Wei Chuang wrote in
 <caafswk3dawklz1zvxjstddzqy+40rnqzzd2sxa-t8hv2rk8...@mail.gmail.com>:
 |At the Wednesday, June 17th DKIM interim, I asked if the working group
 |would be interested in working on PQC for DKIM/DKIM2.  Google feels a PQC
 |migration is necessary by 2029
 ...
 |We welcome feedback on the above threat model for the CFRG.

I -- now i am back again, such a mess! -- but i only want to say
that i thought about a flag seconds 0x71717171 for something like
this.

I honestly think that what currently there is is no good, it is
either too slow, or the signature is too large, or the public key
is much too large for the DNS.

However, looking forward, in the next round of what NIST
considers, there are a couple of things that look pretty good,
i would favour FAEST, but surely MQOM it will be.
All at level 1, of course.

This link is very much of interest:

  https://pqshield.github.io/nist-sigs-zoo/

Ie, i would be stunned if MQOM would land in OpenSSL by 2029, even
if it is part of liboqs as via open-quantum-safe/liboqs of github.

I think this should not be too fast again, like with ed25519,
where not even the ASN.1 syntax of the key was finished.
And software should not implement this complicated stuff itself,
or copy over code from somewhere.  Imho.

Btw i am sorry i had forgotten to switch the submissionType=""
from ietf to independent.  For the next iteration that i will ask
the IESG to publish this is fixed.
I will, after reading RFC 9958, decouple the DKIX-AC: in that
respect from the DKIX-Sig:, and i will add a Q flag to the DNS
record and i think also the signature.  To announce availability
that is, of an implementation of some alias name that will be
filled with usefulness until then.  I think the above flag second
is a good one.  Like Mr. Levine said, and i think also this DKIM2
has some x=, and quantum of that power, until 2029, this not.

Greetings.

--steffen
|
|Der Kragenbaer,                The moon bear,
|der holt sich munter           he cheerfully and one by one
|einen nach dem anderen runter  wa.ks himself off
|(By Robert Gernhardt)

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to