[openpgp] Re: WGLC for draft-ietf-openpgp-pqc [was: Re: I-D Action: draft-ietf-openpgp-pqc-08.txt]
Heiko Schäfer <heiko.schaefer@posteo.de> Fri, 09 May 2025 11:49 UTC
Return-Path: <heiko.schaefer@posteo.de>
X-Original-To: openpgp@mail2.ietf.org
Delivered-To: openpgp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7CB9A26CB4B1 for <openpgp@mail2.ietf.org>; Fri, 9 May 2025 04:49:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.696
X-Spam-Level:
X-Spam-Status: No, score=-0.696 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=posteo.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aJhPgg8aNqm6 for <openpgp@mail2.ietf.org>; Fri, 9 May 2025 04:49:24 -0700 (PDT)
Received: from mout01.posteo.de (mout01.posteo.de [185.67.36.65]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 0EFA226CB4A1 for <openpgp@ietf.org>; Fri, 9 May 2025 04:49:24 -0700 (PDT)
Received: from submission (posteo.de [185.67.36.169]) by mout01.posteo.de (Postfix) with ESMTPS id 200CF240027 for <openpgp@ietf.org>; Fri, 9 May 2025 13:49:23 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=posteo.de; s=2017; t=1746791363; bh=qe2MqpKq+GMZbZC7HH9mL1sbpJiooli/Z/IHaMUlxPc=; h=Content-Type:Message-ID:Date:MIME-Version:Subject:To:From:From; b=I+ZBrowWIj3JcvZiPTmyUBSuMhqZx8lT6g7ikkDI/9Hkz3Hc/iVSDrJjJD9dBfaS8 IDpC0wgJPt1sfX4m9g0eWr0rcfGjaSQZKYe3dDHfEPTuvRTZvhKn9HDU2glRw+BLZm 8N7RiUX6+wOjLGLiY9HFkLsa2SBayj9Ntaog/3PhfSiHAOn/m8lBmo5H1JcCiF4KOU UeCMmkru/GXLHhciZzT/zt3AiioBvGjuecoYEs4q4HoB294DFFSmaLYFf3TXkwkL1i CUw6qVKyBM6FRhcrAxDDjbQW8q0V/tvINJx3Qq/J/r/7K/lHLi390L7cWvfWcCMf3S 9Dsw3oTxzlgaA==
Received: from customer (localhost [127.0.0.1]) by submission (posteo.de) with ESMTPSA id 4Zv6jZ5qWvz9rxK for <openpgp@ietf.org>; Fri, 9 May 2025 13:49:22 +0200 (CEST)
Received: from services.foundation.hs (services.foundation.hs [192.168.21.4]) by mail.foundation.hs (Postfix) with ESMTP id 8834F705C5 for <openpgp@ietf.org>; Fri, 9 May 2025 13:49:22 +0200 (CEST)
Content-Type: multipart/alternative; boundary="------------6ZO7vPhJHNy0wUDHyyTjjQwN"
Message-ID: <a8818ced-1cd4-4c66-8dd0-19cb40ec6c9a@posteo.de>
Date: Fri, 09 May 2025 11:49:21 +0000
MIME-Version: 1.0
To: openpgp@ietf.org
References: <174470653269.1286532.14892820163225351018@dt-datatracker-64c5c9b5f9-hz6qg> <LSicuu3DyGQdz5FlANti-HGJ6GuAucc5BKufbsCa603EsSZ0q1XMXYvt_OubLd0UQkg0gh2F--9y9WpoqWfQu5XU-KEcJ15GG66cSFk9ByU=@wussler.it> <87wmblcr8i.fsf@fifthhorseman.net> <a2fa1a9b-7094-4487-a014-c3e623fec8ad@posteo.de> <tjL4ynTE9NJFn8rNxUVyb2s-NxorQ_1GKD4SHCl6DgFRSsb9A05B4Oq9PZMqTUYc7jTxb3pf-d_CkcrrAIDoFwv1QJIIbGfMjhj7Md6fyQo=@protonmail.com> <QaP8eC7kShQ4wP25aIZPw-3iXIZByHmpa9X30EG1t0NuV8iTXKqsgYdTp5AKSLB5jho_NdgTjppUmaBI8kThnvpkp8moB8-Fp2XWLOuA9oA=@wussler.it>
Content-Language: en-US
From: Heiko Schäfer <heiko.schaefer@posteo.de>
In-Reply-To: <QaP8eC7kShQ4wP25aIZPw-3iXIZByHmpa9X30EG1t0NuV8iTXKqsgYdTp5AKSLB5jho_NdgTjppUmaBI8kThnvpkp8moB8-Fp2XWLOuA9oA=@wussler.it>
Message-ID-Hash: LCNCKTHGUFMXCJX5I2SVWUTK4R3IDVRI
X-Message-ID-Hash: LCNCKTHGUFMXCJX5I2SVWUTK4R3IDVRI
X-MailFrom: heiko.schaefer@posteo.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [was: Re: I-D Action: draft-ietf-openpgp-pqc-08.txt]
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/wpFV_Fpl4fsBkVhKl3CyO7DYpqo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hello Aron, all, > After gathering all the feedback, we decided to simplify the guidance, and consistently remove the remaining statements regarding sub-key selection. > This is reflected in the editor copy [1]. I agree with removing guidance, while consensus is clearly not in immediate reach. Thank you for diligently working towards getting this draft out the door soon! I look forward to seeing it finalized. > We thank the people involved in this discussion and ask them to review this change. I'm happy with the draft, as is. But I do wonder idly if it would be possible and useful to add some kind of informational text that clarifies that senders can consider encrypting only to PQ(/T) keys to achieve post-quantum security, when a sender encounters a case where it finds this possible. Just to state, in the most general of terms, that senders *can* apply such policy decisions, and might want to. But without prescribing any particular approach. Thanks, Heiko PS: FWIW, in the experimental "rsop-pqc" implementation, I have decided to adjust key selection for encryption as follows: For each recipient certificate, if any valid PQC encryption keys exist, rsop now encrypts only to the set of valid PQC subkeys, while ignoring any non-PQC subkeys. While this is somewhat arbitrary, and I look forward to one day implementing official guidance instead, this seems like a reasonable interim solution. I assume most recipients will want this kind of approach to be taken.
- [openpgp] I-D Action: draft-ietf-openpgp-pqc-08.t… internet-drafts
- [openpgp] Re: I-D Action: draft-ietf-openpgp-pqc-… Aron Wussler
- [openpgp] WGLC for draft-ietf-openpgp-pqc [was: R… Daniel Kahn Gillmor
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… andrewg
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Bart Butler
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Neal H. Walfield
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Justus Winter
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Aron Wussler
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Justus Winter
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Andrew Gallagher
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Daniel Kahn Gillmor
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Daniel Huigens
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Heiko Schäfer
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Falko Strenzke
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Michael Richardson
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Daniel Huigens
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Andrew Gallagher
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Daniel Huigens
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Aron Wussler
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Daniel Huigens
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Heiko Schäfer
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc [wa… Aron Wussler
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc Daniel Kahn Gillmor
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc Stephen Farrell
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc Falko Strenzke
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc Stephen Farrell
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc Simo Sorce
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc Stephen Farrell
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc Daniel Kahn Gillmor
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc Simo Sorce
- [openpgp] Re: WGLC for draft-ietf-openpgp-pqc Aron Wussler