[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt

Simo Sorce <[email protected]>
Newsgroups gmane.ietf.openpgp
Organization Red Hat
Message-ID <[email protected]>
On Fri, 2025-10-10 at 06:51 +0200, Falko Strenzke wrote:
> After the adoption of draft-ietf-openpgp-nist-bp-comp, we would like to initiate the discussion about the code points. The draft currently has

> 5 for encryption:
> 
> ML-KEM-512+ECDH-NIST-P-256	MAY
> ML-KEM-768+ECDH-NIST-P-384	MAY
> ML-KEM-1024+ECDH-NIST-P-384	MAY
> ML-KEM-768+ECDH-brainpoolP256r1	MAY
> ML-KEM-1024+ECDH-brainpoolP384r1	MAY

Any reason why ML-KEM-768 is paired with a 384 bit curve for NIST
curves, but a 256bit curve for Brainpool?
It seem inconsistent.

> 
> 5 for signature:
>  
> ML-DSA-44+ECDSA-NIST-P-256	MAY
> ML-DSA-65+ECDSA-NIST-P-384	MAY
> ML-DSA-87+ECDSA-NIST-P-384	MAY
> ML-DSA-65+ECDSA-brainpoolP256r1	MAY
> ML-DSA-87+ECDSA-brainpoolP384r1	MAY

Same q. as above for ML-DSA-65 and NIST v Brainpool


Is it actually worth supporting the 256 bit curves at all?

If we drop them we can reduce the code points to just 3 + 3
(or 4+4 if you want to pair the mid-strenght PQC algorithms with
brainpool 384)


-- 
Simo Sorce
Distinguished Engineer
RHEL Crypto Team
Red Hat, Inc

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.