[CFRG] [Errata Verified] RFC8554 (7409)

RFC Errata System <rfc-editor@rfc-editor.org> Tue, 27 January 2026 20:35 UTC

Return-Path: <wwwrun@rfcpa.rfc-editor.org>
X-Original-To: cfrg@irtf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from rfcpa.rfc-editor.org (unknown [167.172.21.234]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id E0D3EADECB41; Tue, 27 Jan 2026 12:35:57 -0800 (PST)
Received: by rfcpa.rfc-editor.org (Postfix, from userid 461) id CABD6C000CE0; Tue, 27 Jan 2026 12:35:57 -0800 (PST)
To: peter.c@ncsc.gov.uk, mcgrew@cisco.com, micurcio@cisco.com, sfluhrer@cisco.com
From: RFC Errata System <rfc-editor@rfc-editor.org>
Content-Type: text/plain; charset="UTF-8"
Message-Id: <20260127203557.CABD6C000CE0@rfcpa.rfc-editor.org>
Date: Tue, 27 Jan 2026 12:35:57 -0800
Message-ID-Hash: THYEREC7UOLCSX6ZD7NBUUEXSIL3BWYA
X-Message-ID-Hash: THYEREC7UOLCSX6ZD7NBUUEXSIL3BWYA
X-MailFrom: wwwrun@rfcpa.rfc-editor.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: irsg@irtf.org, cfrg@irtf.org, iana@iana.org, rfc-editor@rfc-editor.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] [Errata Verified] RFC8554 (7409)
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/MK4V8I3gopPOMGO-IJo9M_LBDCw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

The following errata report has been verified for RFC8554,
"Leighton-Micali Hash-Based Signatures". 

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid7409

--------------------------------------
Status: Verified
Type: Technical

Reported by: Peter Campbell <peter.c@ncsc.gov.uk>
Date Reported: 2023-03-29
Verified by: Nick Sullivan (IRSG)

Section: Section 6.4, Table 3

Original Text
-------------
   +---------+------------+---------+-------------+ 
   | ParmSet | KeyGenTime | SigSize | KeyLifetime | 
   +---------+------------+---------+-------------+ 
                         ... 

   | 15/10   | 6 sec      | 3172    | 9 hours     | 
   |         |            |         |             | 
   | 15/15   | 6 sec      | 3332    | 12 days     | 
   |         |            |         |             | 
   | 20/10   | 3 min      | 3332    | 12 days     | 
   |         |            |         |             | 
   | 20/15   | 3 min      | 3492    | 1 year      | 
   |         |            |         |             | 
   | 25/10   | 1.5 hour   | 3492    | 1 year      | 
   |         |            |         |             | 
   | 25/15   | 1.5 hour   | 3652    | 34 years    | 
   +---------+------------+---------+-------------+ 
 

Corrected Text
--------------
   +---------+------------+---------+-------------+ 
   | ParmSet | KeyGenTime | SigSize | KeyLifetime | 
   +---------+------------+---------+-------------+ 
                         ... 

   | 15/10   | 6 sec      | 3124    | 9 hours     | 
   |         |            |         |             | 
   | 15/15   | 6 sec      | 3284    | 12 days     | 
   |         |            |         |             | 
   | 20/10   | 3 min      | 3284    | 12 days     | 
   |         |            |         |             | 
   | 20/15   | 3 min      | 3444    | 1 year      | 
   |         |            |         |             | 
   | 25/10   | 1.5 hour   | 3444    | 1 year      | 
   |         |            |         |             | 
   | 25/15   | 1.5 hour   | 3604    | 34 years    | 
   +---------+------------+---------+-------------+ 


Notes
-----
The signature sizes for the two-level HSS parameters in Table 3 are all 48 bytes larger than they should be.  It looks like they were computed assuming a 64-byte identifier I in the level-1 LMS public key pub[1],  but the identifier was reduced to 16 bytes in draft -07.  The signature sizes for the single-level HSS parameters are all correct because they do not have intermediate LMS public keys.

--------------------------------------
RFC8554 (draft-mcgrew-hash-sigs-15)
--------------------------------------
Title               : Leighton-Micali Hash-Based Signatures
Publication Date    : April 2019
Author(s)           : D. McGrew, M. Curcio, S. Fluhrer
Category            : INFORMATIONAL
Source              : Crypto Forum Research Group
Stream              : IRTF
Verifying Party     : IRSG