Skip to main content

IETF Last Call Review of draft-ietf-pquip-pqc-engineers-12
review-ietf-pquip-pqc-engineers-12-artart-lc-fossati-2025-06-15-00

Request Review of draft-ietf-pquip-pqc-engineers
Requested revision No specific revision (document currently at 14)
Type IETF Last Call Review
Team ART Area Review Team (artart)
Deadline 2025-06-20
Requested 2025-05-27
Authors Aritra Banerjee , Tirumaleswar Reddy.K , Dimitrios Schoinianakis , Tim Hollebeek , Mike Ounsworth
I-D last updated 2026-06-18 (Latest revision 2025-08-25)
Completed reviews Dnsdir IETF Last Call review of -12 by Scott Rose (diff)
Opsdir IETF Last Call review of -13 by Susan Hares (diff)
Secdir IETF Last Call review of -12 by Hilarie Orman (diff)
Artart IETF Last Call review of -12 by Thomas Fossati (diff)
Tsvart IETF Last Call review of -12 by Vidhi Goel (diff)
Dnsdir Telechat review of -13 by Scott Rose (diff)
Artart Telechat review of -13 by Thomas Fossati (diff)
Intdir Telechat review of -13 by Dirk Von Hugo (diff)
Iotdir Telechat review of -13 by Mališa Vučinić (diff)
Assignment Reviewer Thomas Fossati
State Completed
Request IETF Last Call review on draft-ietf-pquip-pqc-engineers by ART Area Review Team Assigned
Posted at https://mailarchive.ietf.org/arch/msg/art/O1U3ypHBkU531SJlN0qHp-uisi0
Reviewed revision 12 (document currently at 14)
Result Ready w/issues
Completed 2025-06-15
review-ietf-pquip-pqc-engineers-12-artart-lc-fossati-2025-06-15-00
The stated goals of this document are as follows (taken from the
introduction):

  This document aims to provide general guidance to engineers working on
  cryptographic libraries, network security, and infrastructure
  development, where long-term security planning is crucial.

While the first two categories (netsec and crypto library developers)
are fully catered for, I am not sure that Section 7 provides
infrastructure developers with enough strategic and tactical insight.

This is my main issue with the document.

Personally, I find the editorial style too verbose at times and the
overall structure not particularly cohesive.  Perhaps the editors could
take a step back and review the content to reorganise, reflow, prune and
make it smoother.  However, this is certainly not a deal-breaker: the
document is very informative, and the editors have done a great job of
capturing many important facets.

One minor issue is that the impact on the IoT devices and deployments is
not mentioned.  I am flagging this as a minor issue because perhaps this
topic deserves its own document.

Nits

* Section 1: s/much of classical cryptography/much of classical public
  key cryptography/
* Section 1 (third paragraph): PQC is the acronym for Post-quantum
  cryptography, not "Post-quantum cryptographic"
* Section 1: 4th para doesn’t seem to introduce any new content. Can it
  be dropped?
* Section 1: I am confused by the statement: "PQC is based on
  conventional (that is, not quantum) math"
    * What is "quantum math"?  Is it the mathematics of quantum
      mechanics? If so, I am not sure how it differs from "conventional
      math".
* Section 3: "as this is" => "as they are"?
* What is the purpose of Section 4? Could it be a sentence instead of an
  entire section?
* Section 9:
    * OLD:
      KEMs, on the other hand, behave according to the following API:
      KEM relies on the following primitives [PQCAPI]:
    * NEW:
      KEMs, on the other hand, behave according to the following API
      primitives [PQCAPI]:
* Section 11:
    * OLD:
      The following table discusses the impact
    * NEW:
      The following table illustrates the impact