protected]
> > To unsubscribe send an email to [email protected]
>
> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.