Crypto Streangth- JP CRYPTO REC recommended 192 bits instead of 128 bits as of today.
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Quiet
- Domain
- cryptography
Research direction
No repository files or tests are identified. Start by reviewing the CRYPTOREC guidance and its implications for ML-KEM, hybrid mode, mTLS, DPoP, signatures, and encryption; done requires an agreed scope for the FAPI changes and a way to validate 192-bit and hybrid-algorithm readiness.
Written by the indexing model from the issue text.
Description
Originally submitted by Nat (Nat Sakimura) on 2026-03-30
Japanese government crypto suite council, CRYPTOREC, which I declined to be a member of, issued a new guidance retiring 128-bit security algorithms and moving to 192-bit security.
Also, it has started including ML-KEM and hybrid mode.
That will be coming. ID Token will not be affected much, unless you need it as evidence on a later day. i.e., should be appropriately timestamped.
For other signature algorithms, mTLS means swapping the client certificate to be hybrid or at least make the validity short, server certificate the same, more towards the hybrid.
Need to dig a bit deeper on DPOP.
The encryption part is more of an issue, because collect now, decrypt later can be launched.
This was Japan, but it will come to IETF pretty soon, so we beter start getting ready to it.
Bitbucket status: new
Bitbucket origin: issue 858
- Dominant language
- HTML
- Stars
- 4
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openid/fapi
-
component: FAPI 1: Advanced migrated-from-bitbucket priority: major type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
migrated-from-bitbucket priority: trivial type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 5/5 Over a week Newbie friendliness 30/100
-
component: Implementation & Deployment Advice
Difficulty 2/5 1-3 hours Newbie friendliness 55/100
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
google/go-sev-guest#206 ·
-
Make Composer::append_custom_gate crate-privatePossibly taken @HDauven claimed this 2 days ago. Open
Difficulty 1/5 Under an hour Newbie friendliness 84/100
dusk-network/plonk#988 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
freedomofpress/securedrop-protocol#408 ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Documentation help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
golang/go#81933 · 2 comments ·
Maintainers usually reply within 1 day