[TLS] tls-composite-mldsa downgrade to ML-DSA

Ilari Liusvaara <[email protected]>
Newsgroups gmane.ietf.tls
Message-ID <[email protected]>
Noticed this when reviewing draft-reddy-tls-composite-mldsa-10:

While the security considerations does discuss downgrade to traditional
authentication, it does not discuss downgrade to stand-alone ML-DSA.
Such downgrade would be pointless if one fully trusted ML-DSA. However,
the whole point of composite authentication is not to fully trust either
component, so such downgrade needs to be taken into account.

In general, TLS Relying Party fully trusts any signature algorithm it
accepts. And thus mitigating the issue is up to Relying Party policy.

I think accepting both composite and stand-alone ML-DSA only makes
sense if composites are being deprecated for stand-alone PQ. This
would mean only deploying composites in closed environments or with
security profile standard. Relying Parties enforce the use of acceptable
algorithms, which has presumably been narrowed to something manageable.




-Ilari

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.