[openpgp] Re: I-D Action: draft-ietf-openpgp-persistent-sy mmetric-keys-02.txt

andrewg <[email protected]> Tue, 04 Nov 2025 18:46:47 +0000
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On 2025-11-04 16:26, Daniel Huigens wrote:
> 
> I realized that no, we don't, we could simply use AEAD as a MAC, too,
> by passing the input as additional data, and the empty string as the
> message to encrypt.

That is *very* clever, I like it. ;-)

> If we really want to introduce HMAC or KMAC at a later date after all
> for whatever reason, plenty of nobs remain to do so, such as in a new
> packet or packet version, or a new algorithm ID anyway, and so on.

I think we should pick an extensibility mechanism sooner rather than 
later. If we register the special asymmetric code point 0, then IMO this 
implies that future extensibility will be marked by packet version 
bumps. If so, the algorithm registry entry for "0" should not hard-code 
AEAD, so we will need a new registry for the PSK version/algorithm 
mapping. I think this is reasonable, but we should be explicit about it.

Otherwise, if future PSK specifications might need further special 
asymmetric code points then there's no point using 0 for this one, and 
it might even be misleading - so we'll have burned a special code point 
for peanuts. :-)

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]