[lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draft-ietf-lamps-pq-composite-sigs-08 (Ends 2025-10-06)
"Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com> Wed, 01 October 2025 19:08 UTC
Return-Path: <sfluhrer@cisco.com>
X-Original-To: spasm@mail2.ietf.org
Delivered-To: spasm@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 16F4D6C04DA1; Wed, 1 Oct 2025 12:08:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -11.886
X-Spam-Level:
X-Spam-Status: No, score=-11.886 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_NONE=0.001, T_SPF_HELO_PERMERROR=0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cisco.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EYQ6fXhDImAy; Wed, 1 Oct 2025 12:08:57 -0700 (PDT)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D33286C04D97; Wed, 1 Oct 2025 12:08:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=24879; q=dns/txt; s=iport01; t=1759345737; x=1760555337; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=U5mCAIZSUf6LMKlH9V8G9of6bMtk+oMg2DXfxPhhs/s=; b=VFxxsmVbJ3X0OH2h0K0hTdM2N7kTA2NoHXrZgrn1yH2WGmP6rG0B3Yyf FeeInQ4XMzlAW18hqeA/Cf5bas/F1MdB0plXMIYQCYTnjHDGqMvAcIho7 R4RjXGO0n2DdYnUYIzEaiL0n+5bUOe5uQrs7OKgSlainEeLsJ/CYobRra tRbrVjtnqxiaH6q880sGyeTmcmWvIEm7sY3AwDHquGhZ56qc4RWecN12v p8Ckw4Yy3naGnIR33WPd6GWDW4yvdx77SjDyT2v3ZvUK8z4m61DHdpLgW DJjtbSPLA9gn/Qve+w8/ESBqqq47zGXFYRmyr9NHfJLtIVg0ZH3CwxF42 g==;
X-CSE-ConnectionGUID: BtTa7CXWQp+tf6jU/U6KVg==
X-CSE-MsgGUID: ZXbUTpWMSUaDledG7Eb+pQ==
X-IPAS-Result: A0AFAACke91o/5UQJK1aGQEBAQEBAQEBAQEBAQEBAQEBARIBAQEBAQEBAQEBAQFAJYEbAwEBAQEBCwGBPDEqKAd5AoEcSYggA4UsiHYDi2SMG4E7hGAUgWsPAQEBDQI3GgQBAYUHAoxFAiY1CA4BAgQBAQEBAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQEBAQIBEmcFCwIBCBEEAQEhAwQHIBEUCQgCBAENBQgagmGCHRYHAw8mAwECDqMBAYFAAooreIE0gQHdPg2CW4FJAYJ0hT4eASqBKgqCBoIIO4IJgTh7JxuBSUSBFUKCaD6BBYEaQgEDgSkBEgEjBRgIBQoCBoNXgi8EgiKBAhQdijACgTCEMIQqg2iHH1JyIgMmMywBVRMXCwcFgSBDAyo0MSNLBS0dgSd3gmqBKoQeK0+CHHKBdFdBg1MSDAZrDwaBFRlJAgICBQJDPoFqBhwGHxICAwECAjpXDYF4AgIEgjKBEoIqD4FJAwttPTcUGwUEgTUFlzkHEESCUxFbBwEwDB8EBxQUJQZGAhArHAE3ByUpIhEHkmCDSYwpjl+UJnEKhByKGIIGgliMZYYyF4QEjROYbWeZBiKRb5ErMIUqAgQCBAUCEAEBBoFqAzdpcHAVgyIJSRkPji0WHHYBAoJ8wxd4AjoCBwEKAQEDCZNnAQE
IronPort-PHdr: A9a23:7ULXah1T9aqU2PecsmDPmlBlVkEcU/3cNwoR7N8gk71RN//l9JX5N 0uZ7vJo3xfFXoTevupNkPGe87vhVmoJ/YubvTgcfYZNWR4IhYRenwEpDMOfT0yuBPXrdCc9W s9FUTdY
IronPort-Data: A9a23:kdeRKK2HXiWsFXhTSPbD5dFwkn2cJEfYwER7XKvMYLTBsI5bpzYGy TZMXWuPOfiOajb1fYhzaI+3908G65LUmt5hGQo63Hw8FHgiRegpqji6wuYcGwvIc6UvmWo+t 512huHodZ5yFjmG4E70aNANlFEkvYmQXL3wFeXYDS54QA5gWU8JhAlq8wIDqtYAbeORXUXU6 bsen+WFYAX4gmYsazpOg06+gEoHUMra6WtwUmMWPZinjHeG/1EJAZQWI72GLneQauF8Au6gS u/f+6qy92Xf8g1FIovNfmHTKxBirhb6ZGBiu1IOM0SQqkEqSh8ajs7XAMEhhXJ/0F1lqTzeJ OJl7vRcQS9xVkHFdX90vxNwS0mSNoUekFPLzOTWXcG7lyX7n3XQL/pGJl0KNNIzytlOGSJS+ 6IaFXcwMDO9iLfjqF67YrEEasULJc3vOsYb/3pn1zycVKxgSpHYSKKM7thdtNsyrpkRRrCFO YxAN3w2MEWojx5nYj/7DLolkuO1hmPyaRVTqUmeouw85G27IAlZjea8bIqMIIfaLSlTtnSor F/651vcOSwTGNiSxRXa33jvntaayEsXX6pXTtVU7MVCjEeayHBWCRAKWx6/qPyhkQumQpdUL EkM/TEvsaV3702kVfH8UgG25nmesXY0X9NVC/Z/4wGEy7DPyweUGmZCSSROAPQ9rMYtQBQr2 0OH2dTzClRSXKa9QHaZ8PKQ6Di1IyVQdDVEbi4fRgxD6N7myG0usi/yoh9YOPfdpvX+GCr7x HaBqy1WulnZpZRjO3mTlbwfvw+Rmw==
IronPort-HdrOrdr: A9a23:oeC9iaxNeuUJdMsaOcyNKrPxbOgkLtp133Aq2lEZdPULSL36qy n+ppQmPEHP6Qr5AEtQ5+xoWJPtfZvdnaQFh7X5To3SLTUO2VHYY72KgrGSuQEIdxeOktK1kJ 0QDJSWa+eAQ2SS7/yKnTVQeuxIqLLogcLY4Ns2jU0dMT2CAJsQljuRfzzraXGeMzM2fabReq DsgfZvln6LQ1hSRMK9AXUOQujEoPP2tL+OW3Q7Li9iwjOjyRez5pDHMzXw5HojujV0rosKwC zgqUjU96+ju/a0xlv3zGnI9albn9Pn159qGNGMotJ9EEStti+YIKBaH5GStjE8p++irHwwls PXnhsmN8Nvr1vMY2COpwf30QWI6kds15ai8y7bvZLQm728eNsIMbsHuWufSGqe16MUhqA47E uM5RPBi3MYN2KZoM233am5a/gjrDvGnZNlq59Ts5SaOrFuMoO4auckjRho+JtsJlOJ1Kk3VO ZpF83S//BQbBeTaG3YpHBmxJi2Um00BQrueDlJhiW56UkfoJlC9TpS+OUP2nMbsJ4tQZhN4O rJdqxuibFVV8cTKaZwHv0IT8e7AnHEBUukChPfHX33UKUcf37doZ/+57s4oOmsZZwT1ZM33J DMSklRu2I+c1/nTceOwJpI+BbQR3jVZ0Wh9uhOo5xi/rHsTrviNiOODFgojsu7uv0aRtbWXv 6iUagmSsML7VGeb7qh8zeOLKW6c0NuJfH9kuxLL26zng==
X-Talos-CUID: 9a23:f8q/8GG/XhIbwtQgqmJN6HIdResVTUTFj2vefU2FTls3a4OaHAo=
X-Talos-MUID: 9a23:ReFbqQWPSWC47a/q/A3cjgxeLPhN2JmnJEQAnbpZlsPHLRUlbg==
X-IronPort-Anti-Spam-Filtered: true
Received: from alln-l-core-12.cisco.com ([173.36.16.149]) by alln-iport-4.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 01 Oct 2025 19:08:49 +0000
Received: from alln-opgw-3.cisco.com (alln-opgw-3.cisco.com [173.37.147.251]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-12.cisco.com (Postfix) with ESMTPS id 9418618000156; Wed, 1 Oct 2025 19:08:49 +0000 (GMT)
X-CSE-ConnectionGUID: BcwDgfToTw2A8K+TYrxmBA==
X-CSE-MsgGUID: bLq9rc+nSxWaYcSeMAQePw==
Authentication-Results: alln-opgw-3.cisco.com; dkim=pass (signature verified) header.i=@cisco.com
X-IronPort-AV: E=Sophos;i="6.18,307,1751241600"; d="scan'208,217";a="34073364"
Received: from mail-ch4pr07cu00107.outbound.protection.outlook.com (HELO CH4PR07CU001.outbound.protection.outlook.com) ([40.93.20.103]) by alln-opgw-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 01 Oct 2025 19:08:49 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=p2dlH/ilvqGLycm+0QxrkmMUhRhHrNLfDR9HBJpdQC5jbHQvIPwywRdBZz1U2SIWbhu2+pyyPpOUucau3T2PAYtFH/SKtZ1iXMoxO7BvbXvfOI3C7HDupuIg2fKhs2aKN8j/BAXcieHbUpBPclJiCA6u0LnIjgmBacf6bmapCBW6nDcYx9zhNLxgPVcYQVKy8WHi7oHL9J1bwFg6THtW1NHs7ecRLSTk3miV3SjuVAJWiJ0XXI4NWHrhsATsvmlFSEpV7Eu75+wjf0y8Ca2j9eU/T+W3ZELgswMWbIDQO0SlJ1eNARxqdCHaSaLe4PstGvuhMR3dwGqIEy4p0xmVVw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=U5mCAIZSUf6LMKlH9V8G9of6bMtk+oMg2DXfxPhhs/s=; b=tMqy5E0AbWuUnQuM4y9pxBSrFWFK/bPi5s7ncDDiIFHq0wdjKxPHizLtF1qBnjT5Z2pXksC2zHC+d3IAWtc8MVXgMGGxNYW/+10/ngiaGlu3yNc3efGAJyjQhHGzUBYS3eD4A0YtG0f4trfnUCgw/CSg8viZb9LrWcJAcKGIw7EqcNX9PuMq4emPpdbNZWRMREL+wgXQTuP12Zj6G2ObNcr2ThfYlbi7YMdLgWkj9t2/YWzOHS11ueKqpKgP6dR6vqhfyt6EBLbETFxs/AqZReccjqeNNleytxzh3mUoa1VzevBNvH2d2DnZbUojzZfdC87mje4soMRQpUrxS/6r/w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from IA3PR11MB9133.namprd11.prod.outlook.com (2603:10b6:208:572::22) by DS0PR11MB7411.namprd11.prod.outlook.com (2603:10b6:8:150::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9160.17; Wed, 1 Oct 2025 19:08:46 +0000
Received: from IA3PR11MB9133.namprd11.prod.outlook.com ([fe80::b5d1:1822:49f9:b4ed]) by IA3PR11MB9133.namprd11.prod.outlook.com ([fe80::b5d1:1822:49f9:b4ed%6]) with mapi id 15.20.9115.020; Wed, 1 Oct 2025 19:08:46 +0000
From: "Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com>
To: Mike Ounsworth <ounsworth+ietf@gmail.com>, Peter C <Peter.C@ncsc.gov.uk>
Thread-Topic: [EXTERNAL] Re: [lamps] Re: WG Last Call: draft-ietf-lamps-pq-composite-sigs-08 (Ends 2025-10-06)
Thread-Index: AQHcK9j+05VPmn5nD0WQ7ELp9zdZ2LSiHFQAgAUHFgCAAyXbAIAABzEAgAMZpwWAACy6gIAAEhuAgAABaICAAAaiiw==
Date: Wed, 01 Oct 2025 19:08:46 +0000
Message-ID: <IA3PR11MB9133CC2126CA2EECB91C1C4BC1E6A@IA3PR11MB9133.namprd11.prod.outlook.com>
References: <175855620751.648048.16646357165291761730@dt-datatracker-6c6cdf7f94-h6rnn> <88B43AFC-A176-4125-93D0-2A724D6603C4@vigilsec.com> <LO2P123MB70512155059C90E0339F1190BC1CA@LO2P123MB7051.GBRP123.PROD.OUTLOOK.COM> <CAKZgXHqH0=eJr+ikDnirO+BKHX1O0OhXFecrgBiBW0s+hQ9ePg@mail.gmail.com> <b6c4c399-5bcc-4f4a-8823-b1369953522c@mtg.de> <CH0PR11MB573947BD9F3BFA86A43948DD9F1BA@CH0PR11MB5739.namprd11.prod.outlook.com> <IA3PR11MB91331C8D9B330840676EDF65C1E6A@IA3PR11MB9133.namprd11.prod.outlook.com> <LO2P123MB705145E25B818210D71A1DB6BCE6A@LO2P123MB7051.GBRP123.PROD.OUTLOOK.COM> <CAKZgXHptn2aBkY1UQLA=FnWCK2oH+FttHvnmnwQZikK71t=79Q@mail.gmail.com> <CAKZgXHrfXwe0cCTB-tW6vR6N9F2xx6c9y9LXNixLWdY3q=v8Yw@mail.gmail.com>
In-Reply-To: <CAKZgXHrfXwe0cCTB-tW6vR6N9F2xx6c9y9LXNixLWdY3q=v8Yw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: IA3PR11MB9133:EE_|DS0PR11MB7411:EE_
x-ms-office365-filtering-correlation-id: 871387a9-17e5-4cd4-c94e-08de011df23e
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|376014|8096899003|7053199007|38070700021;
x-microsoft-antispam-message-info: 6oMc4eC6itLPQDpLkbYNhqHk67yv/BLpqpAIhUiBgwL94w78d+XseDlVDDrP+T5Z++IZYYL738JhoesfuVY6qLJlejePNRmK4IlS6FiIfdvV6hnzVot77LmUNCH/tvrsklBsgSYPa2P1ETVj/528G5hGAC1TWtBKdRWN71GbzQiJbBJsrHdJlVNKRqmToR9wjCMugZjEcGUZJGFSWzbToWzE/Gfesv1Wi+4pa/6TZbyLLQmmsQTl/cb/AFSOt5208lcleAR4XL3nQkBH4b5H939n2j19xsKrwfpqePC1/OxrQB+M9ae7tr2yvkKRe1VtBvP4Wm5Tt9ORJqQULZjDKZO55CoGy/9sBUP6ARzQUfBTm0aZnTxZbUxchx7wOyj/3cjIbb9fyr65kb0FLKpVnR1nHGkdv+TJH/SlLU3aK6AB5psyFaZzf5POWW9x+U3YNxAAhplg1Y7rHcko2sHmpCeDhwgXNnZAswkiYt4VnZQiElRDbsJN0CcUEkl5+G2pUAcTCrlVaVhRZGXt2sUtJ2SL23gvx0/q03CQdLM2lGeSxP8hPoIpCCSHLLgxdNw5HcQ7G6OynjO09GxVcJw5npJ95trTj+pqwOKE/CdWCmfF12QM1QnrLOWy6rPPZNEyXUxRL9+OKmEm4nOivFt6LlBplh7B8JicUibURsHHy3t4N4OpJyuvHUZmnjGaBpN1dZfLqetx9zCNAJx/FvtdXZQSZ01eJoC05O8BXEbnCiT76bG+lxsnsK3BR/PHrJNTehCt3O0sYb4GAgE92VeqI68xqVjfNCTWG9Pq5fvQFHdycSPO43EkX09v65LXHH8s+/fkNQFHkn5eMw/gSCBM8rFhnsOmLK6W+XtsfQ9isegLD3n1U+t5M6kMJ3WS1bnF0e8If0sry8axzcTuPQYFH1I7hKmBIc4c5elRB9Tp6Ka8WSPvh8CVjs8CcAEOTrTpeDXP+edjfYqz9gzHCjMEOVMNlQwAhik7dZ1ugMmeINi7C/oAbsxwXF0VA4H2fTo3PLFgqBHIQYDd6tSS/AAc5alh8jIRkJ5hajR+EJ/LBzPnF13XKP9iChlRjXZO59vj8SuFGB3LFvekVvISQpJbUtQK0WdX3bLgUcp4l84J4+NkJvH52wd9qmOG6lH+Uk4J+VdI4hwL5KdGfjmunPyRF3FSF5PttBmBU3ub50mm1gnqw5dWCRmwLIOIc37/S8nT4bBADQFl2nxaAQzODpoEWJM7tnrsg1T0Q74q9PTbYZwtqUSA1qr3+M3/VfI02sZHXRcbgkafhGoFXVjAaFTAVeqMn3WlwOEFgL3yVHuCUY+Jr5KXvfH8iwPAU9xfUU13ZOgRhCQsJ3RJXfqDMgQZZ+lTF15K8KI1iyb+qdMlTRLe2L2CEIt5OsxyoBmKG5iIKRaHn+P8XX6AzCRhWp4cRGtaaZVRsT1hOOV06kDLCEuPFnoxpq9Pa7R6n8rcDI4YEw/4alNfjHruWPuogOpFlQ==
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:IA3PR11MB9133.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(376014)(8096899003)(7053199007)(38070700021);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Z2xi8sV57ueMfVOw/F1neh0i9uXj/5mYtr95K+AUTfVM2n1Gpgqe8nQacoxvpxG/AlMZcUQkNXyr2qKlnD9aGrfLa53qmlrL2eIBljuiE9OVVknCU70Oz4WhXJXiP8afkcvNB6stEgA1R8oFddMJoCsrK5yJ8U3m2jnqk7wHnELkc9y+GDLo4+O7KCmWTsHXB8YUngTT5+7SQRnnsmBGalbfWx22CHTnO5TvdpX3OnDo05WQVPb8kAFizYjnKha59MAP7HHK88SRrH9PTH1cX+M5NqjvEaJ7rpYdN3P+dLfwcJ1zMMjwI4/jAescl9uABCV8nNjgqbu2IW/7uKRC33Q1xAFYnTpVAfUA4SmnwpZGnU8kgi5pFB91LEtqZ/oF0qAb5eibygmmQ8hhcV5NCpLQdRHoOR9uFEnxmHhl+e9iVxjomVPrrMsBK2H8QrTsrjMHYpALPpn+rEf7qHEec+x2d0yap2a+5gYWcLw2hKfpYCLVhnspFNUkf+0Ovmq7RB60huE5AC/bLcpR90lifEIb8MqJXKOCBk9Cplq3RM8yqJ99+8379G7jmc1h22M/NgjktlGom4Sv6M1pUm8Tc069u1vNQ6wB2z1G/WvOvxCSvTrh6B9hCqRKJh85KnMWu393U9nlDr1qfGn2EpME5R4hxN7QKg9xCaH5J/L5Xev4vtW4LTkfmrovUSZ+Hpgrif1VGZc+7SyU8sOvFM3S3x3aG9EToOIhsYz73gJvQuotTQBzHZlK1UZZ0t2SI9++wJvkHfGorQSBHmvNOx72WJhS7KCsXa8qPsw6yl5M9Q50nyZjlAZWDICSANLm0pKyTgMB+zdkfFr0p861xFPX3B3Q1xlvw0imuEQDDF/5YZT784C4JVp1UM5k3vU/YEflihgOfTlkpEWDicoWFjTm58P0RsGVKr1du81x/qu82xrjjXV2iL8haKjQqRI/DTKSb49ckpWOZFGn1S4+u1gyJtPJ1g7DtrJuP0E+B5Srbnw40yC+kF73sziewmoNXamRyiVJ00lFjEL+xRPChS/k3h/SQI0D8wfCzO9NhWWDea138gtXPsFoON3+hRrqKUkvy0FFdhnEwUe+8RcxtEDXcFmu+wMSUkMKFi9EVFEyja68Zjj08omj/NBC2daFOPpYvDsF0lHhbRyPTvX0Pow1DpSQxNwLt16RzhR+jTW5yJX8P3Ud0HxKgWVrBFSF3Jg/OsriXEABExNWJMiYVPO93ujXVXlFcDJFRFMLzWuddBg7AnYnQFBCcJy6kfu7kX91WKRTbe7SdAoHSHYGFG8BcfXcEPPLKCOZ3iZDbeznOzXD0Y7qJ20tc4Dpdu6WjDH+6O1nXmKravUcJSc7c/kvT6AwNIFsFAiKh4UyuKBb+le33/7YadW5ALvV3YI6AQqiyG3FIJkjc141hbWPxR+n6hUWXfckT+SRNemX74MQUcBIJ48Ad288FNBptoKhIY6zMXzJZMFSRisNc7TPF+KdX9X9yEcn8CjTO5U0fEZPtO3/AyZega6aysNIdZWUzNDG1cS/PR3SBFe3dbLeW5k1x0XAOopLLnSJanpx0nHe6MU=
Content-Type: multipart/alternative; boundary="_000_IA3PR11MB9133CC2126CA2EECB91C1C4BC1E6AIA3PR11MB9133namp_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: IA3PR11MB9133.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 871387a9-17e5-4cd4-c94e-08de011df23e
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Oct 2025 19:08:46.2444 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: I1/DTuTeBh53NAFi3AX2wUbvraChoBAL3YvOFjU+FS2S1fb/zx21lvgJZLhlH75U6w8HmVPzErh1LHHAGbVU9A==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS0PR11MB7411
X-Outbound-SMTP-Client: 173.37.147.251, alln-opgw-3.cisco.com
X-Outbound-Node: alln-l-core-12.cisco.com
Message-ID-Hash: ZYJIMCB4UMNAJYROI5GPUYZ7NO6WOJEU
X-Message-ID-Hash: ZYJIMCB4UMNAJYROI5GPUYZ7NO6WOJEU
X-MailFrom: sfluhrer@cisco.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spasm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Mike Ounsworth <Mike.Ounsworth@entrust.com>, Falko Strenzke <falko.strenzke@mtg.de>, Russ Housley <housley@vigilsec.com>, "spasm@ietf.org" <spasm@ietf.org>, "draft-ietf-lamps-pq-composite-sigs@ietf.org" <draft-ietf-lamps-pq-composite-sigs@ietf.org>, "lamps-chairs@ietf.org" <lamps-chairs@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draft-ietf-lamps-pq-composite-sigs-08 (Ends 2025-10-06)
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/fHaNLp4uNBcTIXag8Cfo33gE5AY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>
Mike is right. The relevant question is "can you fool an innocent third party", that is, "can you create a message and signature pair that will be accepted by a pure ML-DSA verifier which is implemented as specified in draft-ietf-lamps-dilithium-certificates", given access to composite signatures (with the same ML-DSA private key). Because you cannot (because of the mismatch in the context strings), you have nonseparability, at least in that aspect. In fact, we have nonseparability against any use that doesn't use the precise context string which happens to be the label for the composite parameter set. Of course, we don't have comparable separability in the RSA side; I don't believe that is possible while treating the RSA implementation as a black box. ________________________________ From: Mike Ounsworth <ounsworth+ietf@gmail.com> Sent: Wednesday, October 1, 2025 2:27 PM To: Peter C <Peter.C@ncsc.gov.uk> Cc: Scott Fluhrer (sfluhrer) <sfluhrer@cisco.com>; Mike Ounsworth <Mike.Ounsworth@entrust.com>; Falko Strenzke <falko.strenzke@mtg.de>; Russ Housley <housley@vigilsec.com>; spasm@ietf.org <spasm@ietf.org>; draft-ietf-lamps-pq-composite-sigs@ietf.org <draft-ietf-lamps-pq-composite-sigs@ietf.org>; lamps-chairs@ietf.org <lamps-chairs@ietf.org> Subject: Re: [EXTERNAL] Re: [lamps] Re: WG Last Call: draft-ietf-lamps-pq-composite-sigs-08 (Ends 2025-10-06) Peter, One additional point though. You said: > The discussion in composite-sigs-08 was framed in terms of an attacker with access to the underlying signing oracles and in that case the context string is just another input to ML-KEM.Sign. I'm not sure I agree though. It's actually not ML-KEM.Sign that's important, it's actually ML-KEM.Verify that matters. And if the attacker controls ML-KEM.Verify, then you're in a Game Over scenario anyway. Scott's point is that because we use an ML-DSA ctx within the composite, but (at least within X.509 and CMS) require ctx to be empty in pure ML-DSA, it is not possible to create a (M, \sigma) pair that is simultaneously valid in both contexts. I am a bit nervous about hacking at Security Considerations during WGLC like this, so I want to slow down and give this some more careful thought before making more text changes. On Wed, 1 Oct 2025 at 13:22, Mike Ounsworth <ounsworth+ietf@gmail.com<mailto:ounsworth%2Bietf@gmail.com>> wrote: Hi Peter, > I’m in favour of reframing the security considerations so that it is clearer which properties of the composite construction hold generally, which only hold when it is used within X.509 or CMS, and which only hold with additional mitigations. Yes. This is the main point. I agree that I was sloppy with this in the changes that I made in -09 I will do another pass over the security considerations. On Wed, 1 Oct 2025 at 12:17, Peter C <Peter.C@ncsc.gov.uk<mailto:Peter.C@ncsc.gov.uk>> wrote: While this might be true for the use of composite ML-DSA and standalone ML-DSA as specified by LAMPS, it is not true in general. The discussion in composite-sigs-08 was framed in terms of an attacker with access to the underlying signing oracles and in that case the context string is just another input to ML-KEM.Sign. I’m in favour of reframing the security considerations so that it is clearer which properties of the composite construction hold generally, which only hold when it is used within X.509 or CMS, and which only hold with additional mitigations. Peter From: Scott Fluhrer (sfluhrer) <sfluhrer=40cisco.com@dmarc.ietf.org<mailto:40cisco.com@dmarc.ietf.org>> Sent: 01 October 2025 15:54 To: Mike Ounsworth <Mike.Ounsworth@entrust.com<mailto:Mike.Ounsworth@entrust.com>>; Falko Strenzke <falko.strenzke@mtg.de<mailto:falko.strenzke@mtg.de>>; Mike Ounsworth <ounsworth+ietf@gmail.com<mailto:ounsworth%2Bietf@gmail.com>>; Peter C <Peter.C@ncsc.gov.uk<mailto:Peter.C@ncsc.gov.uk>> Cc: Russ Housley <housley@vigilsec.com<mailto:housley@vigilsec.com>>; spasm@ietf.org<mailto:spasm@ietf.org>; draft-ietf-lamps-pq-composite-sigs@ietf.org<mailto:draft-ietf-lamps-pq-composite-sigs@ietf.org>; lamps-chairs@ietf.org<mailto:lamps-chairs@ietf.org> Subject: Re: [EXTERNAL] Re: [lamps] Re: WG Last Call: draft-ietf-lamps-pq-composite-sigs-08 (Ends 2025-10-06) That is correct; for composite ML-DSA, we use a nonempty context string, and for pure ML-DSA, the context string is empty. Hence, a stripping attack against a composite ML-DSA signature cannot be used to create a valid pure ML-DSA signature for any message (assuming no break on SHAKE, of course). A stripping attack can be used to take a composite signature, and so we don't get full nonseparability. However, we do get some. ________________________________ From: Falko Strenzke Sent: Monday, September 29, 2025 9:51 AM To: Mike Ounsworth; Peter C Cc: Russ Housley; spasm@ietf.org<mailto:spasm@ietf.org>; draft-ietf-lamps-pq-composite-sigs@ietf.org<mailto:draft-ietf-lamps-pq-composite-sigs@ietf.org>; lamps-chairs@ietf.org<mailto:lamps-chairs@ietf.org> Subject: [EXTERNAL] Re: [lamps] Re: WG Last Call: draft-ietf-lamps-pq-composite-sigs-08 (Ends 2025-10-06) Am 27.09.25 um 16:46 schrieb Mike Ounsworth: The first case (attacker constructing a composite signature from individual components) is indistinguishable from the situation where a legitimate signer stores the component private keys in separate cryptographic modules (as mentioned in section 4.1). Weak non-separability only allows a verifier to detect the second case (attacker splitting a composite signature into its individual components). I am not sure what the current discussion is about exactly, but just this remark: constructing a valid composite signature and message from two component signatures must fail for the proposed combiner, since for the ML-DSA component signature the context parameter is non-empty whereas for the standalone ML-DSA as defined by the current LAMPS draft it is always empty. I didn't check both drafts right now, but previously this was true and I am not aware that the handling of the context parameter was changed in either draft recently. Falko -- MTG AG Dr. Falko Strenzke Phone: +49 6151 8000 24 E-Mail: falko.strenzke@mtg.de<mailto:falko.strenzke@mtg.de> Web: mtg.de<https://www.mtg.de/> ________________________________ MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany Commercial register: HRB 8901 Register Court: Amtsgericht Darmstadt Management Board: Jürgen Ruf (CEO), Tamer Kemeröz Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you are not the correct recipient or have received this email in error, please inform the sender immediately and delete this email.Unauthorised copying or distribution of this email is not permitted. Data protection information: Privacy policy<https://www.mtg.de/en/privacy-policy> Any email and files/attachments transmitted with it are intended solely for the use of the individual or entity to whom they are addressed. If this message has been sent to you in error, you must not copy, distribute or disclose of the information it contains. Please notify Entrust immediately and delete the message from your system.
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… John Mattsson
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… tirumal reddy
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… tirumal reddy
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Peter C
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Peter C
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Salz, Rich
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Peter C
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Corey Bonnell
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: [EXTERNAL] Re: WG Last Call: draft-ie… John Gray
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Ilari Liusvaara
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Salz, Rich
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Pala, Max
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Falko Strenzke
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Salz, Rich
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Bas Westerbaan
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Falko Strenzke
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Falko Strenzke
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Ilari Liusvaara
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Bas Westerbaan
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Falko Strenzke
- [lamps] WG Last Call: draft-ietf-lamps-pq-composi… Russ Housley via Datatracker
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… John Mattsson
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Scott Fluhrer (sfluhrer)
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Peter C
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Corey Bonnell
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Falko Strenzke
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Falko Strenzke
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Falko Strenzke
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Scott Fluhrer (sfluhrer)
- [lamps] Re: [EXTERNAL] Re: WG Last Call: draft-ie… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Peter C
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… John Mattsson
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… John Mattsson
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Scott Fluhrer (sfluhrer)
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Peter C
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: WG Last Call: draft-ie… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Ilari Liusvaara
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… John Mattsson
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Ilari Liusvaara
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Tim Hudson
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… David Hook
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Dennis Jackson
- [lamps] Re: [EXTERNAL] Re: WG Last Call: draft-ie… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Sophie Schmieg
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Popis Piotr
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Jean-Pierre Fiset
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Bas Westerbaan
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Blumenthal, Uri - 0553 - MITLL
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… David Benjamin
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Dennis Jackson
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Blumenthal, Uri - 0553 - MITLL
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Mike Ounsworth
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Blumenthal, Uri - 0553 - MITLL
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Viktor Dukhovni
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Watson Ladd
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… David Hook
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Dennis Jackson
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Viktor Dukhovni
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… David Hook
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Dennis Jackson
- [lamps] Re: [EXTERNAL] Re: [EXT] Re: WG Last Call… John Gray
- [lamps] Re: [EXTERNAL] Re: [EXT] Re: WG Last Call… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: [EXT] Re: WG Last Call… Dennis Jackson
- [lamps] Re: [EXTERNAL] Re: [EXT] Re: WG Last Call… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: [EXT] Re: WG Last Call… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: [EXT] Re: WG Last Call… Dennis Jackson
- [lamps] Re: [EXTERNAL] Re: [EXT] Re: WG Last Call… Viktor Dukhovni
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: [EXTERNAL] Re: [EXT] Re: WG Last Call… Viktor Dukhovni
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Ilari Liusvaara
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Daniel Van Geest
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Daniel Van Geest
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Daniel Van Geest
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Michael Richardson
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Wei-Jun Wang
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Mike Ounsworth
- [lamps] Re: [EXTERNAL] Re: WG Last Call: draft-ie… Carl Wallace
- [lamps] Re: [EXTERNAL] Re: Re: WG Last Call: draf… John Mattsson
- [lamps] Re: [EXT] Re: WG Last Call: draft-ietf-la… Richard Kettlewell
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… D. J. Bernstein
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… David Hook
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… John Mattsson
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Tim Hudson
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: [EXTERNAL] Re: WG Last Call: draft-ie… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Tomas Gustavsson
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Watson Ladd
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Kris Kwiatkowski
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Carl Wallace
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… David Hook
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… David Hook
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Mike Ounsworth
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Daniel Van Geest
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Daniel Van Geest
- [lamps] Re: [EXTERNAL] Re: WG Last Call: draft-ie… John Gray
- [lamps] Re: WG Last Call: draft-ietf-lamps-pq-com… Russ Housley