Thanks Tony for the review, raised PR https://github.com/tireddy2/ikev2-pqc-auth/pull/44 <https://github.com/tireddy2/ikev2-pqc-auth/> to address them.
-Tiru On Wed, 5 Aug 2026 at 06:14, Tony Li via Datatracker <[email protected]> wrote: > Document: draft-ietf-ipsecme-ikev2-pqc-auth > Title: Signature Authentication in the Internet Key Exchange Version 2 > (IKEv2) using PQC > Reviewer: Tony Li > Review result: Has Nits > > OPSDIR Last Call Review of draft-ietf-ipsecme-ikev2-pqc-auth > > Reviewer: Tony Li > > Disclaimer: I don't do security. My crypto skills ended with Caesar > ciphers. I have no expertise in IKE. This is purely an operational review. > > Overall: Ready, with nits > > Substantive: > > Section 3.2: > > Please add a reference for side-channel attacks and how they might > apply to deterministic mode. While I don't feel you need to write a > tutorial on this, a reference to follow would be most helpful. > > Editorial: > > Section 1: > > OLD > > ... > [FIPS205] can be employed as authentication methods within > IKEv2, as they have been standardized the US National > Institute of Standards and Technology (NIST) PQC project. > > NEW > ... > [FIPS205] can be employed as authentication methods within > IKEv2, as they have been standardized by the US National > Institute of Standards and Technology (NIST) PQC project. > > Section 3.1: > > OLD > > IKEv2 can use arbitrary signature algorithms as described in > Signature Authentication in IKEv2 [RFC7427], where the > "Digital Signature" authentication method supersedes > previously defined signature authentication methods. Any PQC > digital signature algorithm can be incorporated using the > "Digital Signature" authentication method, as defined in > [RFC7427]. > > These two sentences seem highly redundant. If there is some nuance > here, it needs clarification. > > OLD > > DER encoded AlgorithmIdentifier ASN.1 objects will be used to > uniquely identify PQC signature algorithm scheme and the > parameter set associated with it. > > NEW > > DER encoded AlgorithmIdentifier ASN.1 objects will be used to > uniquely identify the PQC signature algorithm scheme and the > parameter set associated with it. > > Please expand the acronym DER. > > Section 3.2.1: > > OLD > ... > (value 5) is defined in Section 2 of using EdDSA in IKEv2 > [RFC8420] > ... > > NEW > > ... > (value 5) is defined in Section 2 of "Using the Edwards-Curve > Digital Signature Algorithm (EdDSA) in the Internet Key > Exchange Protocol Version 2 (IKEv2)" [RFC8420] > ... > > Please use an explicit complete title in the reference, otherwise it > does not parse. > > OLD > ... > SIGNATURE_HASH_ALGORITHMS notify. Furthermore, PQC signature > ... > > NEW > ... > SIGNATURE_HASH_ALGORITHMS notification. Furthermore, PQC signature > ... > > OR > ... > SIGNATURE_HASH_ALGORITHMS Notify payload. Furthermore, PQC > signature > ... > > Please capitalize Notify when you are referring to a Notify payload, > throughout the document. > > Section 3.3: > > OLD > > Authentication Method Announcement: Using Announcing Supported > Authentication Method in IKEv2 [RFC9593], which enables peers > to declare their supported authentication methods. > > NEW > > Authentication Method Announcement: Using "Announcing > Supported Authentication Methods in the Internet Key Exchange > Protocol Version 2 (IKEv2)" [RFC9593], which enables peers > to declare their supported authentication methods. > > Quoting the title is necessary for the sentence to parse. Please > quote accurate titles throughout the document. > > OLD > This improves interoperability when IKEv2 peers are configured > with multiple credential types of different type to > authenticate each other. > > NEW > > This improves authentication interoperability when IKEv2 peers > are configured with multiple credential types. > > OLD > However, cryptographic agility, the ability to negotiate and > use different cryptographic algorithms is gaining increased > attention for ensuring long-term security and > interoperability. > > NEW > However, cryptographic agility, the ability to negotiate and > use different cryptographic algorithms, is gaining increased > attention for ensuring long-term security and > interoperability. > > Section 4: > > OLD > ... > hardness lattice problems over module lattices (i.e., the > Module Learning with Errors problem ((commonly referred to as > MLWE)). > > NEW > ... > hardness lattice problems over module lattices (i.e., the > Module Learning with Errors problem (commonly referred to as > MLWE)). > > Section 6: > > OLD > Both ML-DSA and SLH-DSA offer deterministic and hedged signing > modes, where the hedged signing modes includes fresh > randomness in the > > NEW > Both ML-DSA and SLH-DSA offer deterministic and hedged signing > modes, where the hedged signing modes include fresh > randomness in the > > > > >
_______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
