[openpgp] Deb Cooley's No Objection on draft-ietf-openpgp-pq c-14: (with COMMENT)

Deb Cooley via Datatracker <[email protected]> Sun, 14 Dec 2025 03:56:13 -0800
Newsgroups gmane.ietf.openpgp
Message-ID <176571337331.208979.6942842177164611165@dt-datatracker-5bd94c585b-pvtsm>
Deb Cooley has entered the following ballot position for
draft-ietf-openpgp-pqc-14: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks to Brian Weis for their secdir review.

Section 1.4.2, second para:  PKESK?  please, spell out the first time.

Section 3.3, last para:  (why not MUST) Under what circumstances would an
implementation not consider a message correctly signed?

Section 3.4, para 1:  It would be helpful to know what action an implementer
should take in this case.  A ref to a preexisting reference would be fine.

Section 4.1.1.2, para 1, middle sentence:  a typo? Should this be "R=X448(.."
vice "R=25519(..."?

Section 4.2, second to last bullet:  The session key is generated by the sender?

Section 7.1:  Please expand SEIPD on first use.

Section 9:  Please add a section about ensuring that good quality random number
generation is used (I believe at least one of the FIPS already referenced
contains a section that can be referenced).  In addition, if the session keys
(used to encrypt the message content) are generated directly from a random
source, please call that out specifically (or reference the base OpenPGP RFC
9580 Section 13.10).

Nit:  public key or public-key, pick one and use it everywhere (I would choose
public key).  The same comment applies to other hyphenated phrases.



_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]