[openpgp] Re: Updated persistent symmetric keys draft to avo id message limits

Daniel Huigens <[email protected]> Fri, 14 Nov 2025 12:36:07 +0000
Newsgroups gmane.ietf.openpgp
Message-ID <vyihSB_315bXia8a7govgacU2LXbMwXZ8sLLevdwO2AzmwDGSrwvneWDiBwfv38HUW0GA3QVKoBEvUr1B-byTz5I8k3fuhES5km3lcg2Yjw=@protonmail.com>
Hi Andrew,

On Friday, November 14th, 2025 at 12:46, Andrew Gallagher wrote:

> I think this looks reasonable. :-)

Thanks! :)

> I do have one other question though... can we be confident that it is OK
> to pass the empty string as additional data in the AEAD encryption mode?
> Would it be less confusing, simpler and/or more resilient to use similar
> additional data as in the SEIPDv2 packet spec?

I think it's redundant, also in SEIPDv2; we added the HKDF step there
fairly late and just left the additional data, but the key is already
bound to all the parameters included in the AD.

We could still add it, but I thought it would look a but ugly in the
message authentication case to have to concatenate this context-related
AD with the message hash. Still not the end of the world, though, if
we care more about being consistent.

Though I also thought there's unlikely to be all that much code sharing
possible between the two, either way, but I haven't tried yet.

Best,
Daniel

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]