Thanks Mike for the review, raised PR https://github.com/tireddy2/ikev2-pqc-auth/pull/46 to address your comments.
-Tiru On Tue, 18 Aug 2026 at 21:47, Mike Bishop via Datatracker <[email protected]> wrote: > Mike Bishop has entered the following ballot position for > draft-ietf-ipsecme-ikev2-pqc-auth-11: No Objection > > When responding, please keep the subject line intact and reply to all > email addresses included in the To and CC lines. (Feel free to cut this > introductory paragraph, however.) > > > Please refer to > https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ > for more information about how to handle DISCUSS and COMMENT positions. > > > The document, along with other ballot positions, can be found here: > https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-pqc-auth/ > > > > ---------------------------------------------------------------------- > COMMENT: > ---------------------------------------------------------------------- > > # IESG review of draft-ietf-ipsecme-ikev2-pqc-auth-11 > > CC @MikeBishop > > ## Comments > > ### Section 3.2.1, paragraph 5 > ``` > [RFC9329]) or the underlying network is known to support sufficiently > large MTUs without fragmentation issues, since PQC public keys and > ``` > How would one know this? Is PMTUD needed here? > > ### Section 5, paragraph 17 > > "ensures" is a strong word for the unknown future. > > ### Section 8, paragraph 1 > ``` > Section 10.1.1 of PQC for Engineers [RFC9958]). For example, ML-DSA > provides SUF-CMA security. However, some algorithms, such as SLH- > DSA, achieve existential unforgeability under chosen-message attacks > (EUF-CMA; see Section 10.1.1 of PQC for Engineers [RFC9958]). This > ``` > According to RFC9958, `ML-DSA, FN-DSA, and SLH-DSA provide EUF-CMA > security.` > This text suggests that's a distinction between the two, but the citation > suggests they should be equivalent. > > ### Section 8, paragraph 3 > ``` > The Security Considerations section of PKIX Algorithm Identifiers for > ML-DSA [RFC9881] and PKIX Algorithm Identifiers for SLH-DSA [RFC9909] > apply to this specification as well. > ``` > Why are these not normative references? > > ## Nits > > All comments below are about very minor potential issues that you may > choose to > address in some way - or ignore - as you see fit. Some were flagged by > automated tools (via https://github.com/larseggert/ietf-reviewtool), so > there > will likely be some false positives. There is no need to let me know what > you > did with these suggestions. > > ### Grammar/style > > #### "References" > ``` > orithms>. [Lyu09] "V. Lyubashevsky, “Fiat-Shamir With Aborts: Applications > to > ^ > Lattice and Factoring-Based Signatures“, ASIACRYPT 2009", < > https://www.iacr.o > ^ > ``` > Be careful with so-called "smart quotes". Check orientation, etc. or just > use > regular '"' for both. > > > >
_______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
