[openpgp] Re: PQC composite sig context string? [was: Re: Re: AD review of draft-ietf-openpgp-pqc-12]
Falko Strenzke <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Organization | MTG AG |
| Message-ID | <[email protected]> |
I have to correct myself: you are right, it doesn't work with CMS because CMS, even though it also signs the message in pure mode, it signs the message directly and not the hash as OpenPGP. So basically the conclusion is that the attack is typically prevented because OpenPGP uses the pure mode to sign hashes, and other protocols typically will use the pure mode to sign the message directly. Cheers, Falko Am 29.09.25 um 17:06 schrieb Falko Strenzke: >> I believe not even the very liberal CMS lets you do that, for >> instance ML-DSA is specified in pure mode only. > > We are using ML-DSA in pure mode for OpenPGP as well. CMS works thus > works perfectly for such attacks. > -- *MTG AG* Dr. Falko Strenzke Phone: +49 6151 8000 24 E-Mail: [email protected] Web: mtg.de <https://www.mtg.de> ------------------------------------------------------------------------ MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany Commercial register: HRB 8901 Register Court: Amtsgericht Darmstadt Management Board: Jürgen Ruf (CEO), Tamer Kemeröz Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you are not the correct recipient or have received this email in error, please inform the sender immediately and delete this email.Unauthorised copying or distribution of this email is not permitted. Data protection information: Privacy policy <https://www.mtg.de/en/privacy-policy> _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
smime.p7s
(application/pkcs7-signature, 4.9 KB) - not displayed