[TLS] tls-composite-mldsa downgrade to ML-DSA
Ilari Liusvaara <[email protected]>
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <[email protected]> |
Noticed this when reviewing draft-reddy-tls-composite-mldsa-10: While the security considerations does discuss downgrade to traditional authentication, it does not discuss downgrade to stand-alone ML-DSA. Such downgrade would be pointless if one fully trusted ML-DSA. However, the whole point of composite authentication is not to fully trust either component, so such downgrade needs to be taken into account. In general, TLS Relying Party fully trusts any signature algorithm it accepts. And thus mitigating the issue is up to Relying Party policy. I think accepting both composite and stand-alone ML-DSA only makes sense if composites are being deprecated for stand-alone PQ. This would mean only deploying composites in closed environments or with security profile standard. Relying Parties enforce the use of acceptable algorithms, which has presumably been narrowed to something manageable. -Ilari _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]