[openpgp] Small correction for draft-ietf-openpgp-pqc
Daniel Huigens <[email protected]> Mon, 26 Jan 2026 09:54:05 +0000
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <KkQYkRhj-jf9WzOzUPCANDTYaYYGgWDJY27bnZl2GOe19_mgrFIO9-TmYwX_kYVE3KDP7OagceEdDhVgRBYG55fbsKmFGFKDIhhjm9QNGYg=@protonmail.com> |
Hi all, Apologies for the last minute (last second?) comment, but there's a small error in Section 4.3.1 of draft-ietf-openpgp-pqc, which states: > Note that like in the case of the algorithms X25519 and X448 specified > in [RFC9580], for the ML-KEM composite schemes, in the case of a v3 > PKESK packet, the symmetric algorithm identifier is not encrypted. > Instead, it is placed in plaintext after the mlkemCipherText and > before the length octet preceding the wrapped session key. However, according to the preceding list and the test vectors, and more in line with X25519 and X448, the symmetric algorithm ID is placed _after_ the length octet (and included in that length). The proposed additions to the IANA registry also place the octet correctly, which actually is _not_ true for RFC9580, which failed to include it in the table (mea culpa for that one, I'll file an erratum). Best, Daniel _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]