[openpgp] Re: PQC composite sig context string? [was: Re: Re: AD review of draft-ietf-openpgp-pqc-12]
Jakub Jelen <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <CAHrFiA9LeAF=wXp1VHXN5PL2fEMnL0uMCDssN2wJjUnyjcowGQ@mail.gmail.com> |
Hi, we, Red Hat, are on the same boat, quite close to the shipping the current version and rehashing everything from scratch would make it quite a hassle. My understanding is the same key reuse in different contexts is generally discouraged. While I agree that adding the context would make it another layer of defense, I think doing it now is quite late, especially with the CNSA 2 requirements vendors need to go through. Jakub On Thu, Sep 25, 2025 at 10:07 AM Daniel Huigens <d.huigens= [email protected]> wrote: > Hi dkg & all, > > We (Proton) would strongly prefer option A. > > We are close to shipping PQC and would prefer not to delay this :) > > Best, > Daniel > > > On Wednesday, September 24th, 2025 at 19:10, Daniel Kahn Gillmor wrote: > > > Thanks for this cleanup work, Aron and the rest of the authors. The > > draft is better for Paul's review and for your responses to it. > > > > I just wanted to draw the WG's attention to this open question which has > > the potential to invalidate existing implementations and test vectors: > > > > On Tue 2025-09-23 15:08:17 +0000, Aron Wussler wrote: > > > > > > Section 5.1.2. ML-DSA Signatures > > > > > > > Why is the context string empty and not set to "OpenPGP" or > something? Wouldn't > > > > this strengthen against cross protocol attacks? > > > > > > This was decided because of library support, that has since partly > changed. > > > Full discussion here: > https://github.com/openpgp-pqc/draft-openpgp-pqc/issues/231 > > > > > > I personally oppose wire format changes at this stage if not > > > necessary, especially given this would still give implementation > > > headaches with Botan and delay adoption by months. > > > > > > Paul, the consensus of the WG was OK with the decision to omit the > > context string in the past, but that was due in part to limitations in > > underlying crypto libraries, some of which now do support the context > > string for ML-DSA and SLH-DSA. > > > > WG, we need to make a decision between these two choices: > > > > A) Retain the old consensus (and move forward with the draft and test > > vectors as planned, perhaps noting in the draft the historical > > reason for the empty context string), or > > > > B) Select a context string (invalidating existing test vectors and > > implementation branches) > > > > Please give feedback on the list here about whether you prefer A or B. > > > > If you prefer B, please also indicate whether you are OK with the fixed > > context string "OpenPGP", or if you prefer some other context string. > > > > We can see from Aron's message that he prefers A. > > > > Please respond in the coming week so we can move this draft along. > > > > Regards, > > > > --dkg > > _______________________________________________ > > openpgp mailing list -- [email protected] > > To unsubscribe send an email to [email protected] > > _______________________________________________ > openpgp mailing list -- [email protected] > To unsubscribe send an email to [email protected] > _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]