Elektrine lite

← Feed

@pgpkeys@infosec.exchange

Post #2088630

2026-05-05 21:32 UTC

Exciting news from the coalface! The first beta of Hockeypuck 2.4 with PQC support is now live on https://test.pgpkeys.eu for public evaluation. #OpenPGP is going post-quantum in 2026, and the #Hockeypuck #keyserver software is prepared to distribute post-quantum-safe OpenPGP certificates. Hockeypuck 2.4-beta1 supports post-quantum-safe signing and encryption algorithms based on ML-DSA-65, ML-DSA-87, ML-KEM-768, and ML-KEM-1024, each used in hybrid mode with either curve25519 or curve448 ECC. These are the mandatory and recommended algorithms from the upcoming OpenPGP PQC spec [1]. In order to distribute the new primary (signing) keys safely, without adversely impacting older client software, they are only distributed over the HKPv2 API. Hockeypuck implements the `certs`, `index` and `prefixlog` endpoints as defined in the latest HKP draft spec [2]. These enable upload, download, and querying of PQC-enabled primary keys. PQC encryption subkeys using ML-KEM-65 are also distributed over the legacy HKP interface if they are attached to a v4 primary key, because these are safely ignored by #GnuPG. (GnuPG’s “kyber” algorithms are unfortunately not supported due to interoperability issues) Hockeypuck 2.4 development has been kindly supported by @NGIZero Core. [1] https://datatracker.ietf.org/doc/html/draft-ietf-openpgp-pqc [2] https://datatracker.ietf.org/doc/html/draft-gallagher-openpgp-hkp

Replies (0)

No replies.