davsclaus commented on code in PR #27500: URL: https://github.com/apache/camel/pull/27500#discussion_r4215824916
########## components/camel-pqc/src/main/docs/pqc-key-lifecycle.adoc: ########## @@ -1202,22 +1202,27 @@ The lifecycle manager provides sensible defaults for all algorithms: |=== |Algorithm |Default Parameter Spec -|DILITHIUM |dilithium2 +|DILITHIUM |ML-DSA-44 |FALCON |falcon_512 -|SPHINCSPLUS |sha2_128s +|SPHINCSPLUS |SLH-DSA-SHA2-128S |XMSS |10-tree height with SHA-256 |XMSSMT |XMSSMT-SHA2-20d2-256 |LMS/HSS |LMS-SHA256-N32-H10 with SHA256-N32-W4 |NTRU |ntruhps2048509 |NTRULPRime |ntrulpr653 |SNTRUPrime |sntrup761 |SABER |lightsaberkem128r3 -|FRODO |frodokem640aes +|FRODO |frodokem976aes |BIKE |bike128 |HQC |hqc128 -|CMCE |mceliece348864 +|CMCE |mceliece460896 |=== +NOTE: With Bouncy Castle 1.86, CMCE and FRODO use the `BC` provider instead of `BCPQC`. The lifecycle manager defaults +change from `mceliece348864` to `mceliece460896` and from `frodokem640aes` to `frodokem976aes`, respectively. +Stored CMCE and FRODO keys generated by the old `BCPQC` implementations must be regenerated, and the peers +they are shared with updated. Review Comment: On this branch the change also affects DILITHIUM and SPHINCSPLUS: they now resolve `parameterSpec` through the ML-DSA/SLH-DSA specs, so `dilithium2`/`dilithium3`/`dilithium5` are rejected. Picnic goes away entirely. Maybe something like: ```suggestion NOTE: With Bouncy Castle 1.86, CMCE and FRODO use the `BC` provider instead of `BCPQC`. The lifecycle manager defaults change from `mceliece348864` to `mceliece460896` and from `frodokem640aes` to `frodokem976aes`, respectively. Stored CMCE and FRODO keys generated by the old `BCPQC` implementations must be regenerated, and the peers they are shared with updated. Picnic is no longer available. For `DILITHIUM` and `SPHINCSPLUS`, `parameterSpec` takes the standardized parameter-set names (for example `ML-DSA-65` or `SLH-DSA-SHA2-128S`); `dilithium2`, `dilithium3` and `dilithium5` are no longer accepted. ``` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
