)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"d82e490d282e21d85b2e952ab6ef0f0eac87cd1b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"cc71418e_3582f090","updated":"2026-09-08 04:19:22.000000000","message":"This is a \"proposed\" goal - so i\u0027ve no problem fixing things up when we need to \"accept\" the goal.. but several comments inline that you can address if you make another pass.","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"100c8165ff1daa38e92116e3f81d92777d6c0d9f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"0ebb9ce6_d5db965c","updated":"2026-09-21 09:43:29.000000000","message":"@gouthampravi@gmail.com, @fungi@yuggoth.org and @cardoe@cardoe.com, can I have a review here, please?  Thanks!","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"402e184abccd9fdcff93dc5d0a654590d387390d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"d06928b5_1b03f916","updated":"2026-10-05 18:55:21.000000000","message":"I\u0027m okay with this as a proposed goal.. but the proposal is missing the Goal Checklist section that goals/template.rst requires (design finalized, implementation finalized, dependencies or blocker), along with the Description and Status \u0026 Tracking sections (it\u0027s fine to track this on wiki - but, make that obvious) \n\nBased on the writing so far, the honest checklist answers look like NO / partial / YES respectively, and that is perfectly fine to state with links. \n\nBeyond that, please do bring this up at the Indri/Oct 2026 PTG so we can drive consensus towards this being an \"accepted\" goal.","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"}],"goals/proposed/pqc-readiness.rst":[{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"e2da7e86c99d65028dce59b976071133afd29ac5","unresolved":true,"context_lines":[{"line_number":154,"context_line":"approach (offering safer options without breaking existing deployments) is the"},{"line_number":155,"context_line":"right direction."},{"line_number":156,"context_line":""},{"line_number":157,"context_line":"Paramiko is the largest cross-project obstacle, shared with the FIPS goal. It"},{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"}],"source_content_type":"text/x-rst","patch_set":1,"id":"3ec278cb_1d31b8d8","line":157,"range":{"start_line":157,"start_character":48,"end_line":157,"end_character":73},"updated":"2026-08-21 14:47:58.000000000","message":"You should probably avoid tying this to the FIPS goal, since that has since been rolled from accepted back to proposed, and it\u0027s unclear whether it will ever regain traction.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"8f3099cc9c0197340364d187c519646d1990256e","unresolved":false,"context_lines":[{"line_number":154,"context_line":"approach (offering safer options without breaking existing deployments) is the"},{"line_number":155,"context_line":"right direction."},{"line_number":156,"context_line":""},{"line_number":157,"context_line":"Paramiko is the largest cross-project obstacle, shared with the FIPS goal. It"},{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"}],"source_content_type":"text/x-rst","patch_set":1,"id":"71639c8b_b8ff6455","line":157,"range":{"start_line":157,"start_character":48,"end_line":157,"end_character":73},"in_reply_to":"3ec278cb_1d31b8d8","updated":"2026-08-21 15:34:07.000000000","message":"Good point. Removed all references to the FIPS goal. The paramiko problem is real regardless of FIPS status, and tying them together adds unnecessary coupling.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"e2da7e86c99d65028dce59b976071133afd29ac5","unresolved":true,"context_lines":[{"line_number":156,"context_line":""},{"line_number":157,"context_line":"Paramiko is the largest cross-project obstacle, shared with the FIPS goal. It"},{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"},{"line_number":161,"context_line":"exchange support to paramiko, but it requires OpenSSL 3.5+ and the project\u0027s"},{"line_number":162,"context_line":"single-maintainer model creates uncertainty about the merge timeline. The"}],"source_content_type":"text/x-rst","patch_set":1,"id":"1089ed7b_83eb9074","line":159,"range":{"start_line":159,"start_character":37,"end_line":159,"end_character":64},"updated":"2026-08-21 14:47:58.000000000","message":"I would recommend not mentioning Nova\u0027s keypair generation since it\u0027s been deprecated for years and is unlikely to accept any \"fixes\" other than removal anyway.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"8f3099cc9c0197340364d187c519646d1990256e","unresolved":false,"context_lines":[{"line_number":156,"context_line":""},{"line_number":157,"context_line":"Paramiko is the largest cross-project obstacle, shared with the FIPS goal. It"},{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"},{"line_number":161,"context_line":"exchange support to paramiko, but it requires OpenSSL 3.5+ and the project\u0027s"},{"line_number":162,"context_line":"single-maintainer model creates uncertainty about the merge timeline. The"}],"source_content_type":"text/x-rst","patch_set":1,"id":"8116ef90_8b5aeba2","line":159,"range":{"start_line":159,"start_character":37,"end_line":159,"end_character":64},"in_reply_to":"1089ed7b_83eb9074","updated":"2026-08-21 15:34:07.000000000","message":"You are right, removed.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"e2da7e86c99d65028dce59b976071133afd29ac5","unresolved":true,"context_lines":[{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"},{"line_number":161,"context_line":"exchange support to paramiko, but it requires OpenSSL 3.5+ and the project\u0027s"},{"line_number":162,"context_line":"single-maintainer model creates uncertainty about the merge timeline. The"},{"line_number":163,"context_line":"Ironic team is independently exploring a libssh-based alternative for"},{"line_number":164,"context_line":"networking-generic-switch. Neither FIPS compliance nor PQC readiness can be"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c75ffd94_cb156f1a","line":161,"range":{"start_line":161,"start_character":30,"end_line":161,"end_character":58},"updated":"2026-08-21 14:47:58.000000000","message":"I\u0027m unsure why you present the OpenSSL 3.5+ requirement as a problem, since your Problem Statement section implies its TLS improvements are important regardless.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"8f3099cc9c0197340364d187c519646d1990256e","unresolved":false,"context_lines":[{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"},{"line_number":161,"context_line":"exchange support to paramiko, but it requires OpenSSL 3.5+ and the project\u0027s"},{"line_number":162,"context_line":"single-maintainer model creates uncertainty about the merge timeline. The"},{"line_number":163,"context_line":"Ironic team is independently exploring a libssh-based alternative for"},{"line_number":164,"context_line":"networking-generic-switch. Neither FIPS compliance nor PQC readiness can be"}],"source_content_type":"text/x-rst","patch_set":1,"id":"d24b7b12_a9f4c33e","line":161,"range":{"start_line":161,"start_character":30,"end_line":161,"end_character":58},"in_reply_to":"c75ffd94_cb156f1a","updated":"2026-08-21 15:34:07.000000000","message":"Fair point, rephrased. OpenSSL 3.5+ is a prerequisite for PQC anyway, not an additional burden.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"d82e490d282e21d85b2e952ab6ef0f0eac87cd1b","unresolved":true,"context_lines":[{"line_number":7,"context_line":""},{"line_number":8,"context_line":"Several cryptographic algorithms used throughout OpenStack (RSA, ECDSA,"},{"line_number":9,"context_line":"Ed25519, classical Diffie-Hellman) will be broken by a sufficiently"},{"line_number":10,"context_line":"capable quantum computer. This is not a theoretical concern. The NSA\u0027s"},{"line_number":11,"context_line":"CNSA 2.0 timeline mandates that software \"support and prefer\" quantum-safe"},{"line_number":12,"context_line":"algorithms by 2027 and use them exclusively by 2033. Government and"},{"line_number":13,"context_line":"financial sector customers already ask about post-quantum readiness in"},{"line_number":14,"context_line":"their procurement evaluations."},{"line_number":15,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"0e38ff6f_082f2c87","line":12,"range":{"start_line":10,"start_character":61,"end_line":12,"end_character":52},"updated":"2026-09-08 04:19:22.000000000","message":"Would prefer if you dropped any specific government concern here, or dilute it to reflect the goal that would apply regardless of nationalities represented by the OpenStack community.","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"782fb9e741c8cd26947b0f6e13b5d20cabe77094","unresolved":false,"context_lines":[{"line_number":7,"context_line":""},{"line_number":8,"context_line":"Several cryptographic algorithms used throughout OpenStack (RSA, ECDSA,"},{"line_number":9,"context_line":"Ed25519, classical Diffie-Hellman) will be broken by a sufficiently"},{"line_number":10,"context_line":"capable quantum computer. This is not a theoretical concern. The NSA\u0027s"},{"line_number":11,"context_line":"CNSA 2.0 timeline mandates that software \"support and prefer\" quantum-safe"},{"line_number":12,"context_line":"algorithms by 2027 and use them exclusively by 2033. Government and"},{"line_number":13,"context_line":"financial sector customers already ask about post-quantum readiness in"},{"line_number":14,"context_line":"their procurement evaluations."},{"line_number":15,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"1cbad715_e3c1297b","line":12,"range":{"start_line":10,"start_character":61,"end_line":12,"end_character":52},"in_reply_to":"0e38ff6f_082f2c87","updated":"2026-09-14 11:46:58.000000000","message":"Done. Dropped the NSA/CNSA timeline and the government/financial procurement framing. The problem statement now talks about operators and users across the OpenStack community, plus Harvest Now, Decrypt Later on long-lived TLS.","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"d82e490d282e21d85b2e952ab6ef0f0eac87cd1b","unresolved":true,"context_lines":[{"line_number":19,"context_line":"across government, telco, and financial services, the window to act on"},{"line_number":20,"context_line":"TLS key exchange confidentiality is already closing."},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"NIST has published the replacement algorithms (ML-KEM for key exchange,"},{"line_number":23,"context_line":"ML-DSA for digital signatures). Platforms shipping OpenSSL 3.5+ already"},{"line_number":24,"context_line":"negotiate hybrid PQC key exchange on TLS 1.3 connections automatically,"},{"line_number":25,"context_line":"but only if the application code does not block it. A scan of 30 OpenStack"}],"source_content_type":"text/x-rst","patch_set":2,"id":"827a9631_52f50d01","line":22,"range":{"start_line":22,"start_character":0,"end_line":22,"end_character":4},"updated":"2026-09-08 04:19:22.000000000","message":"NIST, a US government affiliated organization, has ..","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"782fb9e741c8cd26947b0f6e13b5d20cabe77094","unresolved":false,"context_lines":[{"line_number":19,"context_line":"across government, telco, and financial services, the window to act on"},{"line_number":20,"context_line":"TLS key exchange confidentiality is already closing."},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"NIST has published the replacement algorithms (ML-KEM for key exchange,"},{"line_number":23,"context_line":"ML-DSA for digital signatures). Platforms shipping OpenSSL 3.5+ already"},{"line_number":24,"context_line":"negotiate hybrid PQC key exchange on TLS 1.3 connections automatically,"},{"line_number":25,"context_line":"but only if the application code does not block it. A scan of 30 OpenStack"}],"source_content_type":"text/x-rst","patch_set":2,"id":"0deddc25_00c5bb8a","line":22,"range":{"start_line":22,"start_character":0,"end_line":22,"end_character":4},"in_reply_to":"827a9631_52f50d01","updated":"2026-09-14 11:46:58.000000000","message":"Done. Rephrased it.","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"d82e490d282e21d85b2e952ab6ef0f0eac87cd1b","unresolved":true,"context_lines":[{"line_number":22,"context_line":"NIST has published the replacement algorithms (ML-KEM for key exchange,"},{"line_number":23,"context_line":"ML-DSA for digital signatures). Platforms shipping OpenSSL 3.5+ already"},{"line_number":24,"context_line":"negotiate hybrid PQC key exchange on TLS 1.3 connections automatically,"},{"line_number":25,"context_line":"but only if the application code does not block it. A scan of 30 OpenStack"},{"line_number":26,"context_line":"project areas found exactly this kind of barrier in many places: code that pins"},{"line_number":27,"context_line":"old TLS versions, uses deprecated SSL APIs, or hardcodes algorithm choices with"},{"line_number":28,"context_line":"no configuration option."},{"line_number":29,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"41c3cda7_ce3da9d4","line":26,"range":{"start_line":25,"start_character":52,"end_line":26,"end_character":63},"updated":"2026-09-08 04:19:22.000000000","message":"there\u0027s a link to the wiki below, but doesn\u0027t hurt to have it here too","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"782fb9e741c8cd26947b0f6e13b5d20cabe77094","unresolved":false,"context_lines":[{"line_number":22,"context_line":"NIST has published the replacement algorithms (ML-KEM for key exchange,"},{"line_number":23,"context_line":"ML-DSA for digital signatures). Platforms shipping OpenSSL 3.5+ already"},{"line_number":24,"context_line":"negotiate hybrid PQC key exchange on TLS 1.3 connections automatically,"},{"line_number":25,"context_line":"but only if the application code does not block it. A scan of 30 OpenStack"},{"line_number":26,"context_line":"project areas found exactly this kind of barrier in many places: code that pins"},{"line_number":27,"context_line":"old TLS versions, uses deprecated SSL APIs, or hardcodes algorithm choices with"},{"line_number":28,"context_line":"no configuration option."},{"line_number":29,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"d8b71383_13082404","line":26,"range":{"start_line":25,"start_character":52,"end_line":26,"end_character":63},"in_reply_to":"41c3cda7_ce3da9d4","updated":"2026-09-14 11:46:58.000000000","message":"Done. The scan sentence now links to https://wiki.openstack.org/wiki/Post_quantum_openstack.","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"d82e490d282e21d85b2e952ab6ef0f0eac87cd1b","unresolved":true,"context_lines":[{"line_number":68,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"To facilitate tracking, commits related to this goal should use the"},{"line_number":71,"context_line":"gerrit topic::"},{"line_number":72,"context_line":""},{"line_number":73,"context_line":"    pqc-migration"},{"line_number":74,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"cd49230a_557baab0","line":71,"range":{"start_line":71,"start_character":7,"end_line":71,"end_character":12},"updated":"2026-09-08 04:19:22.000000000","message":"try hashtags, topics aren\u0027t friendly to group changes across repositories that may have their own conventions","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"782fb9e741c8cd26947b0f6e13b5d20cabe77094","unresolved":false,"context_lines":[{"line_number":68,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"To facilitate tracking, commits related to this goal should use the"},{"line_number":71,"context_line":"gerrit topic::"},{"line_number":72,"context_line":""},{"line_number":73,"context_line":"    pqc-migration"},{"line_number":74,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"39fcf61a_96471c42","line":71,"range":{"start_line":71,"start_character":7,"end_line":71,"end_character":12},"in_reply_to":"cd49230a_557baab0","updated":"2026-09-14 11:46:58.000000000","message":"Done. Replaced the Gerrit Topic section with Gerrit Tracking and the `pqc-migration` hashtag, matching the goal template. Topics stay project-local.","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"d82e490d282e21d85b2e952ab6ef0f0eac87cd1b","unresolved":true,"context_lines":[{"line_number":156,"context_line":"Paramiko is the largest cross-project obstacle. It is used in Cinder"},{"line_number":157,"context_line":"(SAN storage drivers and SSHPool), Manila (storage driver SSH), Tempest"},{"line_number":158,"context_line":"(instance validation), and indirectly in Ironic (netmiko). A recent"},{"line_number":159,"context_line":"experimental PR (#2668) adds ML-KEM hybrid key exchange support to"},{"line_number":160,"context_line":"paramiko, building on OpenSSL 3.5+, but the project\u0027s single-maintainer"},{"line_number":161,"context_line":"model creates uncertainty about the merge timeline. The Ironic team is"},{"line_number":162,"context_line":"independently exploring a libssh-based alternative for"}],"source_content_type":"text/x-rst","patch_set":2,"id":"cb2c5f31_32cd47f1","line":159,"range":{"start_line":159,"start_character":17,"end_line":159,"end_character":22},"updated":"2026-09-08 04:19:22.000000000","message":"link?","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"782fb9e741c8cd26947b0f6e13b5d20cabe77094","unresolved":false,"context_lines":[{"line_number":156,"context_line":"Paramiko is the largest cross-project obstacle. It is used in Cinder"},{"line_number":157,"context_line":"(SAN storage drivers and SSHPool), Manila (storage driver SSH), Tempest"},{"line_number":158,"context_line":"(instance validation), and indirectly in Ironic (netmiko). A recent"},{"line_number":159,"context_line":"experimental PR (#2668) adds ML-KEM hybrid key exchange support to"},{"line_number":160,"context_line":"paramiko, building on OpenSSL 3.5+, but the project\u0027s single-maintainer"},{"line_number":161,"context_line":"model creates uncertainty about the merge timeline. The Ironic team is"},{"line_number":162,"context_line":"independently exploring a libssh-based alternative for"}],"source_content_type":"text/x-rst","patch_set":2,"id":"43be3e3b_95b644aa","line":159,"range":{"start_line":159,"start_character":17,"end_line":159,"end_character":22},"in_reply_to":"cb2c5f31_32cd47f1","updated":"2026-09-14 11:46:58.000000000","message":"Done. Linked https://github.com/paramiko/paramiko/pull/2668 and updated the text: that PR merged on 2026-08-29. The remaining gap is a paramiko release that includes it, and not pinning an older version.","commit_id":"7d640fb4b0b9cf823f4640980d6f04385619f8ff"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"402e184abccd9fdcff93dc5d0a654590d387390d","unresolved":true,"context_lines":[{"line_number":2,"context_line":"Post-Quantum Cryptography Readiness"},{"line_number":3,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":4,"context_line":""},{"line_number":5,"context_line":"Problem Statement"},{"line_number":6,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"Several cryptographic algorithms used throughout OpenStack (RSA, ECDSA,"}],"source_content_type":"text/x-rst","patch_set":3,"id":"df10fc53_4ff6330b","line":5,"range":{"start_line":5,"start_character":0,"end_line":5,"end_character":17},"updated":"2026-10-05 18:55:21.000000000","message":"please follow the template: https://opendev.org/openstack/governance/src/branch/master/goals/template.rst\n\nSome of the structure can be tweaked, but, it\u0027ll make your life easier to answer reviewers\u0027 obvious questions on the timeline and the specifics","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"402e184abccd9fdcff93dc5d0a654590d387390d","unresolved":true,"context_lines":[{"line_number":44,"context_line":""},{"line_number":45,"context_line":"* SSH-based workflows (Cinder and Manila storage drivers, Tempest) remain"},{"line_number":46,"context_line":"  tied to paramiko. Hybrid ML-KEM key exchange has landed upstream"},{"line_number":47,"context_line":"  (`Paramiko PR 2668`_), but OpenStack still depends on a release that"},{"line_number":48,"context_line":"  includes it and on not pinning an older version. Without a reliable"},{"line_number":49,"context_line":"  alternative, these workflows can stay on quantum-vulnerable key"},{"line_number":50,"context_line":"  exchange indefinitely."}],"source_content_type":"text/x-rst","patch_set":3,"id":"81dce65f_1811f18f","line":47,"range":{"start_line":47,"start_character":45,"end_line":47,"end_character":52},"updated":"2026-10-05 18:55:21.000000000","message":"needs?\n\nI didn\u0027t understand this","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"402e184abccd9fdcff93dc5d0a654590d387390d","unresolved":true,"context_lines":[{"line_number":44,"context_line":""},{"line_number":45,"context_line":"* SSH-based workflows (Cinder and Manila storage drivers, Tempest) remain"},{"line_number":46,"context_line":"  tied to paramiko. Hybrid ML-KEM key exchange has landed upstream"},{"line_number":47,"context_line":"  (`Paramiko PR 2668`_), but OpenStack still depends on a release that"},{"line_number":48,"context_line":"  includes it and on not pinning an older version. Without a reliable"},{"line_number":49,"context_line":"  alternative, these workflows can stay on quantum-vulnerable key"},{"line_number":50,"context_line":"  exchange indefinitely."},{"line_number":51,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"d72a90b3_eefae147","line":48,"range":{"start_line":47,"start_character":25,"end_line":48,"end_character":50},"updated":"2026-10-05 18:55:21.000000000","message":"This is good for a proposed goal, but, when paramiko ships this in a release, won\u0027t this risk diminish?\n\nMaybe we need to call out something else regarding this risk? We _need_ a released version so that we can begin testing it with Indri, is this the main risk?","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"402e184abccd9fdcff93dc5d0a654590d387390d","unresolved":true,"context_lines":[{"line_number":53,"context_line":"  post-quantum transitions."},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"The cost of inaction is not a hypothetical future breach. It is"},{"line_number":56,"context_line":"measurable today in lost procurement opportunities and growing technical"},{"line_number":57,"context_line":"debt."},{"line_number":58,"context_line":""},{"line_number":59,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"1f27a960_ed7f18f3","line":56,"range":{"start_line":56,"start_character":20,"end_line":56,"end_character":50},"updated":"2026-10-05 18:55:21.000000000","message":"this is doing a lot of marketing for an open source project; it\u0027s not attractive as a primary motivator to be honest. It feels like a fine goal for a commercial product.\n\ni could get behind avoiding technical debt and meeting operator requirements","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"402e184abccd9fdcff93dc5d0a654590d387390d","unresolved":true,"context_lines":[{"line_number":74,"context_line":"Gerrit hashtag::"},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"    pqc-migration"},{"line_number":77,"context_line":""},{"line_number":78,"context_line":"Hashtags are preferred over topics because they are additive and"},{"line_number":79,"context_line":"support multiple tags per change. Topics are left to each project\u0027s"},{"line_number":80,"context_line":"own convention."},{"line_number":81,"context_line":""},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"Completion Criteria"},{"line_number":84,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":3,"id":"c670a787_a26d21ed","line":81,"range":{"start_line":77,"start_character":0,"end_line":81,"end_character":0},"updated":"2026-10-05 18:55:21.000000000","message":"nit: this explanation is not needed here","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"402e184abccd9fdcff93dc5d0a654590d387390d","unresolved":true,"context_lines":[{"line_number":96,"context_line":"it."},{"line_number":97,"context_line":""},{"line_number":98,"context_line":"* Replace ``ssl.wrap_socket()`` with ``ssl.SSLContext`` in all projects"},{"line_number":99,"context_line":"  that make direct TLS connections (oslo.messaging, Nova VNC, others)."},{"line_number":100,"context_line":"* Drop deprecated SSL protocol constants (``ssl.PROTOCOL_TLSv1`` and"},{"line_number":101,"context_line":"  friends) in favor of ``minimum_version`` / ``maximum_version``."},{"line_number":102,"context_line":"* Clean up dead cryptographic code: the CMS module in"}],"source_content_type":"text/x-rst","patch_set":3,"id":"2035f1a9_930ccd0b","line":99,"range":{"start_line":99,"start_character":35,"end_line":99,"end_character":68},"updated":"2026-10-05 18:55:21.000000000","message":"maybe link this to a wiki page where you\u0027ve identified the full list?","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"402e184abccd9fdcff93dc5d0a654590d387390d","unresolved":true,"context_lines":[{"line_number":102,"context_line":"* Clean up dead cryptographic code: the CMS module in"},{"line_number":103,"context_line":"  python-keystoneclient, HMAC-SHA1 in osprofiler, and any other"},{"line_number":104,"context_line":"  obsolete crypto identified during the inventory."},{"line_number":105,"context_line":"* Raise Keystone\u0027s PBKDF2-SHA512 iterations to 600,000 with transparent"},{"line_number":106,"context_line":"  rehashing on login."},{"line_number":107,"context_line":"* Publish a concrete plan to provide a quantum-safe SSH alternative to"},{"line_number":108,"context_line":"  paramiko, using a library built on platform cryptography"},{"line_number":109,"context_line":"  (python-libssh or asyncssh). The plan must cover which projects are"}],"source_content_type":"text/x-rst","patch_set":3,"id":"25479a78_8be8d846","line":106,"range":{"start_line":105,"start_character":2,"end_line":106,"end_character":21},"updated":"2026-10-05 18:55:21.000000000","message":"Is this directly concerning PQC?","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"402e184abccd9fdcff93dc5d0a654590d387390d","unresolved":true,"context_lines":[{"line_number":153,"context_line":"Work on Milestone 1 is already under way. TLS modernization in oslo.messaging,"},{"line_number":154,"context_line":"PBKDF2 hardening and transparent rehashing in Keystone, crypto-agility"},{"line_number":155,"context_line":"groundwork in Barbican, HMAC-SHA256 upgrade in osprofiler, and CMS module"},{"line_number":156,"context_line":"deprecation in python-keystoneclient all have patches under upstream review,"},{"line_number":157,"context_line":"several with positive reviewer feedback. The pop-up team presented its progress"},{"line_number":158,"context_line":"to the TC on 2026-08-11 and received positive feedback; the TC emphasized the"},{"line_number":159,"context_line":"importance of testing and documentation, and confirmed that the crypto-agility"}],"source_content_type":"text/x-rst","patch_set":3,"id":"6ded379c_316a0c9c","line":156,"range":{"start_line":156,"start_character":37,"end_line":156,"end_character":75},"updated":"2026-10-05 18:55:21.000000000","message":"links? hashtag? this can drift after the goal is published.","commit_id":"634bf207bab43a4f8f342325570cfd24085126f7"}]}
