[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt
Stavros Kousidis <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Dear Simon, dear Simo, I'll try to address all your points in one message. We aligned the combiner a while ago in draft-ietf-openpgp-pqc-07 (see changelog) to match the one defined for the composite KEMs in LAMPS. In view of draft-irtf-cfrg-hybrid-kems, the OpenPGP combiner is QSF from with an OpenPGP-specific label and KDF = SHA3-256 (though we do not strictly meet the unified expandDecapsulationKey() interface there, but IMO this is neither essential nor necessary). To make the curve choices more transparent, I think we will have to recall the development over time: Before the split into draft-ietf-openpgp-pqc and draft-ietf-openpgp-nist-bp-comp, we had the following in one draft: - ML-KEM-768 matched with X25519, NIST-P-256, and brainpoolP256r1 - ML-KEM-1024 matched with X448, NIST-P-384, and brainpoolP384r1 - ML-DSA-65 matched with Ed25519, NIST-P-256, and brainpoolP256r1 - ML-DSA-87 matched with Ed448, NIST-P-384, and brainpoolP384r1 The intention was to have a consistent security level for the EC part. As CNSA 2.0 recommends 384-bit curves for all classification levels, we didn't see a need for NIST-P-521 or brainpoolP512r1 and put X448, NIST-P-384, and brainpoolP384r1 in one pot. Those compositions seemed to be reasonable choices and to give a minimal set. During the split, we didn't modify the original brainpoolP choices. As for the alteration of the NIST-P compositions, see Quynh’s reply (https://mailarchive.ietf.org/arch/msg/openpgp/34145F3_wy67JcazHZe3PqRdWn8 <https://mailarchive.ietf.org/arch/msg/openpgp/34145F3_wy67JcazHZe3PqRdWn8/>/)<https://mailarchive.ietf.org/arch/msg/openpgp/34145F3_wy67JcazHZe3PqRdWn8/> Best Stavros On 10/11/25 13:23, Simon Josefsson wrote: > I like that this document moves NIST/BSI curves out from the main > document, and also that they target the MAY level, so +1 since I think > we need more PQ hyrid options around. I wish that PGP would use a > CFRG-aligned PQ/T combiner, but I also believe CFRG has proven itself > not worthy to wait for guidance on this matter. While I prefer the > Chempat combiner I think it is reasonable to proceed with a custom > PGP-specific combiner here. I also found alignment of MLKEM768 with > P384 and brainpoolP256 surprising, but I don't care strongly about that. > > /Simon > > Falko Strenzke<[email protected]> writes: > >> After the adoption of draft-ietf-openpgp-nist-bp-comp, we would like >> to initiate the discussion about the code points. The draft currently >> has >> >> 5 for encryption: >> >> ML-KEM-512+ECDH-NIST-P-256 MAY >> ML-KEM-768+ECDH-NIST-P-384 MAY >> ML-KEM-1024+ECDH-NIST-P-384 MAY >> ML-KEM-768+ECDH-brainpoolP256r1 MAY >> ML-KEM-1024+ECDH-brainpoolP384r1 MAY >> >> 5 for signature: >> >> ML-DSA-44+ECDSA-NIST-P-256 MAY >> ML-DSA-65+ECDSA-NIST-P-384 MAY >> ML-DSA-87+ECDSA-NIST-P-384 MAY >> ML-DSA-65+ECDSA-brainpoolP256r1 MAY >> ML-DSA-87+ECDSA-brainpoolP384r1 MAY >> >> Please respond on the list whether you agree or disagree with these >> sets. Questions or discussions about the motivations etc. are of >> course also welcome. >> >> @Chairs: Can we plan a slot at the end of the interim next week to >> discuss the code points? >> >> That being said, I also encourage the WG to read the draft in >> general. Since it is fully aligned with draft-ietf-openpgp-pqc, the >> potential for discussions is probably low. The code points are >> presumably the main discussion point. Once the code points have been >> agreed on, the draft can probably progress quickly. >> >> If you want to review the draft, I suggest to wait until version 01, >> as we are currently in the process of applying the latest relevant >> editorial changes that have been made to draft-ietf-openpgp-pqc. >> >> Falko >> >> Am 09.10.25 um 16:18 [email protected]: >>> Internet-Draft draft-ietf-openpgp-nist-bp-comp-00.txt is now available. It is >>> a work item of the Open Specification for Pretty Good Privacy (OPENPGP) WG of >>> the IETF. >>> >>> Title: PQ/T Composite Schemes for OpenPGP using NIST and Brainpool Elliptic Curve Domain Parameters >>> Authors: Quynh Dang >>> Stephan Ehlen >>> Stavros Kousidis >>> Johannes Roth >>> Falko Strenzke >>> Name: draft-ietf-openpgp-nist-bp-comp-00.txt >>> Pages: 29 >>> Dates: 2025-10-09 >>> >>> Abstract: >>> >>> This document defines PQ/T composite schemes based on ML-KEM and ML- >>> DSA combined with ECDH and ECDSA algorithms using the NIST and >>> Brainpool domain parameters for the OpenPGP protocol. >>> >>> The IETF datatracker status page for this Internet-Draft is: >>> https://datatracker.ietf.org/doc/draft-ietf-openpgp-nist-bp-comp/ >>> >>> There is also an HTML version available at: >>> https://www.ietf.org/archive/id/draft-ietf-openpgp-nist-bp-comp-00.html >>> >>> Internet-Drafts are also available by rsync at: >>> rsync.ietf.org::internet-drafts >>> >>> >>> _______________________________________________ >>> openpgp mailing list [email protected] >>> To unsubscribe send an [email protected] _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]