Re: [Pqc] PQC X.509 115 Hackathon

Sofía Celi <cherenkov@riseup.net> Wed, 05 October 2022 12:56 UTC

Return-Path: <cherenkov@riseup.net>
X-Original-To: pqc@ietfa.amsl.com
Delivered-To: pqc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 853C9C14E514 for <pqc@ietfa.amsl.com>; Wed, 5 Oct 2022 05:56:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.806
X-Spam-Level:
X-Spam-Status: No, score=-2.806 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=riseup.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JJGq94GdUMsY for <pqc@ietfa.amsl.com>; Wed, 5 Oct 2022 05:56:02 -0700 (PDT)
Received: from mx1.riseup.net (mx1.riseup.net [198.252.153.129]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 205E9C14F747 for <pqc@ietf.org>; Wed, 5 Oct 2022 05:56:01 -0700 (PDT)
Received: from fews1.riseup.net (fews1-pn.riseup.net [10.0.1.83]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "mail.riseup.net", Issuer "R3" (not verified)) by mx1.riseup.net (Postfix) with ESMTPS id 4MjF1Y2FgrzDs5Q for <pqc@ietf.org>; Wed, 5 Oct 2022 12:56:01 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=riseup.net; s=squak; t=1664974561; bh=vZ6jF2/Sqtyus4vOMhLCsyaDgwciUP14l2wt9GlRY7A=; h=Date:Subject:To:References:From:In-Reply-To:From; b=NXCUnIhNixy530x4jVE6tLCBf7Je+x08FQieBbzlbvd9x+4QUXenUqrMntjlqZXdD GX7J8KxYzggE1U+WT4GxAQew1egFQkR9iGZCzfRSZHAHTMeQ7HF3kRTf2ou/NIxVd/ K5fWmyCa0Ju/bvF6aRgq2m9DU/NB1WRqey/mSq2s=
X-Riseup-User-ID: DDC253E19A864A7A1CD02EA53DA3CCABC2D63B2628682D125B087E3736DBD629
Received: from [127.0.0.1] (localhost [127.0.0.1]) by fews1.riseup.net (Postfix) with ESMTPSA id 4MjF1X5xVbz5vMZ for <pqc@ietf.org>; Wed, 5 Oct 2022 12:56:00 +0000 (UTC)
Message-ID: <bdbc4d9d-b5c8-bb25-02e1-dd0e754d11ff@riseup.net>
Date: Wed, 05 Oct 2022 13:55:57 +0100
MIME-Version: 1.0
To: pqc@ietf.org
References: <CH0PR11MB5739E98B69C5AD88745F539E9F5D9@CH0PR11MB5739.namprd11.prod.outlook.com> <DU0PR03MB86967496D788EDC9BD19CAF4865D9@DU0PR03MB8696.eurprd03.prod.outlook.com>
From: Sofía Celi <cherenkov@riseup.net>
In-Reply-To: <DU0PR03MB86967496D788EDC9BD19CAF4865D9@DU0PR03MB8696.eurprd03.prod.outlook.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/pqc/us08Qu8g7Uf4R2O3uhq7quik2hU>
Subject: Re: [Pqc] PQC X.509 115 Hackathon
X-BeenThere: pqc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Post Quantum Cryptography discussion list <pqc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pqc>, <mailto:pqc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pqc/>
List-Post: <mailto:pqc@ietf.org>
List-Help: <mailto:pqc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pqc>, <mailto:pqc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Oct 2022 12:56:06 -0000

That is a great idea! I hope I can maybe make it. I agree with Paul in 
that in-person is always great, but it will be good to have remote ;)

I'll happily share this idea with others intererested.

Thank you,

On 05/10/2022 08:19, Tomas Gustavsson wrote:
> Great idea. I will not be able to join unfortunately, but would have 
> liked to. In your list mostly everything is important for sure.
> 
> Perhaps from my side I currently think that signatures on certificates, 
> CRLs, CSRs, etc feel pretty stable, certain that it will be right in the 
> end. Some other things you mention are more often overlooked. The basic 
> ability to encode/decode public and private keys from PEM and PKCS#12 
> will be vital to not waste a lot of time implementing and interoperate.
> 
> Just as an example, the two versions of encoding for EdDSA keys cost 
> some hours of work, and some unnecessary if's in code. If we can avoid 
> such seemingly simple annoyances that would be good.
> 
> Cheers,
> Tomas
> 
> ------------------------------------------------------------------------
> *From:* Spasm <spasm-bounces@ietf.org> on behalf of Mike Ounsworth 
> <Mike.Ounsworth=40entrust.com@dmarc.ietf.org>
> *Sent:* Wednesday, October 5, 2022 3:00 AM
> *To:* 'LAMPS' <spasm@ietf.org>; pqc@ietf.org <pqc@ietf.org>
> *Subject:* [lamps] PQC X.509 115 Hackathon
> CAUTION: External Sender - Be cautious when clicking links or opening 
> attachments. Please email InfoSec@keyfactor.com with any questions.
> 
> Hi LAMPS and people interested in PQC!
> 
> As suggested at 114, my colleague John Gray and I would like to do a 115 
> Hackathon on PQ keys and signatures in X.509 / PKIX.
> 
> We are suggesting to play with Dilithium, Falcon, Sphincs+, and 
> Composite signing algorithms in Certs, CRLs, CSRs, PKCS#12s, CMS 
> SignedData, maybe OCSP Responses, maybe Timestamping, maybe CMP. We can 
> bring: the Entrust Toolkit (which we can hack at), Bounce Castle, 
> OpenQuantumSafe-openssl, OpenCA (easier if Max Pala is there, but we can 
> probably figure out how to build it).
> 
> The point of the hackathon, I think, is going to be OIDs, and public key 
> / private key formats (ex.: the differences between Dilithium and Falcon 
> encodings in draft-uni-qsckeys, and 
> draft-massimo-lamps-pq-sig-certificates).
> 
> Question 1: are others interested in joining us at the hackathon? (no 
> point is signing up for a hackathon spot if we’re the only ones there)
> 
> Question 2: whether or not you're joining, what PQ X.509 / PKIX things 
> would you like to see working with Dilithium, Falcon, Sphincs+, Composite?
> 
> ---
> Mike Ounsworth
> Software Security Architect, Entrust
> 
> /Any email and files/attachments transmitted with it are confidential 
> and are intended solely for the use of the individual or entity to whom 
> they are addressed. If this message has been sent to you in error, you 
> must not copy, distribute or disclose of the information it contains. 
> _Please notify Entrust immediately_ and delete the message from your 
> system./
> 

-- 
Sofía Celi
@claucece
Cryptographic research and implementation at many places, specially Brave.
Chair of hprc at IRTF and anti-fraud at W3C.
Reach me out at: cherenkov@riseup.net
Website: https://sofiaceli.com/
3D0B D6E9 4D51 FBC2 CEF7  F004 C835 5EB9 42BF A1D6