Document: draft-ietf-ipsecme-ikev2-pqc-auth
Title: Signature Authentication in the Internet Key Exchange Version 2 (IKEv2) 
using PQC
Reviewer: Tony Li
Review result: Has Nits

OPSDIR Last Call Review of draft-ietf-ipsecme-ikev2-pqc-auth

Reviewer: Tony Li

Disclaimer: I don't do security. My crypto skills ended with Caesar
ciphers. I have no expertise in IKE. This is purely an operational review.

Overall: Ready, with nits

Substantive:

Section 3.2:

Please add a reference for side-channel attacks and how they might
apply to deterministic mode.  While I don't feel you need to write a
tutorial on this, a reference to follow would be most helpful.

Editorial:

Section 1:

OLD

        ...
        [FIPS205] can be employed as authentication methods within
        IKEv2, as they have been standardized the US National
        Institute of Standards and Technology (NIST) PQC project.

NEW
        ...
        [FIPS205] can be employed as authentication methods within
        IKEv2, as they have been standardized by the US National
        Institute of Standards and Technology (NIST) PQC project.

Section 3.1:

OLD

        IKEv2 can use arbitrary signature algorithms as described in
        Signature Authentication in IKEv2 [RFC7427], where the
        "Digital Signature" authentication method supersedes
        previously defined signature authentication methods. Any PQC
        digital signature algorithm can be incorporated using the
        "Digital Signature" authentication method, as defined in
        [RFC7427].

These two sentences seem highly redundant.  If there is some nuance
here, it needs clarification.

OLD

        DER encoded AlgorithmIdentifier ASN.1 objects will be used to
        uniquely identify PQC signature algorithm scheme and the
        parameter set associated with it. 

NEW

        DER encoded AlgorithmIdentifier ASN.1 objects will be used to
        uniquely identify the PQC signature algorithm scheme and the
        parameter set associated with it. 

Please expand the acronym DER.

Section 3.2.1:

OLD
        ...
        (value 5) is defined in Section 2 of using EdDSA in IKEv2
        [RFC8420]
        ...

NEW

        ...
        (value 5) is defined in Section 2 of "Using the Edwards-Curve
        Digital Signature Algorithm (EdDSA) in the Internet Key
        Exchange Protocol Version 2 (IKEv2)" [RFC8420]
        ...

Please use an explicit complete title in the reference, otherwise it
does not parse.

OLD
        ...
        SIGNATURE_HASH_ALGORITHMS notify. Furthermore, PQC signature
        ...

NEW
        ...
        SIGNATURE_HASH_ALGORITHMS notification. Furthermore, PQC signature
        ...

OR
        ...
        SIGNATURE_HASH_ALGORITHMS Notify payload. Furthermore, PQC signature
        ...

Please capitalize Notify when you are referring to a Notify payload,
throughout the document.

Section 3.3:

OLD

        Authentication Method Announcement: Using Announcing Supported
        Authentication Method in IKEv2 [RFC9593], which enables peers
        to declare their supported authentication methods.

NEW

        Authentication Method Announcement: Using "Announcing
        Supported Authentication Methods in the Internet Key Exchange
        Protocol Version 2 (IKEv2)" [RFC9593], which enables peers
        to declare their supported authentication methods.  

Quoting the title is necessary for the sentence to parse.  Please
quote accurate titles throughout the document.

OLD
        This improves interoperability when IKEv2 peers are configured
        with multiple credential types of different type to
        authenticate each other.

NEW

        This improves authentication interoperability when IKEv2 peers
        are configured with multiple credential types.

OLD
        However, cryptographic agility, the ability to negotiate and
        use different cryptographic algorithms is gaining increased
        attention for ensuring long-term security and
        interoperability.

NEW
        However, cryptographic agility, the ability to negotiate and
        use different cryptographic algorithms, is gaining increased
        attention for ensuring long-term security and
        interoperability.

Section 4:

OLD
        ...
        hardness lattice problems over module lattices (i.e., the
        Module Learning with Errors problem ((commonly referred to as
        MLWE)).

NEW
        ...
        hardness lattice problems over module lattices (i.e., the
        Module Learning with Errors problem (commonly referred to as
        MLWE)).

Section 6:

OLD
        Both ML-DSA and SLH-DSA offer deterministic and hedged signing
        modes, where the hedged signing modes includes fresh
        randomness in the

NEW
        Both ML-DSA and SLH-DSA offer deterministic and hedged signing
        modes, where the hedged signing modes include fresh
        randomness in the




_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to