On 21/06/2026 02:41, John Levine wrote:
Is ML-DSA-44 good enough or do we need ML-DSA-65?

As an FYI, OpenPGP hasn't so far defined a signature scheme
using ml-dsa-44 at all, the smallest one is -65. Nor sure if
s/mime did similarly or not. TLS does define a -44 based sig
scheme.

For DKIM2, you could credibly go with recommending either -44
or -65 for those who want a PQ option. I don't currently see a
winning argument in favour of picking one over the other for
a RECOMMENDED statement tbh - -44 involves fewer bits but -65
might result in almost nobody trying to turn it up to 11,
achieving more consistency.

Cheers,
S.


Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to