[openpgp] Re: Status of draft-ietf-openpgp-nist-bp-comp
Andrew Gallagher <[email protected]> Wed, 20 May 2026 23:03:55 +0100
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hi, Falko. On 19 May 2026, at 15:49, Falko Strenzke <[email protected]> wrote: > > We want to give a brief report of the status of draft-ietf-openpgp-nist-bp-comp: > > The itself draft is ready for WGLC from our perspective for quite some time now. > From the point of view of a (current) non-implementer, the draft appears ready for WGLC. I’d like to make one minor suggestion though. We decided to permit the single ML-KEM-768 code point from RFC9980 (to be) in v4 encryption subkeys, to smooth the upgrade pathway for users that couldn’t (for whatever reason) quickly migrate to v6 primary keys. I believe we should similarly permit the two ML-KEM-768 code points from this draft in v4. Users who have a regulatory requirement to use Brainpool or NIST curves are just as likely to benefit from v4 PQC encryption subkeys as those who do not. It would be inconsistent to deny a quick upgrade pathway to those users, after we explicitly opened one for those who can use x25519. The same security considerations would apply to all three ML-KEM-768 code points, however since the Brainpool and NIST curves are optional, the interop burden should be minimal in the general case. AFAICT the draft would only need minor edits, to match the similar edits made to RFC9980. Thanks, A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]