Cipher Preferences Ignored for Kyber keys?
Damien Goutte-Gattat
dgouttegattat at incenp.org
Sun Jul 26 16:35:20 CEST 2026
On Sun Jul 26, 2026 at 12:07 AM BST, scuffbox via Gnupg-users wrote:
> On upgrading to 2.5.x (2.5.20 and 2.5.21) recently to test Kyber keys,
> I have noticed that any preferences relating to cipher choice are
> being ignored.
>
> AES256 appears to be used for encryption to Kyber subkeys regardless
> of the contents of the public key's cipher preferences and the local
> config's personal-cipher-preferences.
Indeed. This is a deliberate behaviour, see the discussion on issue
https://dev.gnupg.org/T7472.
When all the keys we are encrypting to are Kyber keys, then AES-256 is
forcefully used regardless of the preferences.
You can still force the use of any other supported encryption algorithm
with the `--cipher-algo` option.
- Damien
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 265 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260726/8dd53d54/attachment.sig>
More information about the Gnupg-users
mailing list