Closed ounsworth closed 3 months ago
To the extent possible, synchronize with the equivalent OpenPGP drafts:
https://github.com/openpgp-pqc/draft-openpgp-pqc/issues/132#issuecomment-2220386567
Request a meeting with Quynh, Falko, Aron. We also want to discuss whether we can (and whether we should) synchronize domain separators so that our composite KEMs are binary compatible.
Wow. Ok. I completely mis-read Quynh's email to LAMPS: https://mailarchive.ietf.org/arch/msg/spasm/Yh5AelwiAOXhhdjEPzWPmWekYLA/
That means we can un-twist the order in which the ss inputs are fed into the KDF; because in fact we do not need to put the traditional alg first -- keep everything consistent with the order (mlkem, trad).