[COSE] [OPS-DIR] draft-ietf-cose-dilithium call Opsdir review

tirumal reddy <kondtir@gmail.com> Wed, 10 September 2025 13:32 UTC

Return-Path: <kondtir@gmail.com>
X-Original-To: cose@mail2.ietf.org
Delivered-To: cose@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 94891606A9AD; Wed, 10 Sep 2025 06:32:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8kBYxMUAjvLC; Wed, 10 Sep 2025 06:32:20 -0700 (PDT)
Received: from mail-ed1-x52b.google.com (mail-ed1-x52b.google.com [IPv6:2a00:1450:4864:20::52b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id A2175606A92A; Wed, 10 Sep 2025 06:31:57 -0700 (PDT)
Received: by mail-ed1-x52b.google.com with SMTP id 4fb4d7f45d1cf-624fdf51b44so4922663a12.1; Wed, 10 Sep 2025 06:31:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1757511116; x=1758115916; darn=ietf.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=SLKDdgl/AsdRzsJRCQ2cAiZZ/dzy0SlnA4EZXRH8i2A=; b=GANRNLsybBDPpiuqbk8C3J/NN6PvNB3eI10eYd72eqMmfIHpDYaITbrr/oy5x3F1VR ob+1m6pj7KQqwSaVr28XMxR8HRg0ERXobVjAmNQjUEONczTRKh/XclozEDVXp9kmzSWp t5MJplFERyjT4wnphRpaxj2dpCtxTJYDbcclgcVPL9HfkI5qjhQtGv8yY/Gd0rBXPCPg ySLTM397cufGUbVBuI4/twl8WCckyhUKIr7/TQ3D0G16ETc69lqdjJbwe4lrRhck3uaZ nfK8A1ixhtT1WhR6JkqPgDK+aZnvYdsrBXf5FBz7DqZ+y0HcJNbZSDWFsTTPKGahcPmX qJTA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1757511116; x=1758115916; h=to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=SLKDdgl/AsdRzsJRCQ2cAiZZ/dzy0SlnA4EZXRH8i2A=; b=p3FABIz1c0QMfa+16OEt6LKFSC6HkgisWmyBzdoxgWuQZs22fYFMtbH6L4Y2tdHU0H tOwTI85sqqbahpU4zV990X9JUejcIRa/5u9jqhisfHAkMM1T1ulVNJyG+Ydi91hhBKw6 mUgzwVmVD4mVISaQU3ISJWrohW+wtWsK5kwq8AzRT2H3OUsL3k0XGkA+s7NboP753zan CI4anpbyRkRZ4oVR83sIiwuJZ4HGS3ANSETiSJ5zieOrIQf13BZJU9uTma+BHco4L9zY eYzWrWjijJ/lTZIKqFnlUSgPNNLi/LE4tYBOAt5hnLuwPxkxNYiJqMk0nN08BsMSASYM e/LA==
X-Forwarded-Encrypted: i=1; AJvYcCVH3pBLYe+cB0b/UXd/ZkT94CHxaMSasX7M1thgm2/hXo7DqdyKAuGjJ2BJc73c5YQyVid4EHqGiTFmv04XC5LJfbmT9cHMm9BFHDJ8Sq8=@ietf.org, AJvYcCVYgvR9uwchta9KqYctR1UsxcDkhXQwUrx2vN0lOhBSNHYOvI8VF2Z+N55sOmslNhKEgXyzeA==@ietf.org, AJvYcCXOhILKrgvdT/jJhZVjJXtHBxWI0CMD2XWRsxmA1R1svap0trlksMJvbhGVJbt+guKCCXNy@ietf.org, AJvYcCXVKbIY0AyO3E84EwMICJq+iMBP3um6xAgkymZhj/URRTWLhVgkpjvlb+OMzKprq99EaTkoMkaLsqTa@ietf.org
X-Gm-Message-State: AOJu0Ywpz73saqiKEe5622sktg+Kgf5bfSD0plUaD7jc4nvIBu3HdRce PbqPSzDcpDGuNv0xJ1JdkdLkCqfUg+IYTz4ENkIC6JRx96p6qQ4JQmYPG/fPiKqALx99D2nMo8g eA1GgioV58Ua+gsg2+Zy1mPHm7OuvcY4rxO9V0MY=
X-Gm-Gg: ASbGncuTA3x9nF51/86i+/FrXG4aHm6+5uiDuGq3W0L+llc7VLMAYOoBKyuyCYKcCa9 HWjkCC8BJyVm+SqhZkJFEzGy3FZplIGBkK63am5Q97JPRJV+tdQb6CED3/fiVPmvhypcwuAQ4WX dq3q15nHCISHUfAEFelwCzeEpzBhv/AHaN6dtOwY+3I8k8oKIk+mm/C0iK/w46bAR8nAQ3tXdtl OPgaUqaUw==
X-Google-Smtp-Source: AGHT+IGCsF5yZQGmuiGA3dWmXf/VUBtPUdu/XmygqhPRe/7ifT0p15jrSyb+KhSp0kp0gFvAOj9CmuSKGLYgi9/bRBo=
X-Received: by 2002:a05:6402:5203:b0:627:6281:e441 with SMTP id 4fb4d7f45d1cf-6276281e8d7mr11495106a12.23.1757511116059; Wed, 10 Sep 2025 06:31:56 -0700 (PDT)
MIME-Version: 1.0
From: tirumal reddy <kondtir@gmail.com>
Date: Wed, 10 Sep 2025 19:01:19 +0530
X-Gm-Features: AS18NWCZFavjMKPMs9gp01Y0k4Bp94U9e9ug4Bh5uQ6dqllsVpmkpX6ivOzxpF8
Message-ID: <CAFpG3gdU5945E4rcHTLWvZdD_RFeER-dw9jXimb2_G6UPfqAUQ@mail.gmail.com>
To: ops-dir@ietf.org, Last Call <last-call@ietf.org>, draft-ietf-cose-dilithium.all@ietf.org, JOSE WG <jose@ietf.org>, cose <cose@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000c2faf0063e7271d3"
Message-ID-Hash: MWGWG6QMW5XFPY3MKA3UWJSAUXTDCBIC
X-Message-ID-Hash: MWGWG6QMW5XFPY3MKA3UWJSAUXTDCBIC
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cose.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [COSE] [OPS-DIR] draft-ietf-cose-dilithium call Opsdir review
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/1-yzyM7d5Z18hzNjT12efw9y-qM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Owner: <mailto:cose-owner@ietf.org>
List-Post: <mailto:cose@ietf.org>
List-Subscribe: <mailto:cose-join@ietf.org>
List-Unsubscribe: <mailto:cose-leave@ietf.org>

Document: draft-ietf-cose-dilithium
Title: ML-DSA for JOSE and COSE
Reviewer: Tirumaleswar Reddy
Review result: "Ready with Issues"

Hi,

I have reviewed this document as part of the Ops Area Directorate's ongoing
effort to review all IETF documents being processed by the IESG. These
comments are written primarily for the benefit of the Ops Area Directors.
Document editors and WG chairs should treat them like any other Last Call
comments.

The draft is well-written and addresses an important need for PQC
migration.  I have a few operational and deployment-related observations
that may help improve the document:

1. ML-DSA produces significantly larger public keys and signatures compared
to traditional algorithms. This size increase can create challenges for
deployments with limited bandwidth, memory, or processing capacity.  I
suggest adding text to highlight it.

2. I suggest adding a reference to Section 8.3 of
draft-ietf-lamps-dilithium-certificates, which explains the rationale for
disallowing HashML-DSA.

3. It may be useful to add a note to explain why only the seed format was
chosen for private keys, given that the LAMPS WG selected the expanded
private key format to maximize interoperability with existing
implementations.

4. You may want to refer to the security considerations in
https://datatracker.ietf.org/doc/draft-ietf-lamps-dilithium-certificates/
and discuss if randomized signing is preferred over deterministic signing.

Cheers,
-Tiru