davsclaus commented on code in PR #27500:
URL: https://github.com/apache/camel/pull/27500#discussion_r4215824916


##########
components/camel-pqc/src/main/docs/pqc-key-lifecycle.adoc:
##########
@@ -1202,22 +1202,27 @@ The lifecycle manager provides sensible defaults for 
all algorithms:
 |===
 |Algorithm |Default Parameter Spec
 
-|DILITHIUM |dilithium2
+|DILITHIUM |ML-DSA-44
 |FALCON |falcon_512
-|SPHINCSPLUS |sha2_128s
+|SPHINCSPLUS |SLH-DSA-SHA2-128S
 |XMSS |10-tree height with SHA-256
 |XMSSMT |XMSSMT-SHA2-20d2-256
 |LMS/HSS |LMS-SHA256-N32-H10 with SHA256-N32-W4
 |NTRU |ntruhps2048509
 |NTRULPRime |ntrulpr653
 |SNTRUPrime |sntrup761
 |SABER |lightsaberkem128r3
-|FRODO |frodokem640aes
+|FRODO |frodokem976aes
 |BIKE |bike128
 |HQC |hqc128
-|CMCE |mceliece348864
+|CMCE |mceliece460896
 |===
 
+NOTE: With Bouncy Castle 1.86, CMCE and FRODO use the `BC` provider instead of 
`BCPQC`. The lifecycle manager defaults
+change from `mceliece348864` to `mceliece460896` and from `frodokem640aes` to 
`frodokem976aes`, respectively.
+Stored CMCE and FRODO keys generated by the old `BCPQC` implementations must 
be regenerated, and the peers
+they are shared with updated.

Review Comment:
   On this branch the change also affects DILITHIUM and SPHINCSPLUS: they now 
resolve `parameterSpec` through the ML-DSA/SLH-DSA specs, so 
`dilithium2`/`dilithium3`/`dilithium5` are rejected. Picnic goes away entirely. 
Maybe something like:
   
   ```suggestion
   NOTE: With Bouncy Castle 1.86, CMCE and FRODO use the `BC` provider instead 
of `BCPQC`. The lifecycle manager defaults
   change from `mceliece348864` to `mceliece460896` and from `frodokem640aes` 
to `frodokem976aes`, respectively.
   Stored CMCE and FRODO keys generated by the old `BCPQC` implementations must 
be regenerated, and the peers
   they are shared with updated. Picnic is no longer available. For `DILITHIUM` 
and `SPHINCSPLUS`, `parameterSpec`
   takes the standardized parameter-set names (for example `ML-DSA-65` or 
`SLH-DSA-SHA2-128S`); `dilithium2`,
   `dilithium3` and `dilithium5` are no longer accepted.
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to