Thanks Tony for the review, raised PR
https://github.com/tireddy2/ikev2-pqc-auth/pull/44
<https://github.com/tireddy2/ikev2-pqc-auth/> to address them.

-Tiru

On Wed, 5 Aug 2026 at 06:14, Tony Li via Datatracker <[email protected]>
wrote:

> Document: draft-ietf-ipsecme-ikev2-pqc-auth
> Title: Signature Authentication in the Internet Key Exchange Version 2
> (IKEv2) using PQC
> Reviewer: Tony Li
> Review result: Has Nits
>
> OPSDIR Last Call Review of draft-ietf-ipsecme-ikev2-pqc-auth
>
> Reviewer: Tony Li
>
> Disclaimer: I don't do security. My crypto skills ended with Caesar
> ciphers. I have no expertise in IKE. This is purely an operational review.
>
> Overall: Ready, with nits
>
> Substantive:
>
> Section 3.2:
>
> Please add a reference for side-channel attacks and how they might
> apply to deterministic mode.  While I don't feel you need to write a
> tutorial on this, a reference to follow would be most helpful.
>
> Editorial:
>
> Section 1:
>
> OLD
>
>         ...
>         [FIPS205] can be employed as authentication methods within
>         IKEv2, as they have been standardized the US National
>         Institute of Standards and Technology (NIST) PQC project.
>
> NEW
>         ...
>         [FIPS205] can be employed as authentication methods within
>         IKEv2, as they have been standardized by the US National
>         Institute of Standards and Technology (NIST) PQC project.
>
> Section 3.1:
>
> OLD
>
>         IKEv2 can use arbitrary signature algorithms as described in
>         Signature Authentication in IKEv2 [RFC7427], where the
>         "Digital Signature" authentication method supersedes
>         previously defined signature authentication methods. Any PQC
>         digital signature algorithm can be incorporated using the
>         "Digital Signature" authentication method, as defined in
>         [RFC7427].
>
> These two sentences seem highly redundant.  If there is some nuance
> here, it needs clarification.
>
> OLD
>
>         DER encoded AlgorithmIdentifier ASN.1 objects will be used to
>         uniquely identify PQC signature algorithm scheme and the
>         parameter set associated with it.
>
> NEW
>
>         DER encoded AlgorithmIdentifier ASN.1 objects will be used to
>         uniquely identify the PQC signature algorithm scheme and the
>         parameter set associated with it.
>
> Please expand the acronym DER.
>
> Section 3.2.1:
>
> OLD
>         ...
>         (value 5) is defined in Section 2 of using EdDSA in IKEv2
>         [RFC8420]
>         ...
>
> NEW
>
>         ...
>         (value 5) is defined in Section 2 of "Using the Edwards-Curve
>         Digital Signature Algorithm (EdDSA) in the Internet Key
>         Exchange Protocol Version 2 (IKEv2)" [RFC8420]
>         ...
>
> Please use an explicit complete title in the reference, otherwise it
> does not parse.
>
> OLD
>         ...
>         SIGNATURE_HASH_ALGORITHMS notify. Furthermore, PQC signature
>         ...
>
> NEW
>         ...
>         SIGNATURE_HASH_ALGORITHMS notification. Furthermore, PQC signature
>         ...
>
> OR
>         ...
>         SIGNATURE_HASH_ALGORITHMS Notify payload. Furthermore, PQC
> signature
>         ...
>
> Please capitalize Notify when you are referring to a Notify payload,
> throughout the document.
>
> Section 3.3:
>
> OLD
>
>         Authentication Method Announcement: Using Announcing Supported
>         Authentication Method in IKEv2 [RFC9593], which enables peers
>         to declare their supported authentication methods.
>
> NEW
>
>         Authentication Method Announcement: Using "Announcing
>         Supported Authentication Methods in the Internet Key Exchange
>         Protocol Version 2 (IKEv2)" [RFC9593], which enables peers
>         to declare their supported authentication methods.
>
> Quoting the title is necessary for the sentence to parse.  Please
> quote accurate titles throughout the document.
>
> OLD
>         This improves interoperability when IKEv2 peers are configured
>         with multiple credential types of different type to
>         authenticate each other.
>
> NEW
>
>         This improves authentication interoperability when IKEv2 peers
>         are configured with multiple credential types.
>
> OLD
>         However, cryptographic agility, the ability to negotiate and
>         use different cryptographic algorithms is gaining increased
>         attention for ensuring long-term security and
>         interoperability.
>
> NEW
>         However, cryptographic agility, the ability to negotiate and
>         use different cryptographic algorithms, is gaining increased
>         attention for ensuring long-term security and
>         interoperability.
>
> Section 4:
>
> OLD
>         ...
>         hardness lattice problems over module lattices (i.e., the
>         Module Learning with Errors problem ((commonly referred to as
>         MLWE)).
>
> NEW
>         ...
>         hardness lattice problems over module lattices (i.e., the
>         Module Learning with Errors problem (commonly referred to as
>         MLWE)).
>
> Section 6:
>
> OLD
>         Both ML-DSA and SLH-DSA offer deterministic and hedged signing
>         modes, where the hedged signing modes includes fresh
>         randomness in the
>
> NEW
>         Both ML-DSA and SLH-DSA offer deterministic and hedged signing
>         modes, where the hedged signing modes include fresh
>         randomness in the
>
>
>
>
>
_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to