[saag] Re: post quantum guidance draft

Tim Hollebeek <[email protected]> Mon, 1 Dec 2025 17:49:31 +0000
Newsgroups gmane.ietf.saag
Message-ID <SN7PR14MB64921262A8157C872EA0018F83DBA@SN7PR14MB6492.namprd14.prod.outlook.com>
I agree with ekr’s analysis and comments. In addition, I think IETF is at it’s best when we spend our time telling people how to do things correctly, instead of publishing documents telling them what not to do, and I agree with ekr that telling the entire world unilaterally and generically to not do signatures is not helpful, and possibly harmful. At the very least, this document will age badly and be one more thing that needs to be updated in the future, possibly multiple times. We can avoid the maintenance work by not working on it or publishing it.

 

-Tim

 

From: Eric Rescorla <[email protected]> 
Sent: Monday, December 1, 2025 9:29 AM
To: Stephen Farrell <[email protected]>
Cc: [email protected]
Subject: [saag] Re: post quantum guidance draft

 

 

 

On Mon, Dec 1, 2025 at 6:15 AM Stephen Farrell <[email protected] <mailto:[email protected]> > wrote:


Hiya,

On 01/12/2025 14:07, Eric Rescorla wrote:
> This revision does not affect my opinion on the value of this work,
> which is not based on the introduction and background.
> 
> I do not believe the IETF should take it up.

It's entirely fair to have that opinion but can you say why?

 

I already did so on SECDISPATCH:

https://mailarchive.ietf.org/arch/msg/secdispatch/2ae8yAjMc98__3jTkhKWi-JHvEg/

 

These comments are about -03, but as I said, they continue to apply.

 

-Ekr

 


Ta,
S.


> 
> -Ekr
> 
> 
> On Mon, Dec 1, 2025 at 4:38 AM Stephen Farrell <[email protected] <mailto:[email protected]> >
> wrote:
> 
>>
>> Hiya,
>>
>> We chatted a bit about [1] at the secdispatch session
>> in Montreal and the sort-of outcome was that further
>> discussion should be on this list. I've updated [1] a
>> little bit in the meantime.
>>
>> I heard various reactions to [1] at secdispatch and
>> in subsequent chats with a few people, those included:
>>
>> 1. we need something like this (maybe this text or some
>>      other, but some general guidance is needed)
>> 2. we don't need this, specific WGs should provide whatever
>>      guidance is needed, if any
>> 3. we shouldn't bother with this at all, it's just a waste
>>      of time and will go nowhere
>>
>> There are likely other positions on this too of course.
>>
>> Given that we've probably hit 100 new PQ codepoints over
>> the various IANA registries (anyone counted 'em all?), I'm
>> clearly in favour of #1 above. #2 seems likely to make
>> for more confusion and be quite slow, and while #3
>> might turn out to be the case, I think we owe it to
>> people using our stuff to give it a shot.
>>
>> Cheers,
>> S.
>>
>> PS: For those who don't read the draft:-) It doesn't say
>> anything about what WGs should do, it's only about what
>> people deploying stuff ought do in the near term.
>>
>> [1] https://datatracker.ietf.org/doc/draft-farrell-tls-pqg/
>>
>> _______________________________________________
>> saag mailing list -- [email protected] <mailto:[email protected]> 
>> To unsubscribe send an email to [email protected] <mailto:[email protected]> 
>>
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 4.9 KB) - not displayed