Return-Path: <kondtir@gmail.com>
X-Original-To: cose@mail2.ietf.org
Delivered-To: cose@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1])
	by mail2.ietf.org (Postfix) with ESMTP id 94891606A9AD;
	Wed, 10 Sep 2025 06:32:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level: 
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
	HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001,
	SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key)
	header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31])
	by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 8kBYxMUAjvLC; Wed, 10 Sep 2025 06:32:20 -0700 (PDT)
Received: from mail-ed1-x52b.google.com (mail-ed1-x52b.google.com
 [IPv6:2a00:1450:4864:20::52b])
	(using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by mail2.ietf.org (Postfix) with ESMTPS id A2175606A92A;
	Wed, 10 Sep 2025 06:31:57 -0700 (PDT)
Received: by mail-ed1-x52b.google.com with SMTP id
 4fb4d7f45d1cf-624fdf51b44so4922663a12.1;
        Wed, 10 Sep 2025 06:31:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20230601; t=1757511116; x=1758115916; darn=ietf.org;
        h=to:subject:message-id:date:from:mime-version:from:to:cc:subject
         :date:message-id:reply-to;
        bh=SLKDdgl/AsdRzsJRCQ2cAiZZ/dzy0SlnA4EZXRH8i2A=;
        b=GANRNLsybBDPpiuqbk8C3J/NN6PvNB3eI10eYd72eqMmfIHpDYaITbrr/oy5x3F1VR
         ob+1m6pj7KQqwSaVr28XMxR8HRg0ERXobVjAmNQjUEONczTRKh/XclozEDVXp9kmzSWp
         t5MJplFERyjT4wnphRpaxj2dpCtxTJYDbcclgcVPL9HfkI5qjhQtGv8yY/Gd0rBXPCPg
         ySLTM397cufGUbVBuI4/twl8WCckyhUKIr7/TQ3D0G16ETc69lqdjJbwe4lrRhck3uaZ
         nfK8A1ixhtT1WhR6JkqPgDK+aZnvYdsrBXf5FBz7DqZ+y0HcJNbZSDWFsTTPKGahcPmX
         qJTA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20230601; t=1757511116; x=1758115916;
        h=to:subject:message-id:date:from:mime-version:x-gm-message-state
         :from:to:cc:subject:date:message-id:reply-to;
        bh=SLKDdgl/AsdRzsJRCQ2cAiZZ/dzy0SlnA4EZXRH8i2A=;
        b=p3FABIz1c0QMfa+16OEt6LKFSC6HkgisWmyBzdoxgWuQZs22fYFMtbH6L4Y2tdHU0H
         tOwTI85sqqbahpU4zV990X9JUejcIRa/5u9jqhisfHAkMM1T1ulVNJyG+Ydi91hhBKw6
         mUgzwVmVD4mVISaQU3ISJWrohW+wtWsK5kwq8AzRT2H3OUsL3k0XGkA+s7NboP753zan
         CI4anpbyRkRZ4oVR83sIiwuJZ4HGS3ANSETiSJ5zieOrIQf13BZJU9uTma+BHco4L9zY
         eYzWrWjijJ/lTZIKqFnlUSgPNNLi/LE4tYBOAt5hnLuwPxkxNYiJqMk0nN08BsMSASYM
         e/LA==
X-Forwarded-Encrypted: i=1;
 AJvYcCVH3pBLYe+cB0b/UXd/ZkT94CHxaMSasX7M1thgm2/hXo7DqdyKAuGjJ2BJc73c5YQyVid4EHqGiTFmv04XC5LJfbmT9cHMm9BFHDJ8Sq8=@ietf.org,
 AJvYcCVYgvR9uwchta9KqYctR1UsxcDkhXQwUrx2vN0lOhBSNHYOvI8VF2Z+N55sOmslNhKEgXyzeA==@ietf.org,
 AJvYcCXOhILKrgvdT/jJhZVjJXtHBxWI0CMD2XWRsxmA1R1svap0trlksMJvbhGVJbt+guKCCXNy@ietf.org,
 AJvYcCXVKbIY0AyO3E84EwMICJq+iMBP3um6xAgkymZhj/URRTWLhVgkpjvlb+OMzKprq99EaTkoMkaLsqTa@ietf.org
X-Gm-Message-State: AOJu0Ywpz73saqiKEe5622sktg+Kgf5bfSD0plUaD7jc4nvIBu3HdRce
	PbqPSzDcpDGuNv0xJ1JdkdLkCqfUg+IYTz4ENkIC6JRx96p6qQ4JQmYPG/fPiKqALx99D2nMo8g
	eA1GgioV58Ua+gsg2+Zy1mPHm7OuvcY4rxO9V0MY=
X-Gm-Gg: ASbGncuTA3x9nF51/86i+/FrXG4aHm6+5uiDuGq3W0L+llc7VLMAYOoBKyuyCYKcCa9
	HWjkCC8BJyVm+SqhZkJFEzGy3FZplIGBkK63am5Q97JPRJV+tdQb6CED3/fiVPmvhypcwuAQ4WX
	dq3q15nHCISHUfAEFelwCzeEpzBhv/AHaN6dtOwY+3I8k8oKIk+mm/C0iK/w46bAR8nAQ3tXdtl
	OPgaUqaUw==
X-Google-Smtp-Source: 
 AGHT+IGCsF5yZQGmuiGA3dWmXf/VUBtPUdu/XmygqhPRe/7ifT0p15jrSyb+KhSp0kp0gFvAOj9CmuSKGLYgi9/bRBo=
X-Received: by 2002:a05:6402:5203:b0:627:6281:e441 with SMTP id
 4fb4d7f45d1cf-6276281e8d7mr11495106a12.23.1757511116059; Wed, 10 Sep 2025
 06:31:56 -0700 (PDT)
MIME-Version: 1.0
From: tirumal reddy <kondtir@gmail.com>
Date: Wed, 10 Sep 2025 19:01:19 +0530
X-Gm-Features: AS18NWCZFavjMKPMs9gp01Y0k4Bp94U9e9ug4Bh5uQ6dqllsVpmkpX6ivOzxpF8
Message-ID: 
 <CAFpG3gdU5945E4rcHTLWvZdD_RFeER-dw9jXimb2_G6UPfqAUQ@mail.gmail.com>
To: ops-dir@ietf.org, Last Call <last-call@ietf.org>,
	draft-ietf-cose-dilithium.all@ietf.org, JOSE WG <jose@ietf.org>,
	cose <cose@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000c2faf0063e7271d3"
Message-ID-Hash: MWGWG6QMW5XFPY3MKA3UWJSAUXTDCBIC
X-Message-ID-Hash: MWGWG6QMW5XFPY3MKA3UWJSAUXTDCBIC
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-cose.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5BCOSE=5D_=5BOPS-DIR=5D_draft-ietf-cose-dilithium_call_Opsdir_rev?=
	=?utf-8?q?iew?=
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/cose/1-yzyM7d5Z18hzNjT12efw9y-qM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Owner: <mailto:cose-owner@ietf.org>
List-Post: <mailto:cose@ietf.org>
List-Subscribe: <mailto:cose-join@ietf.org>
List-Unsubscribe: <mailto:cose-leave@ietf.org>

--000000000000c2faf0063e7271d3
Content-Type: text/plain; charset="UTF-8"

Document: draft-ietf-cose-dilithium
Title: ML-DSA for JOSE and COSE
Reviewer: Tirumaleswar Reddy
Review result: "Ready with Issues"

Hi,

I have reviewed this document as part of the Ops Area Directorate's ongoing
effort to review all IETF documents being processed by the IESG. These
comments are written primarily for the benefit of the Ops Area Directors.
Document editors and WG chairs should treat them like any other Last Call
comments.

The draft is well-written and addresses an important need for PQC
migration.  I have a few operational and deployment-related observations
that may help improve the document:

1. ML-DSA produces significantly larger public keys and signatures compared
to traditional algorithms. This size increase can create challenges for
deployments with limited bandwidth, memory, or processing capacity.  I
suggest adding text to highlight it.

2. I suggest adding a reference to Section 8.3 of
draft-ietf-lamps-dilithium-certificates, which explains the rationale for
disallowing HashML-DSA.

3. It may be useful to add a note to explain why only the seed format was
chosen for private keys, given that the LAMPS WG selected the expanded
private key format to maximize interoperability with existing
implementations.

4. You may want to refer to the security considerations in
https://datatracker.ietf.org/doc/draft-ietf-lamps-dilithium-certificates/
and discuss if randomized signing is preferred over deterministic signing.

Cheers,
-Tiru

--000000000000c2faf0063e7271d3
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Document: draft-ietf-cose-dilithium<br>Title: ML-DSA for J=
OSE and COSE<br>Reviewer: Tirumaleswar Reddy<br>Review result: &quot;Ready =
with Issues&quot;<div><br></div><div>Hi,<br><br>I have reviewed this docume=
nt as part of the Ops Area Directorate&#39;s ongoing effort to review all I=
ETF documents being processed by the IESG. These comments are written prima=
rily for the benefit of the Ops Area Directors. Document editors and WG cha=
irs should treat them like any other Last Call comments.<br><br>The draft i=
s well-written and addresses an important need for PQC migration.=C2=A0 I h=
ave a few operational and deployment-related observations that may help imp=
rove the document:<br><br>1. ML-DSA produces significantly larger public ke=
ys and signatures compared to traditional algorithms. This size increase ca=
n create challenges for deployments with limited bandwidth, memory, or proc=
essing capacity.=C2=A0

I suggest adding text to highlight it.<br><br>2. I suggest adding a referen=
ce to Section 8.3 of draft-ietf-lamps-dilithium-certificates, which explain=
s the rationale for disallowing HashML-DSA.<br><br>3. It may be useful to a=
dd a note to explain why only the seed format was chosen for private keys, =
given that the LAMPS WG selected the expanded private key format to maximiz=
e interoperability with existing implementations.</div><div><br></div><div>=
4. You may want to refer to the security considerations in <a href=3D"https=
://datatracker.ietf.org/doc/draft-ietf-lamps-dilithium-certificates/">https=
://datatracker.ietf.org/doc/draft-ietf-lamps-dilithium-certificates/</a> an=
d discuss if randomized signing is preferred over deterministic signing.=C2=
=A0</div><div><br></div><div>Cheers,<br>-Tiru</div></div>

--000000000000c2faf0063e7271d3--

