On 21/06/2026 02:41, John Levine wrote:
Is ML-DSA-44 good enough or do we need ML-DSA-65?
As an FYI, OpenPGP hasn't so far defined a signature scheme using ml-dsa-44 at all, the smallest one is -65. Nor sure if s/mime did similarly or not. TLS does define a -44 based sig scheme. For DKIM2, you could credibly go with recommending either -44 or -65 for those who want a PQ option. I don't currently see a winning argument in favour of picking one over the other for a RECOMMENDED statement tbh - -44 involves fewer bits but -65 might result in almost nobody trying to turn it up to 11, achieving more consistency. Cheers, S.
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
