[saag] Re: post quantum guidance draft

Watson Ladd <[email protected]> Thu, 11 Dec 2025 14:27:34 -0800
Newsgroups gmane.ietf.saag
Message-ID <CACsn0ck1+SOasuQxUZKmAyMDEpQexnTzn6HzM=jvpYeA7bs+fg@mail.gmail.com>
On Thu, Dec 11, 2025 at 1:18 PM Salz, Rich
<[email protected]> wrote:
>
> For a project [1] we're part of, (where I'm the resident PQ
> skeptic:-), I had to do a bit of a survey of ongoing IETF PQ
> work and produced [2] which has just been put up on the web
> page for the project following some local bureaucracy.
>
>
> Thanks for the work and making this available. The current survey of IETF work seems even-handed. I’m not sure it gives much justification for your draft, tho.
>
> Do you think all the WGs will end up using the same signature algorithms?
>
> Many people dislike the multiplicative impact of, for example, the three sizes of ML-DSA.  Me too. It’s unfortunate that they’re made explicit. RSA, for example, uses the same identifiers no matter the key size, so I’m not sure it’s right to count that as an argument against PQ por PQ/T signatures.

To adapt an old joke about Baptists (or Trotskyists)
"We support RSA"
"Oh me too. RSA-1025, RSA-2048 or RSA-4096"
"RSA-2048"
"RSA-PSS or RSA-PKCS 1.5"
"RSA-PSS"
"Salt length equal to hash or maximal"
"Maximal"
"Interop failure"

Having explicit indicators makes providing good error messages easier
for programmers, which then helps  adminstrators and users.

Sincerely,
Watson
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]



-- 
Astra mortemque praestare gradatim

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]