[art] Re: draft-ietf-pquip-hbs-state-02 ietf last call Artart review

Stavros Kousidis <kousidis.ietf@gmail.com> Mon, 26 January 2026 19:02 UTC

Return-Path: <kousidis.ietf@gmail.com>
X-Original-To: art@mail2.ietf.org
Delivered-To: art@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E82DDAD5599C for <art@mail2.ietf.org>; Mon, 26 Jan 2026 11:02:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.098
X-Spam-Level:
X-Spam-Status: No, score=-1.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kmM9J6QMQMzT for <art@mail2.ietf.org>; Mon, 26 Jan 2026 11:02:04 -0800 (PST)
Received: from mail-wr1-x42f.google.com (mail-wr1-x42f.google.com [IPv6:2a00:1450:4864:20::42f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4F952AD55976 for <art@ietf.org>; Mon, 26 Jan 2026 11:02:04 -0800 (PST)
Received: by mail-wr1-x42f.google.com with SMTP id ffacd0b85a97d-43590777e22so2941379f8f.3 for <art@ietf.org>; Mon, 26 Jan 2026 11:02:04 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1769454117; x=1770058917; darn=ietf.org; h=in-reply-to:from:content-language:references:cc:to:subject :user-agent:mime-version:date:message-id:from:to:cc:subject:date :message-id:reply-to; bh=yQJcesPjmKBITgsnDBPiRcwVmxOLjQKdmASVUD1AFuc=; b=iTp4jhhbSXouqL+ZJ4VjMTrZGmBIkQe2d1RyxMy18DNQR0m57x0Wl2zWjkR+TBDP0z lnzCyJVCD7WJ49QgevtfHmRjSRyFBTGZRTqHGr8iU7BAQXLCQkqXsMzWLgUtL8nDfsN+ dyioX9yxO1oO/rIXlHjLyoSfk0qwZbU5yictJMytVDpBMT2RjFh4iWr/9wf1Y85nttmS mIXdB++c5xewwH95V5+XmMKCagVJylTf72HEfJjPmY2MZ2Jmy0H9jEbbi8XQ/84lCl6a ltdFDoIcNU9/Bo+E1MPsCjlRPep6wWaeT7k9kJAT089dfS5WzMmvcB4hxLqug53ZsuVP uplQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769454117; x=1770058917; h=in-reply-to:from:content-language:references:cc:to:subject :user-agent:mime-version:date:message-id:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=yQJcesPjmKBITgsnDBPiRcwVmxOLjQKdmASVUD1AFuc=; b=LaOR8fOlBAEmqTpjKk6rdgrWNC+KC5fiQ8fY+mfFQKx+/UZNdxUj1PmNTquxVmt2ko ygjkR2vpAKIy8Bfv/yOY6qeIhhwaK/vQjHOSbgcy8RJTBUIf436QeFa999bR0nW72jaB jUxHWgDXa9aC7KgGjBFU230GjtKkbgVSSLupgZuQ9E+nXOpodkReys1+lEHkcN/rz/3N aW+e/uq8z9a+25YTRZmye5uRsb3SYPuh41Y/yG94hjLYuE7B40353kuchDoM3+Yl240i ff42lHqdJGEmv5pkKJ82Nfu+OCyT1JkyxZlkO7brLnoTeoQBwuwfADY83vYUByLgG49h ADDg==
X-Forwarded-Encrypted: i=1; AJvYcCUAgbdqV63C44LHvAXaaSkFqeNzdJtMJ1Zwyq/TLzJT2ciDfradzjKHt2oO3zZwziLyWws=@ietf.org
X-Gm-Message-State: AOJu0Yza6oTwPH1ol2aVGfb5+CHtjNk2TfHeZN9B+3DDHETRrZONm0rW yYePy/YPs47rexvYmAT7Ap9mcvQhM+WlylXWPKC4cQJLYtpnU8Ka7oc8
X-Gm-Gg: AZuq6aLiaX53ycKuxgN9LhVvNWDqpHYFCf2CGEfRyqPqZo3rRLaWRkHf0Nlj4uYC4jz ZdM+V3KR1cLE9lvM+zZRVuxUh6I290tg0ghb5/ZfDjD6svzrBbqyNDuW33RSFM4cju19rIfcekN eVo2+Pa77i7L2ZKBeNFvnH2rtAkzMtLGbtHhDYUFjOYLVvTMSLfeR1grkeusnejxTooWOerVgI6 Oeot4u/Z2wEMzG+yZT9nDfjJuD/e56ulySHUWsyrDjztbYSX5+HveKMGmK3iw48DPJyqm1RrGqc yg7z2l2qk1u/L0jq7s7z/ceANmLC3+mzG8l8W6PrNXKHumd0euw+uXp8B4tpIr713KRfqtn1Gnz M+oVbPzHK/fUTsg2A6TRoZesUgseEMDFVoNbav37cmtDah+e/RshJFmHm6QzIatdMolEAsYzGKi JQT7Qv72zhSXmCKMcWN0FFp1QdHln2CZHJmmT9gRwlZfl26p9dl5qts3pU0g==
X-Received: by 2002:a5d:5f54:0:b0:435:ad52:31d9 with SMTP id ffacd0b85a97d-435ca1204a8mr9342565f8f.28.1769454116696; Mon, 26 Jan 2026 11:01:56 -0800 (PST)
Received: from ?IPV6:2a02:b30:fa9:ff00:25d0:b00c:1f97:1f9? ([2a02:b30:fa9:ff00:25d0:b00c:1f97:1f9]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-435b1e71562sm31794529f8f.21.2026.01.26.11.01.55 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 26 Jan 2026 11:01:56 -0800 (PST)
Content-Type: multipart/alternative; boundary="------------S3E0jSlt0S1FUSNXlsIQU0xY"
Message-ID: <153c4630-5cce-4c78-bf32-12ec8f51c469@gmail.com>
Date: Mon, 26 Jan 2026 20:01:54 +0100
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Jiankang Yao <yaojk@cnnic.cn>, art@ietf.org
References: <176853972889.809.4710697395942252056@dt-datatracker-865585c994-4fgh4>
Content-Language: en-US
From: Stavros Kousidis <kousidis.ietf@gmail.com>
In-Reply-To: <176853972889.809.4710697395942252056@dt-datatracker-865585c994-4fgh4>
Message-ID-Hash: 7BYIEUV46JLPFNC2VQQWLTW6EVMN4I36
X-Message-ID-Hash: 7BYIEUV46JLPFNC2VQQWLTW6EVMN4I36
X-MailFrom: kousidis.ietf@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-art.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-pquip-hbs-state.all@ietf.org, last-call@ietf.org, pqc@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [art] Re: draft-ietf-pquip-hbs-state-02 ietf last call Artart review
List-Id: Applications and Real-Time Area Discussion <art.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/art/M6ojYS5ytFWHO9nyJ2B6OsUq_nc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/art>
List-Help: <mailto:art-request@ietf.org?subject=help>
List-Owner: <mailto:art-owner@ietf.org>
List-Post: <mailto:art@ietf.org>
List-Subscribe: <mailto:art-join@ietf.org>
List-Unsubscribe: <mailto:art-leave@ietf.org>

Dear Jiankang,

Thank you for taking the time to review the document and for your 
helpful feedback.

Regarding your suggestion to add usage scenarios: the draft already 
provides a high-level discussion of typical deployment contexts for 
stateful hash-based signature schemes. In addition, RFC 9802 (Section 
“Use Cases of Stateful HBS”) discusses concrete use cases, including 
their application in X.509. We have also addressed your comment by 
adding references to other standards that recommend or require LMS/HSS 
and/or XMSS support (e.g., CNSA 2.0 and SUIT MTI) in PR #47 
(https://github.com/hbs-guidance/draft-hbs-state/pull/47) rather than 
introducing document-specific usage examples, as such examples tend to 
be highly application-specific and theoretically unbounded.

With respect to adding pseudocode or implementation examples, we believe 
this is out of scope for this document. The draft is intentionally 
focused on conceptual guidance around state and backup management, 
rather than on concrete algorithms or implementation techniques.

Best regards,
On behalf of the authors


On 1/16/26 06:02, Jiankang Yao via Datatracker wrote:
> Document: draft-ietf-pquip-hbs-state
> Title: Hash-based Signatures: State and Backup Management
> Reviewer: Jiankang Yao
> Review result: Almost Ready
>
> I am the assigned ART-ART reviewer for this draft. The Art Area
> Review Team (ART-ART) reviews all IETF documents being processed
> by the IESG.  Please treat these comments just
> like any other last call comments.
>
> Document: draft-ietf-pquip-hbs-state-02
> Reviewer: Jiankang Yao
> Review Date: 2026-01-16
>
> Summary: Almost Ready.
>
> This document describes Hash-based Signatures: State and Backup Management.
> This document is somewhat complex. It is recommended to add usage scenarios in
> the main text and include pseudocode or implementation examples in the appendix
> to facilitate readers' understanding and comprehension.
>
>