[Gen-art] Re: draft-ietf-lamps-x509-slhdsa-07 ietf last call Genart review
Daniel Van Geest <daniel.vangeest@cryptonext-security.com> Wed, 21 May 2025 17:47 UTC
Return-Path: <daniel.vangeest@cryptonext-security.com>
X-Original-To: gen-art@mail2.ietf.org
Delivered-To: gen-art@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4DD972B563CE; Wed, 21 May 2025 10:47:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cryptonext-security.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2xFwxvBDQlK2; Wed, 21 May 2025 10:47:19 -0700 (PDT)
Received: from PA5P264CU001.outbound.protection.outlook.com (mail-francecentralazon11020110.outbound.protection.outlook.com [52.101.167.110]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 6978B2B563C6; Wed, 21 May 2025 10:47:16 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=EiWIVh4VXVvL3M7OQSqnyRO1QW17c/Plnb9on3Qi1PpMVB3ow8UnU1dqBFrQs3AKr6Tpv+IFcLlfKnplLUPExOIT4ymG3cXmgNfL2hYOtWVtsHSZjqoXj3hYKQsX0w2LhCkQBSvuLPouwrwzsyX48W6/nnInOBT1/7dliO9qGj03eOPcownwLm34M6KyL1nknnt2BYZUDzXw2F33GUdBrwO7RnCJualyMqHZLN9JhI0rzSDm9WhvrhmRjq0IiSE7VTFvTq0wzOvIb4VY/e8jvniVOS5fT7mOWLXZxUDit0pVqBFCax8zOkkw63U8+W1sbCdIexB4xZUCZ2u3+wpEAQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=cvnLM6N9ExzUl3roFpz3uhW6h0SFYoJaOOo2fJq7ugo=; b=Ig4a5bZ2YEyAaMH0vVZFor5SynTJX/vObZKtUFCpXKXVNklpYYOUdwl5VQqdsGIfNHuuMn5fV+1WT6wJqEJfJpAIKISr+5ZFfCb+Zi1z3P7NDzdtDMJRlwRnZWmL8IxKrBQxiM84Oz1+S9ETVeHEj32OgP9XLsKLjRa2hr5Cbj/DfRdAL36GL4DnNP48siKd4d2DVfm+KWMFof8ONxJsnktqfqiWEy/WoqAZxKwqBs3neSwrNNlcZiOrFtapUNeJGdGARyrZwBWtLYQKp0sanTThz6+sUhmrQUe5TAdEBuC2DLNRvBC4QPy4GCXtZfVdG8w70YQbeyHk0gSo8/CmIA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cryptonext-security.com; dmarc=pass action=none header.from=cryptonext-security.com; dkim=pass header.d=cryptonext-security.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cryptonext-security.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cvnLM6N9ExzUl3roFpz3uhW6h0SFYoJaOOo2fJq7ugo=; b=r4+KyXusqsmNXmqrmqupZxKILT0sSp9OrNIKCKQYKxIzIWpP6ZA1wxytZUOYNjr6BxYb6l9++ix5T3qLPgX4NLK2q5kT4l0TB5biczMe3LcYxEnmZZzrp8Vi9mSOh4p1Uc6H7AUe0MrM4m0Jk2d8qH4BsCkOipWKc35TFwpZNrLs1Riqmifi1jsBiXZuCNau2k+eu5Lu941/rjIgMeDCXvM6Pq7xsYs/8bMlTX6qvxgfOYATGAedjkG812LzS1TeEk6iPGuFsNjrYgbwlOZk8qJB+fYrm1UL9qwK7mXmWfjBig5G4hgihLhHwUvLVFxQV8lTgMiSKaptrZ3vDSXzTg==
Received: from MR2P264MB0484.FRAP264.PROD.OUTLOOK.COM (2603:10a6:500:7::11) by PARP264MB5295.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:3f1::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8769.19; Wed, 21 May 2025 17:47:14 +0000
Received: from MR2P264MB0484.FRAP264.PROD.OUTLOOK.COM ([fe80::ba77:3351:6b26:d845]) by MR2P264MB0484.FRAP264.PROD.OUTLOOK.COM ([fe80::ba77:3351:6b26:d845%4]) with mapi id 15.20.8769.019; Wed, 21 May 2025 17:47:13 +0000
From: Daniel Van Geest <daniel.vangeest@cryptonext-security.com>
To: Dale Worley <worley@ariadne.com>, "gen-art@ietf.org" <gen-art@ietf.org>
Thread-Topic: draft-ietf-lamps-x509-slhdsa-07 ietf last call Genart review
Thread-Index: AQHbyP36WF8FPP9oVE+cIJxfJj4ZtbPdXsiA
Date: Wed, 21 May 2025 17:47:13 +0000
Message-ID: <8f5db7a5-98b8-4c55-aada-fdbe155198a9@cryptonext-security.com>
References: <174768710478.478496.18086687690232050269@dt-datatracker-59b84fc74f-84jsl>
In-Reply-To: <174768710478.478496.18086687690232050269@dt-datatracker-59b84fc74f-84jsl>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cryptonext-security.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MR2P264MB0484:EE_|PARP264MB5295:EE_
x-ms-office365-filtering-correlation-id: fb995008-344d-432a-85ec-08dd988f8525
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|366016|376014|1800799024|38070700018|13003099007|8096899003;
x-microsoft-antispam-message-info: RHIwi7z4Bbwg+UlM4AXZ+7eWbEMf6OSNLZRwoMqCq/UlabkDnn+jf/+sqs24H/qIuFwFcuSsvF2tJ96Ya7OWG9xdXs9NKSMulpdXL67BmYo3gybWoGnxPjZdItQssOfzK2G/CYIwdbdQbfpf8DChua+646EztKdMSXOcO6C+gp8fPSOE8dMNFGWTLtRcmYL8bR2GYHgVhhkO+MDzp1CJsUpluK3IKlS2yyHWujf1dymo+mGkKipSE3p9wBqFHBB5POQwwQi6p9Bm/0Azn7vGRbyvKdGFTiJda0//RXpvHZmNkB5nltbRUNvfrE5JaboRLmXnf1F0xvRXHpsCTmkt332/4FSAtOT+I9hwJYfwbLeOUlqLQEcpvKMD6cdsvBO3gFlbdsTT9udNSdWqr5NkkE+vTEIYlO5FcHAGOKU5zXBscVIcOxAObqkm9rnmCciK6qnZUhlb4uVz2pWzSxKZvrawHgCdaZO6HIm7bqkmOFFSuO34HU/cpF0CDkYnJopl7xus06K9G7jRpXYwwg/7pnI+W3iqguHsGeV0nq9v9hsS0Yn4yeNNj1XGwSbr8TdNl3TMgj3Moek3Be5JLfFNGm6ACCZIN5BUuT8yGJq56ClW2QEMRknEJ6+WpgsFoDWH0FtwVl3UaAWFdILN3zExAiCOA3KvylHdQtTbsdWBB1oocxi6TBjJvqcAiAWc7CU5B3biYAsbYzx6yHsZijgk9WgzfpQxah75TfOwgRxnGBPb8hbL6XsOmOOCA8XtcbbtFAk26IhRRlLuLefnQminSpTkZc1kRMp+uhtqXRdQV5jG4IUgTDqJwEOU0bwkEz6P7nW38m9HY5a6CVGhp0B3aXy3SqhRAPAVJzs2r17hTB9jQo774SNnFnUZxyMaiubJC4XMQ2x972k4mHjvS/Zjt3CQOL9hLcAjORKCyzCGaukJucBlQC4q/9L3oueGNdDMiH5eCMC9wh6YIjLz+SdFLuh8eT+yjAkP6jQ0tEbOcZzZ6x8f6KKbNKZ/iSJU6AI6vxLL8VR4cMmF+3ZuNbWjIs1ZFCWMZ286dESmfGq7dN/TuVUazGwMb2rxg3AbZu5TWPvSFjqnK/W719tS8E5ekEYQ9wthAY7sVKG8lpQfw2aXrYoQG47rhTXchkTrigqMvUYic6QRUSu0CKTGH7CYs8YZa0M8/3PB4lDDPsaVeM7zgT0QdzU/fswUTzBTQ0uHgn8lr5+yYSQOfKCtx+OGMq7kyORYWZfZ5NZBeDByPgW4494mS05HpBK/YKu74lgxAT6PXIu7A3LgIZzTCsI5HBKjv8WpaJEGA++d/wKAoDXaZiRazuy7dl9wT+njr66gwepfuX1vCyYOGX/lwM3VsfE5F23bnIhhgEyczMBVXaIBPOCAUutspoevzBxz7Maj5kb3XLTXPmQ0FNroIfRML3Lhm87/xV+5A3ErntzO0oY=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MR2P264MB0484.FRAP264.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(376014)(1800799024)(38070700018)(13003099007)(8096899003);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: ome0QnXeS2Pfx2yPVMLafk5OaOiA+9qUUDR7coARN25rTP1VUXq/JPYIQcGRcYyicU+LKlbstKHqtLEZAmiY7HiWCWfNmk9bl6tfCl4cYvxdKXThQ1f+yNfrhgs468UqRs5MqcDF9CnJPqKJrnVk8Ob4mddkGYet0veZxCPg6SEKIWofvQOAZI+AF+0IV/St0/jDfL1FxuYmnyRY1sCHl/0c+DvNY7ftTR44nfq3r/FqHYQBkh9sBv3EAHh5QovC3GBQibyUj5b1k3ROi3/cdlf36S6LMBTfJwnwv3cNy5CaMjoGLUHPnXGqHHQJKveIuLKa07/UbiQTckMS6nticIZfdLsQZsLqc2xej8p9840zaK52HWZuS0nZ4ejJyGdW8KJMaW1y/axwqsYP2nibLdaN9263oPPJPh1g//FbgLoovpFPjUKegtZTf6rufir7MzlweQ3jKVNfBuy6ix00JzXW+DiUBcdx0V37qC9LB4RyDItoAOzKvJscQkjssit5ZNIzSOz+mwFTRBGkPRfjvxncV7CgyO/JmQeUzfCDGPwLGWMNDGzZErAHxPD0pOix4QpwyOO7izO14dsviBMevLbQpB/4JHGdrkYdLGjm1isC7yXmcahV4ZuMmkVAz+r/tWE+sLFPP7CyA/TGGLUIWJyYQyYXj6bekencRJKtCRtQ8TZzLX6F5un3AW09klqk06STFLLpk7ueh/6r/AOQeH0dpRxA4cl2xxye6dlMZ1zgfPKGFkgKHFUcMRGt6F+YlCoUTrYYGrDXfJ/uY6K2+3nkXF/IENu2tLb31pnbQWb8BaZUPdsJirbxMdMSJe3fqdc/MD4hMAjo4L0BhaR9dpo5jSRmFtAku452kh4t0N9roSOHUrBqVY+5XUoVAOI80wdBrhunZ5pgxxzpR8RpJ2n82tch5y4JJBbaZ2unSaxdQ5OnuRJCzn/nFBZIWb97HftEd5gU5+2UWeNTPIq6b2Beeb9idKx9CCZv1ktyDYfmyyLoMMnIjWvIAaKN/RgLRfXjhtZKKXW+NjGJREoLoONzLqmFt3J9weYCxAm7gK7N4XelwkfejzMvHCDsqYBSWt0j1P5DSJDU7oW+//WRssLZ5l5bmxFUFH62RxlvcgxcNB3KG9vJHCFP/QDoeTCi4ZOAO8Ex5aF5OXJDML8PiKusoPbhEJCUAI4BJFssU7RmuDCyAiv3gwxjkcuSRF3iSoR9HLpkoteb7xLgddhAtmImcGZaJkFiu4xQVubcFrAH03uWrURUEk7rZS8++zAynR35t+bjqqLEsS7qhM2FN0/moh70NSWEAQEkSHZfBmeGy44hZ0akFL6NEmODeACXpRLwPr+Gd7yCmaSx3KJ3sz4nFbqpevnf4bqDomKtapVRy5KncUHmfrDvYICaN4xkjfSpVh6R2K40Rl+7TFfIvOEY2dVXweFiX3xU99pduwxPo+O8iFTh7pDOo3dAHKHGXMtrm58b/8GG3xzc+i/eJ1sw+0WmPanpob8gfaF1LBn6kyo6GGbZesaBr3KltsaXy351Tf3OlvwQzNoN/Z9IO2SaqRFurBkxBCqWnb49tm6ervBxhjx2KHojMl6W4K0bfjgeVRKWW4hV8/q72VPA4Fu5rm9LAtIi01mhuOdseGo=
Content-Type: multipart/alternative; boundary="_000_8f5db7a598b84c55aadafdbe155198a9cryptonextsecuritycom_"
MIME-Version: 1.0
X-OriginatorOrg: cryptonext-security.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MR2P264MB0484.FRAP264.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: fb995008-344d-432a-85ec-08dd988f8525
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 May 2025 17:47:13.7642 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: da4a2df1-4b1b-489d-a7f4-224b58fd4200
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 31/tEZo2nlSv6dWdq9tX0l6/Zh8JRbaNcAgPF84UawayipCP2SiDxYofEcIRgA8snKiNtua5SUAqb+oo6X+c2HWiGs6+RjpvpVF0B4phJnlbFwCiY4CaTVpl9Lqgl9aG
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PARP264MB5295
Message-ID-Hash: 6E5NN3FR4HJPZ6LV64Y5GFUWMQNGTS3K
X-Message-ID-Hash: 6E5NN3FR4HJPZ6LV64Y5GFUWMQNGTS3K
X-MailFrom: daniel.vangeest@cryptonext-security.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-gen-art.ietf.org-0; header-match-gen-art.ietf.org-1; header-match-gen-art.ietf.org-2; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "draft-ietf-lamps-x509-slhdsa.all@ietf.org" <draft-ietf-lamps-x509-slhdsa.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, "spasm@ietf.org" <spasm@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Gen-art] Re: draft-ietf-lamps-x509-slhdsa-07 ietf last call Genart review
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/gen-art/vN0SUqg_I6WvtmUVKMt3SIeeiQM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gen-art>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Owner: <mailto:gen-art-owner@ietf.org>
List-Post: <mailto:gen-art@ietf.org>
List-Subscribe: <mailto:gen-art-join@ietf.org>
List-Unsubscribe: <mailto:gen-art-leave@ietf.org>
Dale,
Thank you for the review. Comments are inline...
On 2025-05-19 9:38 p.m., Dale Worley via Datatracker wrote:
Document: draft-ietf-lamps-x509-slhdsa
Title: Internet X.509 Public Key Infrastructure: Algorithm Identifiers for SLH-DSA
Reviewer: Dale Worley
Review result: Ready with Nits
I am the assigned Gen-ART reviewer for this draft. The General Area
Review Team (Gen-ART) reviews all IETF documents being processed
by the IESG for the IETF Chair. Please treat these comments just
like any other last call comments.
For more information, please see the FAQ at
<https://wiki.ietf.org/en/group/gen/GenArtFAQ><https://wiki.ietf.org/en/group/gen/GenArtFAQ>.
Document: draft-ietf-lamps-x509-slhdsa-07
Reviewer: Dale R. Worley
Review Date:
IETF LC End Date: 2025-05-22
IESG Telechat date: unknown
I have only reviewed the document for readability by a non-expert. I
expect the security people to check the algorithms and their uses, and
also the ASN.1 constructions.
Summary:
This draft is basically ready for publication, but has nits that
should be fixed before publication.
Technical issues:
The authors should verify that it is intended that the ASN.1 module
does not define signature algorithm numbers 20 through 31.
Nits/editorial comments:
1. Introduction
When a pure or pre-hash mode needs to be
differentiated, the terms Pure SLH-DSA and HashSLH-DSA are used.
It reads oddly that "Pure SLH-DSA" has a space in it but "HashSLH-DSA"
does not. Is there a reason for this difference?
FIPS 205 refers to the general algorithm as SLH-DSA. There are pure and pre-hash variants of the algorithm. FIPS 205 uses HashSLH-DSA to identify the pre-hash version, and also refers to HashSLH-DSA as "the pre-hash SLH-DSA (signature,version)." But for the pure version they just refer to it as "the pure SLH-DSA (signature,version)." Since there is no NIST name for the pure version, we used the term "Pure SLH-DSA" but wanted to use the NIST term "HashSLH-DSA" for the pre-hash version.
Separate algorithm identifiers have been assigned for SLH-DSA at each
of these security levels, fast vs small, and SHA2 vs SHAKE256.
Better to make it clear that not just each attribute alone has an OID
but each *combination* has an OID, and that pure vs. pre-hash is also
part of the combination:
Separate algorithm identifiers have been assigned for SLH-DSA for
each combination of these security levels, fast vs small, SHA2 vs
SHAKE256 and pure mode vs pre-hash mode.
will update.
3. Algorithm Identifiers
The AlgorithmIdentifier type, is defined as follows:
AlgorithmIdentifier{ALGORITHM-TYPE, ALGORITHM-TYPE:AlgorithmSet} ::=
SEQUENCE {
I would have found reading this to be smoother if it had stated before
the definition that this is not a new definition:
The AlgorithmIdentifier type is defined in [RFC5912] as follows:
AlgorithmIdentifier{ALGORITHM-TYPE, ALGORITHM-TYPE:AlgorithmSet} ::=
SEQUENCE {
will update
--
The same OID is used to identify an SLH-DSA public key
and its associated signature algorithm.
Is this the proper/usual use of "identify"? Clearly, the OID
identifies the algorithm, as there is only one algorithm with a given
OID. But there are many keys that use the same algorithm; the OID for
the algorithm is an attribute of the key but is not sufficient to
identify it.
RFC 8410 uses "The same algorithm identifiers are used for identifying a public key, a private key, and a signature."
Would that be better?
11. References
For the ASN.1 Module in the Appendix of this document,
I would be specific:
For the ASN.1 Module in Appendix A of this document,
will update
Appendix A. ASN.1 Module
I note that while section 3 defines signature algorithm numbers 20
through 31 and 35 through 46, the ASN.1 module only defines numbers 35
through 46. Though I assume that the authors have a reason that the
pure algorithms have no defined identifier in the module, it would be
good to explain why for the naive reader.
I propose to change
The Pure SLH-DSA OIDs are:
to
The Pure SLH-DSA OIDs are defined in
[I-D.ietf-lamps-cms-sphincs-plus]'s ASN.1 module and reproduced here
for convenience:
Thanks, Daniel Van Geest
[END]
- [Gen-art] draft-ietf-lamps-x509-slhdsa-07 ietf la… Dale Worley via Datatracker
- [Gen-art] Re: draft-ietf-lamps-x509-slhdsa-07 iet… Russ Housley
- [Gen-art] Re: draft-ietf-lamps-x509-slhdsa-07 iet… Daniel Van Geest