[saag] Re: [External⚠️] post quantum guidanc e draft
Yaroslav Rosomakho <[email protected]> Thu, 4 Dec 2025 10:59:04 +0000
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CAMtubr351Je=bkW3jDY=oVeoMc7RDucY1_ybXnDGSaJQU8WH-A@mail.gmail.com> |
Hi Stephen, Thanks for driving this discussion. I do think there is value in a document that provides implementers and deployers with concrete guidance as they navigate PQC adoption. Given the pace at which new PQ codepoints are appearing across registries, having a consolidated view could help reduce confusion. At the same time, I believe the guidance needs to reflect a broader set of deployment realities. The current “use hybrid KEM and avoid PQ signatures for now” line of thinking may reflect rough consensus for general web use, but we all know there are other environments (constrained devices, regulated sectors, long-lived systems, and similar profiles) where the trade-offs look quite different. Many of these have been debated extensively across TLS, LAMPS, and other lists. For such a document to be useful, I think it needs to present these perspectives transparently, along with the pros and cons of the different choices. If we find that we cannot reasonably capture the range of legitimate use cases and viewpoints in a single piece of guidance, then it may be better to acknowledge that and not pursue the document further. Given the typical temperature of PQC related discussions I suspect finding a rough consensus will not be easy. -yaroslav On Mon, Dec 1, 2025 at 1:38 PM Stephen Farrell <[email protected]> wrote: > > Hiya, > > We chatted a bit about [1] at the secdispatch session > in Montreal and the sort-of outcome was that further > discussion should be on this list. I've updated [1] a > little bit in the meantime. > > I heard various reactions to [1] at secdispatch and > in subsequent chats with a few people, those included: > > 1. we need something like this (maybe this text or some > other, but some general guidance is needed) > 2. we don't need this, specific WGs should provide whatever > guidance is needed, if any > 3. we shouldn't bother with this at all, it's just a waste > of time and will go nowhere > > There are likely other positions on this too of course. > > Given that we've probably hit 100 new PQ codepoints over > the various IANA registries (anyone counted 'em all?), I'm > clearly in favour of #1 above. #2 seems likely to make > for more confusion and be quite slow, and while #3 > might turn out to be the case, I think we owe it to > people using our stuff to give it a shot. > > Cheers, > S. > > PS: For those who don't read the draft:-) It doesn't say > anything about what WGs should do, it's only about what > people deploying stuff ought do in the near term. > > [1] https://datatracker.ietf.org/doc/draft-farrell-tls-pqg/ > > _______________________________________________ > saag mailing list -- [email protected] > To unsubscribe send an email to [email protected] > -- This communication (including any attachments) is intended for the sole use of the intended recipient and may contain confidential, non-public, and/or privileged material. Use, distribution, or reproduction of this communication by unintended recipients is not authorized. If you received this communication in error, please immediately notify the sender and then delete all copies of this communication from your system. _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]