Re: [lamps] Can ML-DSA be used in CMS?

Sean Turner <sean@sn3rd.com> Wed, 14 February 2024 15:07 UTC

Return-Path: <sean@sn3rd.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ABF74C151078 for <spasm@ietfa.amsl.com>; Wed, 14 Feb 2024 07:07:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.107
X-Spam-Level:
X-Spam-Status: No, score=-7.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PaKwrlvh6pPr for <spasm@ietfa.amsl.com>; Wed, 14 Feb 2024 07:07:00 -0800 (PST)
Received: from mail-qk1-x72b.google.com (mail-qk1-x72b.google.com [IPv6:2607:f8b0:4864:20::72b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 893B9C14CE27 for <spasm@ietf.org>; Wed, 14 Feb 2024 07:07:00 -0800 (PST)
Received: by mail-qk1-x72b.google.com with SMTP id af79cd13be357-7872bc61fccso31032385a.1 for <spasm@ietf.org>; Wed, 14 Feb 2024 07:07:00 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; t=1707923219; x=1708528019; darn=ietf.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=VX6W2xBd7gFET60zKMPZCIHb9R9WSVt82DYsBbKeRN8=; b=bQwmT1uHMaDLJLGd3OLY47Me07FujjTjJZXoCkv4YbOsEO1y43Z3CdtR45GGQ5h2P+ kQsDSTjoRNr7Ematyxg9zZfpJC4RznLIi7dPAGXkliwx5puyvhzf6q1QWuk/p4SjUnl1 JjwTZhOes9loINFIk4EHSNuCGgd4Z14eXsocA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1707923219; x=1708528019; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=VX6W2xBd7gFET60zKMPZCIHb9R9WSVt82DYsBbKeRN8=; b=MQRL3IlYsWOCQ8Gvsxho6l6Tq3JXnhfjgtpfm2f13vvFaUweSPQqySdWa4G7Kn8vtk jpZO8/0BFUJTqQ0b/ZWhcZhRIMXVKlmzou6O4HxAWnZHRNdoODtrMBhAr4OkS6tqRpi1 5WeyWXJud3qIJSdYLjOE3PtPGGQoiTrdM+6AP4zks62glo039/fVi1sz1rMCSjo+vm79 AX3aFa5QRy184q6gkEWf4NF64hMIDVkF2+k4CaiQFPk6SxtpjjgC0dip74X0263D89Jr IerhSRWOZCR8HtpLmm+iKAVyODvVQqdPoZoLkpHBFAPW4SW3bz63drG/BC1D6tr0Hm7a TuRw==
X-Forwarded-Encrypted: i=1; AJvYcCWhCXru1DLiuisoYhwc6dq9V3KNUHGoDVagk39X27HGB2xPbWh3gQkjHgqnk7hyP8vfI6dFxUT3M68Zq+3tWw==
X-Gm-Message-State: AOJu0YxUbNzf395DI8eZ1m5CslfxU/WHV+f33NdwOBZYPWUZ4nQpVcuI y4jA0cCjl43tIh0YZ31an94tk66uNQBzywcJYh3asuDJirwg5mNCvR8yl5ccd1w=
X-Google-Smtp-Source: AGHT+IE0ROjmMOshrD7Qo/+0kEttC72EilyfY0LFqq6qtoN5t7FZUJQzSThAoXL0H9bRp/A8YOM6xA==
X-Received: by 2002:a05:620a:b86:b0:787:214c:3301 with SMTP id k6-20020a05620a0b8600b00787214c3301mr2573717qkh.46.1707923219432; Wed, 14 Feb 2024 07:06:59 -0800 (PST)
X-Forwarded-Encrypted: i=1; AJvYcCUb5S7P12YHRJEV9GFlPvR+bmE+RYIyxPk0rzGewKLnk/ySHeqWOXXXozGKemWCMfOZb3wtSCmq5afvfX1zNYuys1g3OZu1fygq7MPVu5koRPlsRu13xowBdp/KIPq0slRie2b7M97PCsHjGV7l12Hn
Received: from smtpclient.apple (pool-68-238-162-47.washdc.fios.verizon.net. [68.238.162.47]) by smtp.gmail.com with ESMTPSA id j28-20020a05620a0a5c00b00786ae5be3c6sm2026600qka.132.2024.02.14.07.06.58 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 14 Feb 2024 07:06:58 -0800 (PST)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.15\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <MW3PR15MB404385AF5F6D6F86A030A200814F2@MW3PR15MB4043.namprd15.prod.outlook.com>
Date: Wed, 14 Feb 2024 10:06:58 -0500
Cc: Mike Ounsworth <Mike.Ounsworth@entrust.com>, "draft-ietf-lamps-dilithium-certificates@ietf.org" <draft-ietf-lamps-dilithium-certificates@ietf.org>, LAMPS <spasm@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <C29BDCF2-7F2A-4D06-835F-3FF9FB8EE63D@sn3rd.com>
References: <CH0PR11MB5739AF8408E1669FB9EF912A9F4F2@CH0PR11MB5739.namprd11.prod.outlook.com> <MW3PR15MB404385AF5F6D6F86A030A200814F2@MW3PR15MB4043.namprd15.prod.outlook.com>
To: Wai Choi <wchoi@us.ibm.com>
X-Mailer: Apple Mail (2.3654.120.0.1.15)
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/EG4ZitoEiBiahdkeLhuEwlzMIrA>
Subject: Re: [lamps] Can ML-DSA be used in CMS?
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Feb 2024 15:07:04 -0000


> On Feb 13, 2024, at 09:09, Wai Choi <wchoi@us.ibm.com> wrote:
> 
> Do we need a draft to address how to use Kyber in X.509 certificate?

We already have one!  The kyber in certificates I-D link can be found via the link Mike provided in s6.3.2, but a direct link is:
https://datatracker.ietf.org/doc/draft-ietf-lamps-kyber-certificates/

spt