[saag] Re: post quantum guidance draft
Stephen Farrell <[email protected]> Fri, 12 Dec 2025 16:25:25 +0000
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Hiya, On 12/12/2025 13:52, Salz, Rich wrote: > I guess I was too cute, trying for a Lord of the Rings reference. I > didn’t mean “rule” in any real sense of constraining what IETF WG’s > do. Each of the many WGs you summarize wants to do PQ stuff and > thinks they should. An IETF document that says “this part is fine, > but maybe don’t do that part right now” is going to contradict all > those efforts. Well, it's not saying "don't do" to implemeters but rather "don't deploy" to those deploying. But, it's a fair point to say that if a WG has developed PQ deployment guidance for a protocol, then that specific guidance should over-ride more generic guidance. I think having this (proposed) document could also make it easier for WGs to finish their work, e.g. if we have general guidance for hybrid KEMs (or x25519 and ML-KEM) that might reduce the friction in WGs when they want to define other codepoints that could be controversial in the absence of general guidance. > As for near-term guidance, how do we know when the time has come? The time for this guidance (IMO:-) is... now. And the time to supercede it is when we know how to do sigs for email and the web and related PKIs. Maybe in a year or two. After that, maybe when there's some credible PQ story from plants or related to dnssec. Cheers, S. _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
OpenPGP_signature.asc
(application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE----- wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCaTxB9QUDAAAAAAAKCRDk2On5l6gz3XOA AQD+P+q/ZcwPrVcXLGnlK/3lL9GEj5wRjs8sNpjAxd4OQwEAn8LiSSDgq64K/U7HFlN1GlzzAp+w 4ipSz6jzXTb43A4= =P9R8 -----END PGP SIGNATURE-----