Cipher Preferences Ignored for Kyber keys?

Werner Koch wk at gnupg.org
Mon Jul 27 11:06:15 CEST 2026


On Sun, 26 Jul 2026 15:33, scuffbox said:
> honored where ciphers use a suitable key size though. GnuPG supports at least
> two other ciphers with 256bit keys, TWOFISH and CAMELLIA256, which may be
> used instead of AES256 if all recipients support/prefer them.

We already have way to many algorithms thus if there is an option to
limit them we should take this opportunity.  AES256 is the cipher
algorithm everyone use and it has hardware support.

Twofish was an AES candidate which did not make it.  Camellia was
included for pure political reasons.  Frankly, I am glad that we have
not seen a demand for other national cipher algorithms in the last 20
years (Despite that there are at least a Russian and a Chinese set of
algorithms).

RFC-9980 (the alternative PQC for OpenPGP) actually allows AES-128 with
ML-KEM but uses some wishy-washy language to justify it.


Salam-Shalom,

   Werner

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein
-------------- next part --------------
A non-text attachment was scrubbed...
Name: openpgp-digital-signature.asc
Type: application/pgp-signature
Size: 284 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260727/f615297d/attachment.sig>


More information about the Gnupg-users mailing list