[openpgp] Mohamed Boucadair's No Objection on draft-ietf-ope npgp-pqc-14: (with COMMENT)
Mohamed Boucadair via Datatracker <[email protected]> Fri, 12 Dec 2025 01:58:34 -0800
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <176553351413.1633172.4402698518936931372@dt-datatracker-5bd94c585b-wk4l4> |
Mohamed Boucadair has entered the following ballot position for draft-ietf-openpgp-pqc-14: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ for more information about how to handle DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/ ---------------------------------------------------------------------- COMMENT: ---------------------------------------------------------------------- Hi Stavros, Johannes, Falko, and Aron, Thank you for the effort put into this well-written specification. I appreciate OPS-related discussion about migration (Section 8) and performance (Section 10). This can be even convenient if these two sections are moved under an “Operational Considerations” section. Please find below some very few comments: # Interpretation of RFC 9580 CURRENT: Implementations SHOULD consider the message correctly signed if at least one of the non-ignored signatures validates successfully. This is an interpretation of Section 5.2.5 of [RFC9580]. I read this as basically adhering to what is already in 9580. I find the use of normative language here confusing as it gives the impression that this is new behavior. Focusing on new behavior would help identify updates to RFC9580 (which is not straightforward as rightfully raised by Ketan). # Mapping with US FIPS 20x Tables The various tables do not map 1:1 to their counterpart in FIPS 20x documents. For example, how Key share/ Secret key maps to Table 3 of FIPS-203? # Do we have any reference to cite here? CURRENT: This feature is generally considered to be a high security guarantee. # (nit) Believed CURRENT: All schemes listed here are believed to provide security in the presence of a CRQC. .. The scheme is believed to provide security against cryptanalytic attacks based on classical as well as quantum algorithms. Not sure “believed” is appropriate in an RFC. Cheers, Med _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]