Hi Rifaat, given the title "Guidance for Migration to Composite, Dual, or PQC Authentication" I guess we can not neglect the 'operational' impact of that choice.
IMHO, it is not enough to define and provide some data structures, rather we should care about how to use those in an existing world with a heterogeneous infrastructure; among TPMs are one part. A few years ago, it was my duty to extend the 'libdkim' with ECC signatures [1], [2]. This involved three steps: a) To generate ECC DKIM signatures (and advertise them im the email header - you can verify this by looking at this mail) in a hybrid mode. b) A parser, able to verify RSA and ECC DKIM signatures. c) To provide users with the capability to offer the DKIM public keys in the DNS (given my 'Bernstein SW' related 'universe'). Thus, my argumentation is: In order to give a valid guidance, one has to consider generation, transport, and usage of those certificates. I would call this a 360 degree view. It would be helpful if the draft can be extended to meet those requirements. Unfortunately, the last step seems to be quite research intensive to me and probably will never be 100% close to what is expected. Rather, if not in-scope, the introduction of your draft should at least mention that obstacle. Also, some kind of operational picture - providing insight into the different domains given the different data structures - would certainly help. On the long run, the (qualified) operational use of hybrid certificates could be addressed in a different document. Regards. --eh. [1] https://datatracker.ietf.org/doc/html/rfc8463 [2] https://www.fehcom.de/pub/DKIM.pdf Am Mittwoch, dem 15.07.2026 um 12:13 -0400 schrieb Rifaat Shekh-Yusef: > Hi Erwin, > > TPMs are out of scope for this document, because this deals with what > goes "on the wire". > > Can you elaborate on what you have in mind about TPMs in this case? -- Dr. Erwin Hoffmann | www.fehcom.de PGP key-id: 36553F7F9C58D1CC PGP key-fingerprint: 950B 5555 0B08 5A2A 1C00 9594 3655 3F7F 9C58 D1CC
signature.asc
Description: This is a digitally signed message part
_______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
