[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt
Simo Sorce <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
On Fri, 2025-10-10 at 06:51 +0200, Falko Strenzke wrote: > After the adoption of draft-ietf-openpgp-nist-bp-comp, we would like to initiate the discussion about the code points. The draft currently has > 5 for encryption: > > ML-KEM-512+ECDH-NIST-P-256 MAY > ML-KEM-768+ECDH-NIST-P-384 MAY > ML-KEM-1024+ECDH-NIST-P-384 MAY > ML-KEM-768+ECDH-brainpoolP256r1 MAY > ML-KEM-1024+ECDH-brainpoolP384r1 MAY Any reason why ML-KEM-768 is paired with a 384 bit curve for NIST curves, but a 256bit curve for Brainpool? It seem inconsistent. > > 5 for signature: > > ML-DSA-44+ECDSA-NIST-P-256 MAY > ML-DSA-65+ECDSA-NIST-P-384 MAY > ML-DSA-87+ECDSA-NIST-P-384 MAY > ML-DSA-65+ECDSA-brainpoolP256r1 MAY > ML-DSA-87+ECDSA-brainpoolP384r1 MAY Same q. as above for ML-DSA-65 and NIST v Brainpool Is it actually worth supporting the 256 bit curves at all? If we drop them we can reduce the code points to just 3 + 3 (or 4+4 if you want to pair the mid-strenght PQC algorithms with brainpool 384) -- Simo Sorce Distinguished Engineer RHEL Crypto Team Red Hat, Inc _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]