[lamps] Re: Liaison Statement from ETSI TC ESI WG PQC to IETF LAMPS working group

Jonathan Hammell <jfhamme.cccs@gmail.com> Wed, 17 June 2026 20:52 UTC

Return-Path: <jfhamme.cccs@gmail.com>
X-Original-To: spasm@mail2.ietf.org
Delivered-To: spasm@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 67813102F5C23 for <spasm@mail2.ietf.org>; Wed, 17 Jun 2026 13:52:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1781729567; bh=PpEY/CDu9a9bANr+VkflLXZNarDgBzoJjwxLISF+ozs=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=Azmq4sj1uVpF+nFMs0o2TyKup+UykWIolymlxI4zvbNb1RGKAJPuKkrglWXfQ08ge Fm1jaNQJJtuGSfj3EPFoacLwHpeuq1bu4PKJaCtavMg3GnfcnLisyW3uzq5ea0RTxK rk+wHy6YIjUMWb2lPoFSw9qjx7dhU7lT6omC/OIE=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9XJAicjzfWu8 for <spasm@mail2.ietf.org>; Wed, 17 Jun 2026 13:52:46 -0700 (PDT)
Received: from mail-pg1-x529.google.com (mail-pg1-x529.google.com [IPv6:2607:f8b0:4864:20::529]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 7A7FE102F5B01 for <spasm@ietf.org>; Wed, 17 Jun 2026 13:52:27 -0700 (PDT)
Received: by mail-pg1-x529.google.com with SMTP id 41be03b00d2f7-c88b8fe9059so118971a12.3 for <spasm@ietf.org>; Wed, 17 Jun 2026 13:52:27 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1781729540; cv=none; d=google.com; s=arc-20240605; b=MHJZZJ7GmzbPJgyeLjr6PW6eqZUha3QEZI0FDv1wy+/nEhrYbtLg6pvbNNO93LFFM/ 1FFQOk/rvQbX/UzjSieHzqj2MoIu9HyB6eCfrzwUqcx/D35BasPIeuOwzaVD0oCXllxU T0bYiWtDGNIcp/gH73h+fDeLcjOfIopa3xCXOc7XPkVE/a2s+ak6MKPmBpUEHOfkpf+c KEeuB3N7k3l35/tfjs2gHcVJkvNh/VTjGD3u9eWLSOhdHvWxVaDwuxyzN8DRxtmEs4dW sSh0XsPX0b4I14MmI2Rv7AixU1mnw1NivL93in0w/cZ2BLRc7S7ZtZZ88707tlQvhF82 2QtQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=jPbtXBBcuFAyJINZzgSTp5mO+5Q2eQmsQEA1VZ0kLV0=; fh=cAEF2sqNjOX12MOd1JgH12ZM2fyD+Pw2WWl0xg7ReWU=; b=LiLq6wb/HI7M4JU7UlgB+moLyQTEHADvNVWlMTJoBAS8UVrnxTrirvwj3RTKVjOcyB scImdTsbwfitM4O2wi/2Z+o2rTpMot8t+akHvxfQ30ukTxGEp3w3MN49XFe20/Fm5Em9 9SbxKErHZ0hS12djwmjqaz9TQLXZgNooJnT3hrZVSpBgLzHW+Yn1MqZpGvyGYyXYSSWo ZDWR+PIS7wP6DdgT3S8A7Km8/u47w4kUyPuhmPylZ/FLHWtDaMt2vSQieVCyPtDcLGjM 1QHEEATwzVXzgIATtOjQrlxZ0qPApIm121FLpuKzYmBL4LJ/mSQvZ+8Eu2a5iyU7yrpK pD/w==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781729540; x=1782334340; darn=ietf.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=jPbtXBBcuFAyJINZzgSTp5mO+5Q2eQmsQEA1VZ0kLV0=; b=aaydaZ678UwdNqmubxvix7foSATuJD5Dt71tMPA91sZr1jvtMjhHFGfQwRZkQ9hM2G BZrptI7+jC+jvL9yKMpfdLlLU/iMbL5x5sb03f3I/fDKYuVgKtD9/7MW3GDgEFV2GJaI +1OKqCdRY5IsT9q3lY+xz1DVOJDv8vwWoltbosVPyRrcrVON2aO2Ny63DEZJc0k255xs jbAPV40oJs8SgKtooUWgcKIupoccp0z9UExi+KUfbBkpV9LrDCEaHW4YrLOnnwVzq3g8 5jcB+arIGd+ems5j50g3JKNQelhBCGB8J/YwtWJkG/o5HbFWyoGE25taCq3Pbfhi3BMG xsGQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781729540; x=1782334340; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=jPbtXBBcuFAyJINZzgSTp5mO+5Q2eQmsQEA1VZ0kLV0=; b=At3/XnFJBJeDgbkn8UZbgAJHfRd+xGbQnC6H4Hh0Js8d5a30VAhrq2fe0ghyFgw8He OQI92eR5DOEi7TiwU9WW0rNhLa1ubpIQw1zWT5/BcP2D8jFDevH6YJo3YO0wYtoeUwii QFArzCemiFM6x72Y0etNSR+VMr9uCWQHiCke9a7WXsw7ANof39f1lDGhHq91oxc1Xi1G URmFisrrKoCxCgC8zbUAzmX9/4OlXZIBb4ldKVYD3m5j65EtTOKlqahsVCih4XWgKLB/ RFajSbKdkSOGbN4JAIdOvGR0AFX+s9hIXc8UmZuJIaIsB3jSZZK6leV7R6MU31T0u1/K bLEg==
X-Gm-Message-State: AOJu0Yw/+u9l7GvLWRBc94NcQj+SQvzrLQ24z7GKrB+jyzuISnbhvwcd 3ixpuMDVmvFCzFrCVlE7r8mg/SOytgr3Az0vARliTopHdg6+zaacHevJUQcSaIqXxe+h3lvJPXE DZx3csGaDJ813KGqRsKlrPq3srtUyddw=
X-Gm-Gg: Acq92OEllgfvOAOJQJbjuRAomEGFAfGxIE3CBIRhDw+7SjSvtTW0AZIqgNPwVnPK2HQ G2k2VY0CN80FQANIl6vdhip/dYz3pHbm9gxt8iAiAkr9V9+uEMgeo2Oixbjpuc2B93SQeEnV585 RM+vipXWlFbbzSOCwrLlpGufpQbWRPbtI8YVLu2XerCn5a5ZF+nmeCrT7Ahu7K9vzTTMz7DpNso hrIBG+Iev4mH9H28Q3rTGrj0PpN8F7Ra4+jIwC8UdCk9YbpbVP1faNe628t2iOJO2mSbhhOs2Q=
X-Received: by 2002:a05:6a20:b603:b0:3b4:6155:cde8 with SMTP id adf61e73a8af0-3b8be3b191dmr6121964637.21.1781729540467; Wed, 17 Jun 2026 13:52:20 -0700 (PDT)
MIME-Version: 1.0
References: <MRZP264MB1830869F62E9E74B0B2F60F9B51C2@MRZP264MB1830.FRAP264.PROD.OUTLOOK.COM> <F335A6FC-E94F-439F-890E-6D5B7C350BFB@vigilsec.com> <BD11F206-7C69-40C6-86DE-30316BE1CD0F@vigilsec.com> <14637.1781017066@obiwan.sandelman.ca> <FF87C66E-2A46-4B90-ACCE-26C4098D30D1@vigilsec.com> <PAXPR10MB4898DF978BF28343E695A5B4FE1A2@PAXPR10MB4898.EURPRD10.PROD.OUTLOOK.COM>
In-Reply-To: <PAXPR10MB4898DF978BF28343E695A5B4FE1A2@PAXPR10MB4898.EURPRD10.PROD.OUTLOOK.COM>
From: Jonathan Hammell <jfhamme.cccs@gmail.com>
Date: Wed, 17 Jun 2026 16:52:09 -0400
X-Gm-Features: AVVi8CcGWsfdQj5BZDQy2GXUUGa5wFnghOo-FQg22gE_ePNCLFsE_idPd3REkUs
Message-ID: <CALhKWghTNDk8pUoG4ThaKXH1pmxgc98H74rmaKqzt-BoghZKFg@mail.gmail.com>
To: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: H2EFEDUO5O3UJITTHNU72VXSLDIUOEQO
X-Message-ID-Hash: H2EFEDUO5O3UJITTHNU72VXSLDIUOEQO
X-MailFrom: jfhamme.cccs@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spasm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IETF LAMPS <spasm@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [lamps] Re: Liaison Statement from ETSI TC ESI WG PQC to IETF LAMPS working group
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/jiOaxaIVlpiJcc9lwr09qHt5UYk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>

Hi Russ,
Thanks for drafting this response.

Small typo for Use of the HSS/LMS in CMS:
s/RFC 8708/RFC 9708

Apologies if I'm pointing this out too late.

Jonathan

On Wed, Jun 10, 2026 at 1:39 AM Brockhaus, Hendrik
<hendrik.brockhaus=40siemens.com@dmarc.ietf.org> wrote:
>
> I like the additional pointer to RFC 9810 for managing KEM certificates as ETSI/3GPP uses CMP already.
>
> Hendrik
>
> > -----Ursprüngliche Nachricht-----
> > Von: Russ Housley <housley@vigilsec.com>
> > Gesendet: Dienstag, 9. Juni 2026 20:33
> > An: Michael Richardson <mcr+ietf@sandelman.ca>
> > Cc: IETF LAMPS <spasm@ietf.org>
> > Betreff: [lamps] Re: Liaison Statement from ETSI TC ESI WG PQC to IETF LAMPS
> > working group
> >
> > CMP and CMC already have more than one proof-of-possesion approach.  RFC
> > 9883 adds an additional workflow based on a different trust model.  So, I suggest a
> > bit higher-level description around enrollment:
> >
> > The LAMPS WG has been updating certificate enrollment protocols to
> > support certification of KEM public keys.  For example CMPv3 has been
> > published as RFC 9810.  Further work is anticipated related to
> > proof-of-possession and certificate enrollment.  We invite people
> > from the ETSI community to participate should this work get adopted.
> >
> > Russ
> >
> > > On Jun 9, 2026, at 10:57 AM, Michael Richardson <mcr+ietf@sandelman.ca>
> > wrote:
> > >
> > >
> > > Russ Housley <housley@vigilsec.com> wrote:
> > >> Please review the proposed response to this liaison statement.
> > >
> > > Weird that ETSI is using the term PQC, as they have preferred "quantum-safe"
> > > otherwise...
> > > EVerything you wrote looks fine to me.
> > >
> > > They did not ask specifically about plans for enrollment of keys that can not
> > > sign (either by policy, or because math).   Okay, that's a pet project of
> > > mine.
> > > I might add:
> > >
> > > "The LAMPS WG has been doing maintenance on enrollment protocols such as
> > CMP
> > > and EST and is contemplating starting new work to update these protocols
> > > and/or the underlying CSR concept to support algorithms that do not support
> > > signing as proof-of-possession.  We invite ETSI to participate in this
> > > process, should it get adopted."
> > >
> > >
> > >> = = = = = = = =
> > >
> > >> Since the CAdES specifications rely in particular on RFC 5652, the
> > >> LAMPS WG wants ETSI TC EIS to be aware of the work that has already
> > >> been accomplished to prepare CMS for use with PQC algorithms.  First,
> > >> RFC 9629 specifies the use of Key Encapsulation Mechanism (KEM)
> > >> Algorithms in the CMS.  Second, several specifications for the use of
> > >> PQC signature algorithms have been written, including: RFC 8708, RFC
> > >> 9814, and RFC 9882.  More are on the way, including support for
> > >> composite signature algorithms.  Third, several specifications for the
> > >> use of PQC KEM algorithms have been written, including: RFC 9936.  More
> > >> are on the way, including support for composite KEM algorithms.
> > >
> > >> Since the EN 319 412 technical specification series build on RFC 5280,
> > >> the LAMPS WG wants ETSI TC EIS to be aware of the work that has already
> > >> been accomplished to prepare public key certificates for use with PQC
> > >> algorithms.  First, several specifications for the use of PQC signature
> > >> algorithms have been written, including: RFC 9802, RFC 9881, and RFC
> > >> 9909.  More are on the way, including support for composite signature
> > >> algorithms.  Second, RFC 9935 specifies the way to carry an ML-KEM
> > >> public key as the certificate subject public key.  Similar
> > >> specifications are on the way for other PQC KEMs, including support for
> > >> composite KEM algorithms.
> > >
> > >> US NIST is assigning algorithm identifiers for PQC algorithms that they
> > >> specify, and you will see that the RFCs listed above use these
> > >> algorithm identifiers for these algorithms.
> > >
> > >> ISO has assigned algorithm identifiers for the FrodoKEM algorithm.  The
> > >> LAMPS WG is considering adopting specifications related to this
> > >> algorithm, and these use the ISO-assigned algorithm identifiers.
> > >
> > >> IANA has assigned algorithm identifiers for HSS/LMS, XMSS, XMSS^MT,
> > >> composite KEM algorithms, and composite signature algorithms.  These
> > >> algorithm identifiers are included in this registry:
> > >
> > >>
> > https://www.iana.or/
> > g%2Fassignments%2Fsmi-numbers%2Fsmi-numbers.xhtml%23smi-numbers-
> > 1.3.6.1.5.5.7.6&data=05%7C02%7Chendrik.brockhaus%40siemens.com%7Cd6c8
> > 9f1fbdba4ec6e31008dec6559442%7C38ae3bcd95794fd4addab42e1495d55a%7C1
> > %7C0%7C639166268065463639%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1
> > hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIj
> > oyfQ%3D%3D%7C0%7C%7C%7C&sdata=BWj3U%2BqMwYYaBIhUYfNxTx2MZ%
> > 2FECUz%2Faj1Okj%2F5NRzY%3D&reserved=0
> > >
> > >> Best Regards, Russ and Tim
> > >
> > >
> > >>> On Jun 8, 2026, at 11:39 AM, Russ Housley <housley@vigilsec.com>
> > >>> wrote:
> > >>>
> > >>>
> > >>>
> > >>>> Begin forwarded message:
> > >>>>
> > >>>> From: ETSI ESIsupport <ESIsupport@etsi.org> Subject: Liaison
> > >>>> Statement from ETSI TC ESI WG PQC to IETF LAMPS working group Date:
> > >>>> June 8, 2026 at 4:37:44 AM EDT To: "housley@vigilsec.com"
> > >>>> <housley@vigilsec.com>, "tim.hollebeek@digicert.com"
> > >>>> <tim.hollebeek@digicert.com>, "debcooley1@gmail.com"
> > >>>> <debcooley1@gmail.com> Cc: Nick Pope <nick.pope@secstanassoc.com>,
> > >>>> Jean-Emmanuel Perez Hernandez
> > >>>> <jean-emmanuel.perez.hernandez@nowina.lu>, Lucas PRABEL
> > >>>> <lucas.prabel@huawei.com>
> > >>>>
> > >>>> Dear IETF LAMPS experts,
> > >>>>
> > >>>> Please find attached a liaison statement from ETSI TC ESI WG PQC to
> > >>>> IETF LAMPS working group.
> > >>>>
> > >>>> 2. Actions: Considering that the CAdES specifications rely in
> > >>>> particular on RFC 5652, and that the EN 319 412 technical
> > >>>> specification series build on RFC 5280, ESI PQC would welcome
> > >>>> collaborating with the IETF LAMPS working group to ensure that the
> > >>>> CAdES standard and the EN 319 412 series remains aligned with the
> > >>>> latest and upcoming specifications from IETF LAMPS that deal with
> > >>>> PQC, in particular it is kindly requested to IETF LAMPS for an update
> > >>>> on the status of the support of PQC algorithms in IETF LAMPS
> > >>>> specifications, especially whether algorithm identifiers have already
> > >>>> been allocated for use in CMS signatures and X.509 certificates.
> > >>>>
> > >>>> 3. Date of next meetings of the originator: ESIPQC#1a 3rd July 2026
> > >>>> ESIPQC#1b 28th August 2026 ESIPQC#2 15 October 2026
> > >>>>
> > >>>> Best regards,
> > >>>>
> > >>>> Antoine.
> > >>> <ESI(26)000319_LS_form_ESI_PQC_to_IETF_LAMPS.docx>
> > >>>
> > >>> _______________________________________________ Spasm mailing list -
> > -
> > >>> spasm@ietf.org To unsubscribe send an email to spasm-leave@ietf.org
> > >
> > >
> > >> ----------------------------------------------------
> > >> Alternatives:
> > >
> > >> ----------------------------------------------------
> > >> _______________________________________________ Spasm mailing list --
> > >> spasm@ietf.org To unsubscribe send an email to spasm-leave@ietf.org
> > >
> > > --
> > > Michael Richardson <mcr+IETF@sandelman.ca>   . o O ( IPv6 IøT consulting )
> > >           Sandelman Software Works Inc, Ottawa and Worldwide
> > >
> > > **       My working hours and your working hours may be different.         **
> > > ** Please do not feel obligated to reply outside your normal working hours **
> > >
> > >
> > >
> > >
> >
> > _______________________________________________
> > Spasm mailing list -- spasm@ietf.org
> > To unsubscribe send an email to spasm-leave@ietf.org
> _______________________________________________
> Spasm mailing list -- spasm@ietf.org
> To unsubscribe send an email to spasm-leave@ietf.org