[PATCH gpgme] Add RFC 9980 post-quantum public-key algorithms
Werner Koch
wk at gnupg.org
Thu Sep 24 11:35:25 CEST 2026
On Wed, 23 Sep 2026 15:24, Stavros Kousidis said:
> For the latter, the algorithm identifier denotes a family and
> parameters such as curve or key size complete the definition. For the
> RFC 9980 composites, the OpenPGP algorithm identifier itself already
> denotes the complete construction, e.g. ML-KEM-768+X25519.
Which is a major problem with that IETF reworked BSI draft. It drives
OpenPGP into the same complexity as we have seen for TLS with its
hundreds of algorithm combinations.
> Mapping that back to |GPGME_PK_MLKEM| plus auxiliary parameters
> therefore decomposes a protocol-defined algorithm and requires
> applications to reconstruct its identity afterwards. I think that is
We already do some of this. GPGME is an abstraction layer and thus
should hide some of the complexity. The algorithm numbers are anyway
only used for information/diagnostics.
> two cryptographic components, and |768| is a parameter-set
> designation, not a key length or security strength in bits.
This is the same as with DSA where a the specified length is also
implictly includes the subgroup size.
> mismatches. I strongly think this should not be pursued, and that the
> protocol-defined composite algorithm should remain represented as such
> rather than being decomposed and reconstructed later.
When generating the key you need to provide an algorithm string, like
"ed25519/cert,sign+cv25519/encr" or its current alias "default"
"bp384/cert,sign+kyber768_bp256/encr" or its current alias "pqc"
"ietf27/cert,sign+mlk768_bp384/encr" or its current alias "pqc9980"
and no algorithm numbers.
Salam-Shalom,
Werner
--
The pioneers of a warless world are the youth that
refuse military service. - A. Einstein
-------------- next part --------------
A non-text attachment was scrubbed...
Name: openpgp-digital-signature.asc
Type: application/pgp-signature
Size: 284 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-devel/attachments/20260924/8fe19d30/attachment.sig>
More information about the Gnupg-devel
mailing list