Skip to content

Draft SC-XX: Add MLDSA-87#624

Draft
CBonnell wants to merge 5 commits into
cabforum:mainfrom
CBonnell:mldsa-87
Draft

Draft SC-XX: Add MLDSA-87#624
CBonnell wants to merge 5 commits into
cabforum:mainfrom
CBonnell:mldsa-87

Conversation

@CBonnell

Copy link
Copy Markdown
Member

This preliminary proposal outlines the changes needed to the TLS BR to facilitate the TLS PQC pilot program.

Comment thread docs/BR.md
For ML-DSA key pairs, the CA SHALL:

* Ensure the Key uses one of the following parameter sets:
* ML-DSA-87 (OID: 2.16.840.1.101.3.4.3.19).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Microsoft's announcement at the CABForum F2F yesterday said "Mandatory support for ML-DSA-87".

ML-DSA-44 and ML-DSA-65 weren't mentioned at all. I don't know if that implies that the PQC Pilot Program will (1) disallow these parameter sets or (2) permit (but not require) them to be supported.

If 2, then this PR should probably allow them too.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the call-out on this. I discussed this with the MSFT reps a bit ago and they confirmed that the pilot is limited to MLDSA-87 only at this point. So, I believe this language can stay as-is.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Leaving a comment here as welll, since it's not yet clear whether this PR or #662 will be the one that moves forward.

Now that we're making this change due to general preparedness, and not just the Microsoft pilot program, we should allow ML-DSA-44 and ML-DSA-65.

Comment thread docs/BR.md Outdated
Comment thread docs/BR.md
Comment thread docs/BR.md Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants