On Mon 2019-08-05 14:24:22 -0400, Paul Wouters wrote:
On Aug 5, 2019, at 13:44, Werner Koch <wk(_at_)gnupg(_dot_)org> wrote:
I view this as problematic in the light of our preparations to allow for
larger key material. With PQC we may need megabyte large keys and then
including an entire key would double the size of a keyblock.
There is only one proposal in the NIST competition with that issue
(McEliece) , and unlikely to be the winner, precisely because of that.
I also note that PQ key material is most significantly relevant today
for *encryption/decryption* keys, which *are not* likely to be
designated revokers (McEliece itself is rarely used for signing, aiui).
--dkg
signature.asc
Description: PGP signature
_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp