[openpgp] Re: [EXTERNAL] Re: draft-ietf-openpgp-nist-b p-comp: add Category-5/P-384 combinations
"Dang, Quynh H. \(Fed\)" <[email protected]> Tue, 7 Jul 2026 10:40:42 +0000
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <MW4PR09MB100599C553AD71CC5B4E8333DF3F02@MW4PR09MB10059.namprd09.prod.outlook.com> |
--===============1696518308132769704== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_MW4PR09MB100599C553AD71CC5B4E8333DF3F02MW4PR09MB10059na_" --_000_MW4PR09MB100599C553AD71CC5B4E8333DF3F02MW4PR09MB10059na_ Content-Type: text/plain; charset="iso-8859-2" Content-Transfer-Encoding: quoted-printable Hi Gergely, One thing I know you can do is to write a short draft specifying the option= s that you need/want, then ask the working group to adopt it. If the worki= ng group does not adopt it, you could ask for only code points (I don't kno= w if the working group would approve that). Regards, Quynh. From: NGG <[email protected]> Sent: Monday, July 6, 2026 11:05 AM To: Falko Strenzke <[email protected]> Cc: [email protected] Subject: [EXTERNAL] [openpgp] Re: draft-ietf-openpgp-nist-bp-comp: add Cate= gory-5/P-384 combinations You don't often get email from [email protected]<mailto:ngg=3D4= [email protected]>. Learn why this is important<https://aka.ms/LearnAb= outSenderIdentification> Hello Falko, Thanks for the question. I did not mean that any single one of the existing profiles requires both h= ybrid use and category-5 ML-* alone. My point is interoperability across profiles: some environments allow P-384= but not P-521, while other requirements may call for category-5 ML-*. Impl= ementations may need one standardized hybrid option that works across as ma= ny such environments as possible. So the goal is not to satisfy a single profile with one algorithm choice, b= ut to define an optional P-384/category-5 combination that is broadly usabl= e across multiple profiles and avoids private, non-standard combinations. Best regards, Gergely Falko Strenzke <[email protected]<mailto:[email protected]>> ezt = =EDrta (id=F5pont: 2026. j=FAl. 6., H, 16:35): Hi Gergely, On Sat, 2026-06-20 at 22:56 +0200, NGG wrote: Hello OpenPGP WG, I would like to suggest adding the following optional combinations to draft= -ietf-openpgp-nist-bp-comp: * ML-KEM-1024+ECDH-NIST-P-384 * ML-DSA-87+ECDSA-NIST-P-384 The current draft pairs the category-5 ML-* parameter sets only with P-521,= while P-384 is paired with category-3. The motivation is compliance interoperability. Some deployed profiles, including CNSA 1.0 and NATO FMN certificate profile= s, admit P-384 but not P-521. Separately, other policies or deployment requirements may call for the cate= gory-5 ML-* parameter sets. What requirements of profiles are you exactly referring to? CNSA does not r= equire multi-algorithm at all, so for this purpose the security level of th= e traditional component should not matter. In fact it could simply be ignor= ed for the signature at least. Falko These are not necessarily requirements imposed by the same profile, but sof= tware may need to operate across several such environments. Standardized P-384/category-5 combinations would provide a useful intersect= ion. There is already relevant IETF precedent: * The TLS ECDHE-MLKEM specification defines SecP384r1MLKEM1024. * The LAMPS composite-signature specification defines id-MLDSA87-ECDSA-P384= -SHA512. These combinations could be added alongside the existing P-521 variants, wi= thout changing or replacing them. Would the WG consider adding them? Best regards, Gergely Nagy _______________________________________________ openpgp mailing list -- [email protected]<mailto:[email protected]> To unsubscribe send an email to [email protected]<mailto:openpgp-leave= @ietf.org> -- MTG AG Dr. Falko Strenzke Phone: +49 6151 8000 24 E-Mail: [email protected]<mailto:[email protected]> Web: mtg.de<http://mtg.de/> MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany Commercial register: HRB 8901 Register Court: Amtsgericht Darmstadt Management Board: J=FCrgen Ruf (CEO), Tamer Kemer=F6z Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you a= re not the correct recipient or have received this email in error, please inform the sender immediately and delete this email.Unauthorised cop= ying or distribution of this email is not permitted. Data protection information: Privacy policy --_000_MW4PR09MB100599C553AD71CC5B4E8333DF3F02MW4PR09MB10059na_ Content-Type: text/html; charset="iso-8859-2" Content-Transfer-Encoding: quoted-printable <html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc= hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of= fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-= 2"> <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Aptos;} @font-face {font-family:Consolas; panose-1:2 11 6 9 2 2 4 3 2 4;} @font-face {font-family:"Segoe UI"; panose-1:2 11 5 2 4 2 4 2 2 3;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; font-size:12.0pt; font-family:"Aptos",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} pre {mso-style-priority:99; mso-style-link:"HTML Preformatted Char"; margin:0in; font-size:10.0pt; font-family:"Courier New";} p.gmail-pdq2pgselectionanchorcontainer, li.gmail-pdq2pgselectionanchorconta= iner, div.gmail-pdq2pgselectionanchorcontainer {mso-style-name:gmail-pdq2pg_selectionanchorcontainer; mso-margin-top-alt:auto; margin-right:0in; mso-margin-bottom-alt:auto; margin-left:0in; font-size:12.0pt; font-family:"Aptos",sans-serif;} span.HTMLPreformattedChar {mso-style-name:"HTML Preformatted Char"; mso-style-priority:99; mso-style-link:"HTML Preformatted"; font-family:Consolas;} span.EmailStyle24 {mso-style-type:personal-reply; font-family:"Aptos",sans-serif; color:windowtext;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt; mso-ligatures:none;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} --></style> </head> <body lang=3D"EN-US" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea= k-word"> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">Hi Gergely,<o:p></o= :p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">One thing I know yo= u can do is to write a short draft specifying the options that you need/wan= t, then ask the working group to adopt it. If the working group does = not adopt it, you could ask for only code points (I don’t know if the working group would approve that). <o:p>= </o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">Regards,<o:p></o:p>= </span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">Quynh. <o:p></o:p><= /span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt"><o:p> </o:p></= span></p> <div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in = 4.0pt"> <div> <div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in = 0in 0in"> <p class=3D"MsoNormal"><b><span style=3D"font-size:11.0pt;font-family:"= ;Calibri",sans-serif">From:</span></b><span style=3D"font-size:11.0pt;= font-family:"Calibri",sans-serif"> NGG <[email protected]= etf.org> <br> <b>Sent:</b> Monday, July 6, 2026 11:05 AM<br> <b>To:</b> Falko Strenzke <[email protected]><br> <b>Cc:</b> [email protected]<br> <b>Subject:</b> [EXTERNAL] [openpgp] Re: draft-ietf-openpgp-nist-bp-comp: a= dd Category-5/P-384 combinations<o:p></o:p></span></p> </div> </div> <p class=3D"MsoNormal"><o:p> </o:p></p> <table class=3D"MsoNormalTable" border=3D"0" cellspacing=3D"0" cellpadding= =3D"0" align=3D"left" width=3D"100%" style=3D"width:100.0%"> <tbody> <tr> <td width=3D"0" style=3D"width:.3pt;background:#A6A6A6;padding:5.25pt 1.5pt= 5.25pt 1.5pt"> </td> <td width=3D"100%" style=3D"width:100.0%;background:#EAEAEA;padding:5.25pt = 3.75pt 5.25pt 11.25pt;aspect-ratio: revert !important;background:revert !im= portant;block-size: revert !important;border:revert !important;bottom: reve= rt !important;color:revert !important;color-scheme: revert !important;conte= nt-visibility: revert !important;cursor:revert !important;direction:revert = !important;display:revert !important;font-size:revert !important;height:rev= ert !important;hyphens: revert !important;letter-spacing:revert !important;= line-height:revert !important;margin:revert !important;opacity: revert !imp= ortant;order: revert !important;outline: revert !important;overflow:revert = !important;padding:revert !important;position:revert !important;resize: rev= ert !important;rotate: revert !important;scale: revert !important;tab-size:= revert !important;table-layout:revert !important;text-align:revert !import= ant;text-indent:revert !important;text-orientation: revert !important;text-= overflow: revert !important;text-shadow:revert !important;text-transform:re= vert !important;text-wrap: revert !important;top:revert !important;transiti= on: revert !important;user-select: revert !important;vertical-align:revert = !important;visibility:revert !important;white-space:revert !important;width= :revert !important;word-break:revert !important;word-spacing:revert !import= ant;writing-mode:revert !important;zoom: revert !important"> <div> <p class=3D"MsoNormal" style=3D"mso-element:frame;mso-element-frame-hspace:= 2.25pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-el= ement-anchor-horizontal:column;mso-height-rule:exactly"> <span style=3D"font-size:9.0pt;font-family:"Segoe UI",sans-serif;= color:#212121">You don't often get email from <a href=3D"mailto:[email protected]">[email protected].= org</a>. <a href=3D"https://aka.ms/LearnAboutSenderIdentification"> Learn why this is important</a> <o:p></o:p></span></p> </div> </td> <td width=3D"75" style=3D"width:56.25pt;background:#EAEAEA;padding:5.25pt 3= .75pt 5.25pt 3.75pt;aspect-ratio: revert !important;background:revert !impo= rtant;block-size: revert !important;border:revert !important;bottom: revert= !important;color:revert !important;color-scheme: revert !important;content= -visibility: revert !important;cursor:revert !important;direction:revert !i= mportant;display:revert !important;font-size:revert !important;height:rever= t !important;hyphens: revert !important;letter-spacing:revert !important;li= ne-height:revert !important;margin:revert !important;opacity: revert !impor= tant;order: revert !important;outline: revert !important;overflow:revert !i= mportant;padding:revert !important;position:revert !important;resize: rever= t !important;rotate: revert !important;scale: revert !important;tab-size: r= evert !important;table-layout:revert !important;text-align:revert !importan= t;text-indent:revert !important;text-orientation: revert !important;text-ov= erflow: revert !important;text-shadow:revert !important;text-transform:reve= rt !important;text-wrap: revert !important;top:revert !important;transition= : revert !important;user-select: revert !important;vertical-align:revert !i= mportant;visibility:revert !important;white-space:revert !important;width:r= evert !important;word-break:revert !important;word-spacing:revert !importan= t;writing-mode:revert !important;zoom: revert !important;align: left !impor= tant"> </td> </tr> </tbody> </table> <div> <div> <p class=3D"gmail-pdq2pgselectionanchorcontainer">Hello Falko,<o:p></o:p></= p> <p>Thanks for the question.<o:p></o:p></p> <p>I did not mean that any single one of the existing profiles requires bot= h hybrid use and category-5 ML-* alone.<o:p></o:p></p> <p>My point is interoperability across profiles: some environments allow P-= 384 but not P-521, while other requirements may call for category-5 ML-*. I= mplementations may need one standardized hybrid option that works across as= many such environments as possible.<o:p></o:p></p> <p>So the goal is not to satisfy a single profile with one algorithm choice= , but to define an optional P-384/category-5 combination that is broadly us= able across multiple profiles and avoids private, non-standard combinations= .<o:p></o:p></p> <p>Best regards,<br> Gergely<o:p></o:p></p> </div> <p class=3D"MsoNormal"><o:p> </o:p></p> <div> <div> <p class=3D"MsoNormal">Falko Strenzke <<a href=3D"mailto:falko.strenzke@= mtg.de">[email protected]</a>> ezt =EDrta (id=F5pont: 2026. j=FAl. 6= ., H, 16:35):<o:p></o:p></p> </div> <blockquote style=3D"border:none;border-left:solid #CCCCCC 1.0pt;padding:0i= n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in"> <div> <div> <div> <p class=3D"MsoNormal">Hi Gergely,<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">On Sat, 2026-06-20 at 22:56 +0200, NGG wrote:<o:p></= o:p></p> </div> <blockquote style=3D"border:none;border-left:solid #729FCF 1.5pt;padding:0i= n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in"> <div> <p class=3D"MsoNormal">Hello OpenPGP WG,<br> <br> I would like to suggest adding the following optional combinations to = draft-ietf-openpgp-nist-bp-comp:<br> <br> * ML-KEM-1024+ECDH-NIST-P-384<br> * ML-DSA-87+ECDSA-NIST-P-384<br> <br> The current draft pairs the category-5 ML-* parameter sets only with P= -521, while P-384 is paired with category-3.<br> <br> The motivation is compliance interoperability. <o:p></o:p></p> <div> <p class=3D"MsoNormal">Some deployed profiles, including CNSA 1.0 and = NATO FMN certificate profiles, admit P-384 but not P-521. <o:p></o:p></p> <div> <p class=3D"MsoNormal">Separately, other policies or deployment requirement= s may call for the category-5 ML-* parameter sets.<o:p></o:p></p> </div> </div> </div> </blockquote> <div> <p class=3D"MsoNormal">What requirements of profiles are you exactly referr= ing to? CNSA does not require multi-algorithm at all, so for this purpose t= he security level of the traditional component should not matter. In fact i= t could simply be ignored for the signature at least.<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">Falko<o:p></o:p></p> </div> <blockquote style=3D"border:none;border-left:solid #729FCF 1.5pt;padding:0i= n 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in"> <div> <div> <div> <div> <p class=3D"MsoNormal"><br> These are not necessarily requirements imposed by the same profile, but&nbs= p;software may need to operate across several such environments.<o:p></o:p>= </p> </div> <div> <p class=3D"MsoNormal">Standardized P-384/category-5 combinations would pro= vide a useful intersection.<br> <br> There is already relevant IETF precedent:<br> <br> * The TLS ECDHE-MLKEM specification defines SecP384r1MLKEM1024.<br> * The LAMPS composite-signature specification defines id-MLDSA87-ECDSA-P384= -SHA512.<br> <br> These combinations could be added alongside the existing P-521 variants,&nb= sp;without changing or replacing them.<br> <br> Would the WG consider adding them?<br> <br> Best regards, <o:p></o:p></p> <div> <p class=3D"MsoNormal">Gergely Nagy<o:p></o:p></p> </div> </div> </div> </div> </div> <pre>_______________________________________________<o:p></o:p></pre> <pre>openpgp mailing list -- <a href=3D"mailto:[email protected]" target=3D"= _blank">[email protected]</a><o:p></o:p></pre> <pre>To unsubscribe send an email to <a href=3D"mailto:[email protected]= rg" target=3D"_blank">[email protected]</a><o:p></o:p></pre> </blockquote> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <pre>-- <o:p></o:p></pre> <div> <p class=3D"MsoNormal">MTG AG<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">Dr. Falko Strenzke<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">Phone: +49 6151 8000 24<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">E-Mail: <a href=3D"mailto:[email protected]" tar= get=3D"_blank"> [email protected]</a><o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">Web: <a href=3D"http://mtg.de/" target=3D"_blank">mt= g.de</a><o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany<o:= p></o:p></p> </div> <div> <p class=3D"MsoNormal">Commercial register: HRB 8901<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">Register Court: Amtsgericht Darmstadt<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">Management Board: J=FCrgen Ruf (CEO), Tamer Kemer=F6= z<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">Chairman of the Supervisory Board: Dr. Thomas Milde<= o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">This email may contain confidential and/or privilege= d information. If you are not the correct recipient or have received this e= mail in error,<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">please inform the sender immediately and delete this= email.Unauthorised copying or distribution of this email is not permitted.= <o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">Data protection information: Privacy policy<o:p></o:= p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> </div> </div> </div> </blockquote> </div> </div> </div> </div> </body> </html> --_000_MW4PR09MB100599C553AD71CC5B4E8333DF3F02MW4PR09MB10059na_-- --===============1696518308132769704== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kb3BlbnBncCBt YWlsaW5nIGxpc3QgLS0gb3BlbnBncEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVt YWlsIHRvIG9wZW5wZ3AtbGVhdmVAaWV0Zi5vcmcK --===============1696518308132769704==--