Both changes look good to me.
(I am not a fan of the choice of pure over Hash variants for Jose, but
it is a fine choice either way).

On Wed, 2026-05-06 at 08:46 -0500, Orie wrote:
> Hi,
> 
> I raised 2 new PRs. I felt we needed to address Simo's comment regarding
> the choice of algorithms, I used the smaller number as the suggestion.
> I've also added some text to align with similar text we used for ML-DSA.
> 
> https://github.com/cose-wg/draft-ietf-cose-sphincs-plus/pulls
> 
> I think these changes might be substantial enough to trigger another WGLC.
> 
> If the chairs determine they are not needed, I can close the PR and push a
> new version.
> 
> Regards,
> 
> OS
> 
> 
> 
> On Tue, May 5, 2026 at 1:22 PM Michael Jones <[email protected]>
> wrote:
> 
> > Orie, Mike, and Hannes – can you please publish a new draft containing the
> > updated examples?  At that point, if no objections are raised within a
> > week, we’ll proceed to a shepherd review.
> > 
> > 
> > 
> > Volunteers to shepherd the document are welcome.
> > 
> > 
> > 
> >                                                                 -- Mike &
> > Ivo
> > 
> > 
> > 
> > *From:* Orie <[email protected]>
> > *Sent:* Thursday, April 30, 2026 2:01 PM
> > *To:* Simo Sorce <[email protected]>
> > *Cc:* [email protected]; cose <[email protected]>
> > *Subject:* [jose] Re: [COSE] WGLC: draft-ietf-cose-sphincs-plus-07 (Ends
> > 2026-04-14)
> > 
> > 
> > 
> > I merged: https://github.com/cose-wg/draft-ietf-cose-sphincs-plus/pull/13
> > 
> > Regarding the selected algorithms, I think there has not been a lot of
> > thought about them.
> > 
> > Perhaps we just test for objections to going with the 2 128s?
> > 
> > Regards,
> > 
> > OS
> > 
> > 
> > 
> > On Mon, Apr 6, 2026 at 10:25 AM Simo Sorce <simo=
> > [email protected]> wrote:
> > 
> > I think that there should be also at least one sentence that provides
> > some rationale about why these three specific parameter sets among the
> > 12 specified in FIPS-205 were chosen.
> > 
> > I would expect either just 2 (the 128s) or 4 (2x128s + 2x128f)
> > parameter sets to be introduced, assuming size/strength is the reason.
> > 
> > That 3 were selected is curious and requires explanation.
> > 
> > Simo.
> > 
> > On Fri, 2026-04-03 at 14:55 +0200, Filip Skokan wrote:
> > > Furthermore, if you intend to keep JOSE in then please update the JOSE
> > > examples appendix section with actual working vectors. The existing
> > > "example" leaves a lot to be desired.
> > > 
> > > S pozdravem,
> > > *Filip Skokan*
> > > 
> > > 
> > > On Fri, 3 Apr 2026 at 14:40, Filip Skokan <[email protected]> wrote:
> > > 
> > > > Since this draft registers JOSE algorithms and defines JWK
> > representations
> > > > it would be prudent to send its WGLC notice there as well. cc @JOSE WG
> > > > <[email protected]>
> > > > 
> > > > I appreciate the algorithm set is kept at a minimum. But I still don't
> > see
> > > > these as general purpose algorithms that we necessarily "*need"* to
> > have
> > > > in JOSE (unlike ML-DSA/FN-DSA). I'll bite tho and say that it doesn't
> > hurt
> > > > to have them registered as backup given the novelty and some small
> > > > uncertainty surrounding the other PQC algs in general.
> > > > 
> > > > That being said I would welcome it if the draft did mention something
> > > > along those lines, these algorithms are either targeting a niche
> > purpose or
> > > > serve as backup, the former is more likely. General purpose JOSE
> > libraries
> > > > shouldn't bother implementing these. I for one certainly won't, being
> > > > mindful of the library footprint. Also none of the Web Cryptography API
> > > > implementers currently plan to support them despite being included in
> > the
> > > > API's Modern Algorithms <
> > https://wicg.github.io/webcrypto-modern-algos/>
> > > >  extension.
> > > > 
> > > > Speaking of which, the Web Cryptography extension will register all
> > > > remaining SLH-DSA parameter sets in JOSE IANA for JWK representation
> > > > purposes only (Algorithm Usage Location(s): "JWK"). It currently lists
> > the
> > > > ones from this draft too but that's merely because at some point it was
> > > > uncertain whether this is going to move forward or not. I will update
> > the
> > > > extension proposal accordingly depending on what gets published in this
> > > > draft.
> > > > 
> > > > S pozdravem,
> > > > *Filip Skokan*
> > > > 
> > > > 
> > > > On Tue, 24 Mar 2026 at 18:58, Ivaylo Petrov <ivaylopetrov=
> > > > [email protected]> wrote:
> > > > 
> > > > > Dear COSE WG members,
> > > > > 
> > > > > As discussed during IETF 125, this message starts a WG Last Call
> > (WGLC)
> > > > > for:
> > > > > https://datatracker.ietf.org/doc/draft-ietf-cose-sphincs-plus/
> > > > > 
> > > > > Please review and indicate your support or objection to proceeding
> > with
> > > > > the
> > > > > publication of this document by replying to this email keeping
> > > > > [email protected]
> > > > > in copy. Please provide rationale for support and explanations or
> > > > > suggestions
> > > > > for objections.
> > > > > 
> > > > > This Working Group Last Call ends on 2026-04-14
> > > > > 
> > > > > 
> > > > >                                                             Thank
> > you,
> > > > > 
> > > > >                                                             -- Mike
> > and
> > > > > Ivo
> > > > > 
> > > > >                                                             COSE
> > co-chairs
> > > > > 
> > > > > 
> > > > > Please note:
> > > > > Authors, and WG participants in general, are reminded of the
> > Intellectual
> > > > > Property Rights (IPR) disclosure obligations described in BCP 79 [1].
> > > > > Appropriate IPR disclosures required for full conformance with the
> > > > > provisions
> > > > > of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.
> > > > > Sanctions available for application to violators of IETF IPR Policy
> > can be
> > > > > found at [3].
> > > > > 
> > > > > [1] https://datatracker.ietf.org/doc/bcp78/
> > > > > [2] https://datatracker.ietf.org/doc/bcp79/
> > > > > [3] https://datatracker.ietf.org/doc/rfc6701/
> > > > > _______________________________________________
> > > > > COSE mailing list -- [email protected]
> > > > > To unsubscribe send an email to [email protected]
> > > > > 
> > > > 
> > > _______________________________________________
> > > jose mailing list -- [email protected]
> > > To unsubscribe send an email to [email protected]
> > 
> > --
> > Simo Sorce
> > Distinguished Engineer
> > RHEL Crypto Team
> > Red Hat, Inc
> > 
> > _______________________________________________
> > jose mailing list -- [email protected]
> > To unsubscribe send an email to [email protected]
> > 
> > 

-- 
Simo Sorce
Distinguished Engineer
RHEL Crypto Team
Red Hat, Inc

_______________________________________________
COSE mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to