[openpgp] Re: Small correction for draft-ietf-openpgp-pqc

Johannes Roth <[email protected]> Tue, 27 Jan 2026 16:01:57 +0100
Newsgroups gmane.ietf.openpgp
Organization MTG AG
Message-ID <[email protected]>
Hi all,

I have created a PR [1] to fix the description in the PQC draft and we 
will release a new version soon.

Thanks for catching the error!

Best,
Johannes

[1] https://github.com/openpgp-pqc/draft-openpgp-pqc/pull/266


On 26.01.2026 14:02, Daniel Kahn Gillmor wrote:
> On Mon 2026-01-26 09:54:05 +0000, Daniel Huigens wrote:
>> Apologies for the last minute (last second?) comment, but there's a
>> small error in Section 4.3.1 of draft-ietf-openpgp-pqc, which states:
>>
>>> Note that like in the case of the algorithms X25519 and X448 specified
>>> in [RFC9580], for the ML-KEM composite schemes, in the case of a v3
>>> PKESK packet, the symmetric algorithm identifier is not encrypted.
>>> Instead, it is placed in plaintext after the mlkemCipherText and
>>> before the length octet preceding the wrapped session key.
>>
>> However, according to the preceding list and the test vectors, and more
>> in line with X25519 and X448, the symmetric algorithm ID is placed
>> _after_ the length octet (and included in that length).
>>
>> The proposed additions to the IANA registry also place the octet
>> correctly, which actually is _not_ true for RFC9580, which failed to
>> include it in the table (mea culpa for that one, I'll file an erratum).
> 
> Thanks for catching this!  Please propose concrete text to be
> incorporated during the RFC Editor's phase, and file that erratum.
> We'll get it sorted.
> 
>          --dkg
> 
> 
> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 4.9 KB) - not displayed