[openpgp] Re: Ketan Talaulikar's Discuss on draft-ietf-ope npgp-pqc-14: (with DISCUSS and COMMENT)
Stephen Farrell <[email protected]> Thu, 11 Dec 2025 21:15:04 +0000
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hiya, On 11/12/2025 19:08, Ketan Talaulikar via Datatracker wrote: > ---------------------------------------------------------------------- > DISCUSS: > ---------------------------------------------------------------------- > > Thanks to the authors and the WG for their work on this document. > > I have one aspect of this document that I would like to discuss. The document > is updating RFC9580, but is not specifying what is it that is it modifying in > that base OpenPGP spec. Is the introduction of new algorithms/codepoints and > the use of composite/hybrid approach for KEM and certificates an extension of > OpenPGP or is updating (as in say fixing or changing the working) of OpenPGP? > My impression (and I could be wrong) is that this is an extension to OpenPGP? This just adds new algorithms, using the planned extensibility mechanism, which is an extremely common one for pretty much all cryptographic protocols. > In either case, a short summary or description of what is being updated in or > done differently than what is in RFC9850 in the abstract and introduction would > help clarify for readers and address this discussion point. I'm not sure that's really needed - an implementer who is going to make use of this spec will definitely not need that level of introductory material. I'm also uncertain as to how this discuss matches the discuss criteria. [1] Can you explain? (ISTM, the ask here is pretty close to a bullet in section 3.2 of [1]: "The motivation for a particular feature of a protocol is not clear enough. At the IESG review stage, protocols should not be blocked because they provide capabilities beyond what seems necessary to acquit their responsibilities." But maybe I'm missing something here? Thanks, S. [1] https://datatracker.ietf.org/doc/statement-iesg-discuss-criteria-in-iesg-review-20140507/ > > > ---------------------------------------------------------------------- > COMMENT: > ---------------------------------------------------------------------- > > > I have just one nit to bring to your attention. I believe the correct term is > "public key" and not "public-key". This is the case even in the base RFC9850 > that is being updated. > > > _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
OpenPGP_signature.asc
(application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE----- wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCaTs0WAUDAAAAAAAKCRDk2On5l6gz3dg9 AQDTfmm2/ZLUhIy0lhOoOXz45svqK9kPnm3bESzUR2aeTgD+P9zgzyO8yICKeki2aABuNS5HPaqb 6JeNEjEjrhBK2gU= =0zAK -----END PGP SIGNATURE-----