[openpgp] Re: Mohamed Boucadair's No Objection on draft-ie tf-openpgp-pqc-14: (with COMMENT)

Aron Wussler <[email protected]> Mon, 15 Dec 2025 12:46:44 +0000
Newsgroups gmane.ietf.openpgp
Message-ID <_Sx0vPSWETjEtND3AMIwaTh0y5ZfRUoYgo5_y4OWLZjHnmotudfu2r-Nlvb5G1vYxNbdSuwpuvL2_PWtB56dzXLI1yB5wy-chXpNQBW4yoI=@wussler.it>
Hi Med,

Thank you for the review :)

We've addressed your comments on GitHub [1] and plan to publish them in the upcoming days.

> I appreciate OPS-related discussion about migration (Section 8) and performance
> (Section 10). This can be even convenient if these two sections are moved under
> an “Operational Considerations” section.

The reason why we preferred keeping them separate is because 8 is normative and 10 isn't :)

> Please find below some very few comments:
> 

> # Interpretation of RFC 9580
> 

> CURRENT:
> Implementations SHOULD consider the message correctly signed if at
> least one of the non-ignored signatures validates successfully. This
> is an interpretation of Section 5.2.5 of [RFC9580].
> 

> I read this as basically adhering to what is already in 9580.
> 

> I find the use of normative language here confusing as it gives the impression
> that this is new behavior. Focusing on new behavior would help identify updates
> to RFC9580 (which is not straightforward as rightfully raised by Ketan).

This is not clearly specified in RFC 9580, but it's quite implicit, and it's what most implementations are doing.
We wanted to clear this up in order to allow for a smooth transition to PQC.

> # Mapping with US FIPS 20x Tables
> 

> The various tables do not map 1:1 to their counterpart in FIPS 20x documents.
> For example, how Key share/ Secret key maps to Table 3 of FIPS-203?

Changed the tables to contain the original terms for FIPS-20[345]

> CURRENT:
> This feature is generally considered
> to be a high security guarantee.
>
> # (nit) Believed
> 

> CURRENT:
> All schemes listed here are believed to provide security in
> the presence of a CRQC.
> 

> ..
> 

> The scheme is
> believed to provide security against cryptanalytic attacks based on
> classical as well as quantum algorithms.
> 

> Not sure “believed” is appropriate in an RFC.

I _believe_ the two proposed changes are conflicting ;)
Happy to adjust terminology, as long as it's consistent.

Cheers,
Aron

[1] https://github.com/openpgp-pqc/draft-openpgp-pqc/pull/257

--
Aron Wussler
Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wrsEARYKAG0FgmlAAysJEH5nYVY+/jkwRRQAAAAAABwAIHNhbHRAbm90YXRp
b25zLm9wZW5wZ3Bqcy5vcmdH7plhzc9zlsiMmrFgyH9OPeyikeGWKtng+JLH
K9s2IRYhBIuVslFfa7tqthSdVX5nYVY+/jkwAACTNwD/QXkNRmjATxx9ErHj
rlazF1KKrlcrUEZmCsH0rEgf7NEBAIEZxRl6kyYukmCGLPlvjO6uYQiK/6b5
4T5brPUJ6KkE
=07jO
-----END PGP SIGNATURE-----