[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt
Quynh Dang <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <CAE3-qLTdCvODRpEz3HzibZ-DbnnYdOxQchJda+i0E77vNzxacA@mail.gmail.com> |
On Tue, Oct 14, 2025 at 1:30 PM Simo Sorce <[email protected]> wrote: > On Tue, 2025-10-14 at 12:41 -0400, Quynh Dang wrote: > > > > On Tue, Oct 14, 2025 at 10:58 AM Simo Sorce <[email protected]> wrote: > > On Fri, 2025-10-10 at 12:12 -0400, Quynh Dang wrote: > > Hi Simo, > > On Fri, Oct 10, 2025 at 10:05 AM Simo Sorce <simo= > [email protected]> wrote: > > On Fri, 2025-10-10 at 06:51 +0200, Falko Strenzke wrote: > > After the adoption of draft-ietf-openpgp-nist-bp-comp, we would like to > initiate the discussion about the code points. The draft currently has > > > 5 for encryption: > > > > ML-KEM-512+ECDH-NIST-P-256 MAY > > ML-KEM-768+ECDH-NIST-P-384 MAY > > ML-KEM-1024+ECDH-NIST-P-384 MAY > > ML-KEM-768+ECDH-brainpoolP256r1 MAY > > ML-KEM-1024+ECDH-brainpoolP384r1 MAY > > Any reason why ML-KEM-768 is paired with a 384 bit curve for NIST > curves, but a 256bit curve for Brainpool? > It seem inconsistent. > > > I can speak for the NIST algorithms only. ML-KEM-512+ECDH-NIST-P-256 is > for level 1 security. ML-KEM-768+ECDH-NIST-P-384 is for level 3 security > (not getting into the details of classical and pq security here). The > reason for having P-384 instead of P521 in ML-KEM-1024+ECDH-NIST-P-384 is > that P-521 is rarely supported as I have seen in various presentations and > I prefer ML-KEM-1024 over ML-KEM-768 and ML-KEM-512. > > > When you say "rarely supported" do you have a specific field of use in > mind? > > > I meant less supported or rarely used from what I have seen in the past in > various presentations. Another data point just came up in a TLS' thread > here: > https://mailarchive.ietf.org/arch/msg/tls/c5gEMi7Lv6glU-8dKEulz_X9FbI/ > which showed that the use of P521 was not found. > > > That's because it is more expensive and most commercial users are fine > with the security provided by P256, In the same discussion there you can > see that ML-KEM-1024 is almost unused compared to ML-KEM-768 (0.015% vs > 99.96%)... > > Should strength choices be influence by biased popularity contests ? > I would have no objections if you or another member want to add ML-KEM-1024 with P521. Regards, Quynh. > > -- > > Simo Sorce > Distinguished Engineer > RHEL Crypto Team > Red Hat, Inc > > _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]