[saag] Re: post quantum guidance draft

"Bellebaum, Thomas" <[email protected]> Fri, 12 Dec 2025 09:02:23 +0000
Newsgroups gmane.ietf.saag
Message-ID <b065a457c1f1b21aa337cc3aa71a715bfe938d32.camel@aisec.fraunhofer.de>
Hi John,

> A common position is that there is a meaningful chance of a CRQC being built within the next 15 years. If that assumption is true, then we urgently need to migrate signatures in long-lived devices. Recommending inaction in that scenario is like having your house on fire, arguing about whether to use a powder or foam extinguisher, and ultimately deciding to recommend doing nothing.

Yeah, I originally wrote something about long-term authenticity. Stephen eventually changed that to

> Systems dealing with signatures that are required to still be
> usefully verifiable in the timeframe that might include a CRQC are
> rare and complex and are not further considered here. Systems that
> need to select a signature verification public key (and hence
> algorithm) now, for use in some years time, are also not covered by
> this guidance.

FWIW I think for a first guidance document this direction is a good balance. It makes for a short recommendation section for common scenarios yet is still explicit about such use cases. I would like the "For almost all deployments" in section 3.2 to become more explicit eventually (e.g. "For data/peer authentication within the next few years"; it is ok if this somewhat limits the scope to use cases we feel more confident about) and the "rare and complex" in the justification section to be more helpful in deciding whether or not $my_use_case might require worring further about such things.
But I feel like those are details we could work out :)

Best,

-- TBB

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 6.6 KB) - not displayed