[saag] Re: [External⚠️] post quantum guidanc e draft

Yaroslav Rosomakho <[email protected]> Thu, 4 Dec 2025 10:59:04 +0000
Newsgroups gmane.ietf.saag
Message-ID <CAMtubr351Je=bkW3jDY=oVeoMc7RDucY1_ybXnDGSaJQU8WH-A@mail.gmail.com>
Hi Stephen,

Thanks for driving this discussion.

I do think there is value in a document that provides implementers and
deployers with concrete guidance as they navigate PQC adoption. Given the
pace at which new PQ codepoints are appearing across registries, having a
consolidated view could help reduce confusion.

At the same time, I believe the guidance needs to reflect a broader set of
deployment realities. The current “use hybrid KEM and avoid PQ signatures
for now” line of thinking may reflect rough consensus for general web use,
but we all know there are other environments (constrained devices,
regulated sectors, long-lived systems, and similar profiles) where the
trade-offs look quite different. Many of these have been debated
extensively across TLS, LAMPS, and other lists.

For such a document to be useful, I think it needs to present these
perspectives transparently, along with the pros and cons of the different
choices. If we find that we cannot reasonably capture the range of
legitimate use cases and viewpoints in a single piece of guidance, then it
may be better to acknowledge that and not pursue the document further.
Given the typical temperature of PQC related discussions I suspect finding
a rough consensus will not be easy.

-yaroslav


On Mon, Dec 1, 2025 at 1:38 PM Stephen Farrell <[email protected]>
wrote:

>
> Hiya,
>
> We chatted a bit about [1] at the secdispatch session
> in Montreal and the sort-of outcome was that further
> discussion should be on this list. I've updated [1] a
> little bit in the meantime.
>
> I heard various reactions to [1] at secdispatch and
> in subsequent chats with a few people, those included:
>
> 1. we need something like this (maybe this text or some
>     other, but some general guidance is needed)
> 2. we don't need this, specific WGs should provide whatever
>     guidance is needed, if any
> 3. we shouldn't bother with this at all, it's just a waste
>     of time and will go nowhere
>
> There are likely other positions on this too of course.
>
> Given that we've probably hit 100 new PQ codepoints over
> the various IANA registries (anyone counted 'em all?), I'm
> clearly in favour of #1 above. #2 seems likely to make
> for more confusion and be quite slow, and while #3
> might turn out to be the case, I think we owe it to
> people using our stuff to give it a shot.
>
> Cheers,
> S.
>
> PS: For those who don't read the draft:-) It doesn't say
> anything about what WGs should do, it's only about what
> people deploying stuff ought do in the near term.
>
> [1] https://datatracker.ietf.org/doc/draft-farrell-tls-pqg/
>
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

-- 


This communication (including any attachments) is intended for the sole 
use of the intended recipient and may contain confidential, non-public, 
and/or privileged material. Use, distribution, or reproduction of this 
communication by unintended recipients is not authorized. If you received 
this communication in error, please immediately notify the sender and then 
delete all copies of this communication from your system.

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]