[auth48] Re: Final Review: RFC-to-be 10042 (draft-ietf-sshm-mlkem-hybrid-kex) in XML
Douglas Stebila <dstebila@uwaterloo.ca> Fri, 28 August 2026 16:55 UTC
Return-Path: <prvs=6938b231c=dstebila@uwaterloo.ca>
X-Original-To: auth48archive@mail2.ietf.org
Delivered-To: auth48archive@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 259171311688E; Fri, 28 Aug 2026 09:55:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787936119; bh=gumdDb5IkfvnLrHWAMQLES7+yDE7uRhY/YUQEzpKWMU=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=bNagmTq2PGt/S2yH27Jp0CV14zwiPZcTliWJNxaNNAQ35OJHOzXf9zAO5PDxGQlHY DY9RADceghzoAowfa2XhmgEESXc2jPUhW3gUk2gcstWTVk/Fx6Ir9SnX8LffzLiJv8 LemVq28s+5FfdlkvWJJh0A3vSX9+M1piO5MkyFjc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=uwaterloo.ca
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QjoQhzPmhleS; Fri, 28 Aug 2026 09:55:17 -0700 (PDT)
Received: from esa.hc503-62.ca.iphmx.com (esa.hc503-62.ca.iphmx.com [216.71.131.47]) by mail2.ietf.org (Postfix) with ESMTP id 380A31311687F; Fri, 28 Aug 2026 09:55:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=uwaterloo.ca; i=@uwaterloo.ca; q=dns/txt; s=ces1; t=1787936117; x=1819472117; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=gumdDb5IkfvnLrHWAMQLES7+yDE7uRhY/YUQEzpKWMU=; b=q+f6o47xwUmpXHoCi2sz6BcY05Z67DEYN0jcyMERRBoDIHK5nbEpF6e7 CaONmlLPcGbEqE3q5rtPti+u78qBeJDukiHjt2eGeZDQrz2SpMZpejjay VOzSAfhDaeWpyBNBidAa8I7JzyjQqv/L/uOKH2WILCVqw99zcvLmMRXR4 o=;
X-CSE-ConnectionGUID: 5Cw3rmlhRKmiRrVl/OR4rA==
X-CSE-MsgGUID: FkjNhAGgSgWAAmn3N5SpcA==
X-Talos-CUID: 9a23:r3ZHVGw/zlwoHUn5n6KWBgVJMd9+aHjZzE3zJk6CE1htD5qvFUW5rfY=
X-Talos-MUID: 9a23:ILSIOQSZPKPUPg3NRXTChzNENO5H7J+hN2kklJNdnZS/LSdZbmI=
Received: from mail-canadacentralazon11021099.outbound.protection.outlook.com (HELO YT5PR01CU002.outbound.protection.outlook.com) ([40.107.192.99]) by ob1.hc503-62.ca.iphmx.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 28 Aug 2026 12:55:08 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=er+lrFAlIt/E4umv+rXvpr1DY/MHnvdyKxSeTh3P0au8uRNEYBZ1YByExgX+ywbrr9UmvQMdL1H1fe0hiEt6reSrtYdEB79aRtQ8CjxhMhHHSbvy6UchtCAcTOdKeIGW8kerPDsowMIhfcFDuAtXvdM504PvQFXs9FsUOEkvvmmSkGEinjvvt5uaRoCQtcfHHwpqunb33UcChll0EhVZ4QqV/R5J0Qz384XY8lDI7UhO27JKM1EhPfOl1IFdN9/iYgZplCUohpl52SIyRHvF9y3ATPwauCvdkYGHHza8V5/m7+orqxzrtvO8yHeptVnAlbkvOZu36oWu/BPXAIDkWg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gumdDb5IkfvnLrHWAMQLES7+yDE7uRhY/YUQEzpKWMU=; b=U7Fma2NmGJGomTcM95J7GxwPV+ArGuS5pwwKcqLU2Fwz9z2bhs6+ZzhbPuFlozdlbK6wur7tWjzEB/7gy1ICgzUG5YGuJhLMYIw/X+h8aYtlUaRqmqar4tfxvWJtrqvYg5ZLIU6m0PXqBGg/o+rklbtCHMfWmDPVTvN3dxEt0eZOzjbMvPmNWMB5uDBhA0Km+GhbEd+VPfFfeh8EZUJ3Nih3xQaJprIFVqJnzowm71Aa7B9x0wSbEyILj9Hx9pDD/vFXI6LszGnycKPVI6OQCdynug1OfJTeX1XGsf7FMe6FDiua9JkltK9w4vf+oZRpwBza15+09hDbpqnwkyL5XQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=uwaterloo.ca; dmarc=pass action=none header.from=uwaterloo.ca; dkim=pass header.d=uwaterloo.ca; arc=none
Received: from YT2PPF7545EB94C.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:b08::452) by QB1PPF80340BAD8.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:c08::256) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.11; Fri, 28 Aug 2026 16:55:04 +0000
Received: from YT2PPF7545EB94C.CANPRD01.PROD.OUTLOOK.COM ([fe80::6459:9f0e:bc2:f897]) by YT2PPF7545EB94C.CANPRD01.PROD.OUTLOOK.COM ([fe80::6459:9f0e:bc2:f897%8]) with mapi id 15.21.0360.008; Fri, 28 Aug 2026 16:55:04 +0000
From: Douglas Stebila <dstebila@uwaterloo.ca>
To: "Hansen, Torben" <htorben@amazon.com>
Thread-Topic: Final Review: RFC-to-be 10042 (draft-ietf-sshm-mlkem-hybrid-kex) in XML
Thread-Index: AQHdNBa9rkC8Ero1y0+9IFv1kP0oD7auGwuAgAQm0ICAAI6NgIAAsSkAgAAx/gA=
Date: Fri, 28 Aug 2026 16:55:04 +0000
Message-ID: <7EF6D995-69C7-4C78-8254-03DAD9B12888@uwaterloo.ca>
References: <178760998555.11.7692986499892033650@rfc-editor.org> <BYAPR18MB2648E3E9CDE45319B1D9860CABAF2@BYAPR18MB2648.namprd18.prod.outlook.com> <af4a87aa-d3d4-4760-b81a-93eefaec28ef@staff.rfc-editor.org> <BYAPR18MB2648C26081EB0237161DFA39ABAC2@BYAPR18MB2648.namprd18.prod.outlook.com> <SJ0PR18MB45114A4FC060DCA594C19217CBAC2@SJ0PR18MB4511.namprd18.prod.outlook.com>
In-Reply-To: <SJ0PR18MB45114A4FC060DCA594C19217CBAC2@SJ0PR18MB4511.namprd18.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3864.700.51.1.1)
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=uwaterloo.ca;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: YT2PPF7545EB94C:EE_|QB1PPF80340BAD8:EE_
x-ms-office365-filtering-correlation-id: 48940a5c-cb49-42e7-7245-08df05251bac
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|786006|23010399003|376014|1800799024|366016|7416014|10067099003|3023799007|18002099003|22082099003|11063799006|5023799004|56012099006|8096899003|4143699003|13003099007|38070700021;
x-microsoft-antispam-message-info: TAXViApUVMJAhjwT0DDNbblwe2u8zTRPqjWHVe9l8mjg7zNTOAtRXxFZ2mIN2p26ITcdugBpuUpB9dIaeZV/8r5FZFdOPNh+w1OofUDiqnieVX0ISCZ2JY48zKJ/o0VAPL4dIPUW5t/iI1QjEYIuS00qudwbdTdMNjIZ0jn9da7S0mYtUWBUygpxvWw+iPmtRbImmg5Lm/rfq40If154bix24XHssT778Zy/YXzNfTFCNG0ubbeL378Kfb8tAcdmSHIXHKGUpAbgQTsFhQ4szuIYrvCNJDlpvpf+5r5EuwO/RArFaUcBSg6Mhsoy26WgQhOijoo0VfzVdvcmAuNEY9y3UxyBjsZnsBGAntzCoqaIvr9KjsUOaoW8xKhrWNkyk/KfWJvxwwhsG1a6q2JJ/z6Sh0XGlHBZePjHtj8JYXgye4bLYG6SA/kxH7IPzN+8upwghW8DmW+mtsmyJ72y3DPbuCAAFJwvLeynNT4lF/CuYa7wZSOOqsfMICHhcOfnQJip3TN7ZwHLEwxggVysJyD4ZetflXh6XnyZ9UR0B6M6gNgcYfKqkWAnq6w7JugaF+ogPbm/o74mge+WWgBhXYNgf5iX7gVQXMkPuSGcIgSJzNG7O+IECV8v2obBTwfXoxnIhWXvlPUCyKjX77cc/8hyaf3HSazSqn4y/Sbkfec=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:YT2PPF7545EB94C.CANPRD01.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(786006)(23010399003)(376014)(1800799024)(366016)(7416014)(10067099003)(3023799007)(18002099003)(22082099003)(11063799006)(5023799004)(56012099006)(8096899003)(4143699003)(13003099007)(38070700021);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: ZGbL/kgZluk5sCT+3wPqAGNOe6dAIceTrLqW3ssgKjRO3LbQRluA1OfJM6pQ0vYDz75tsSjXmoyGg4yDUqCND0QlC19WAPw9nG6C1v/PjBtsg/2a7q2cAf5TQfnejsn5zg1kL76zbrgfEWkiTDHiceApdKTPxaCGE7KwQNgoAvNGIOPqdSzX32nKe4XvyCFK66cBOXsKPWw2OtwkSKzDS1VCjHKAc0bIQXf8Djp1wVpot3TkNNbYL/7LK4oM1CaxSPYxKsjyDuZtCNlfXL9L9MWBoOn9KChmWWzNw3A03N/udRKdKeryzLvOk+sEOI8FDHZD/8lGx3Olgl0w7XrZ+LYC52kYH25xAybLsZg3Ehz/uUmNvOp6OJeNYsA6Ap5ynT5ZHsjMWwIN9sc3AaVc3QvVPGUh5xdNNaNExUTOr6jLciZ/ZiGouu/3uY9bXiAZPk2447rSIXU5phhS/DJNgda6ccBiLAKu4YHgglz6V/kaTpImJpkMMiLOLip5S7PWIlo10j4PZmyn/VMiShKFaCjnyFfa+YlTv6rViixEda2Qlk21gOe7gg+ixIjQhARPp/UEbCBHPFpxaxy6CtZyralA/7cUvbAo/azHIa4postK6/mjtl5guLvXguXdGBpES1c22nPJFGchgjCTfiT551hZQWB4EL4m862Nnvz1btiZz4ixDITSveMwenNs8/r9ucbW+F9TxbPY+yHhF83ItZenmriYSvd7HRiK4QsPrP/NdVqsmILLLn57BfQJNMMh/Tp+v5DLmHt/C7Pu8pVCdnzRERolD1wbxu9U23T/SeyDT4ZbPhObDUFXsioT2/rVbO1w5R3ueFNgWd2RqMK48HNXKJYdCYhXemZsr/6N1C7cJB8C3OrgXNizBUPPEAA5xt+6tF1r7+OmYpyH14KRyL6piwOUNYSlcjzm8J7uKRcUvwgH/he2RXEhPhMwoHHKwN+HT/6Dvr0SilfhnlcnkRFbTkSU/XP4VA91HnYWKbq/TszlMw9RMw0v4E3Wwhb5cf6q1kAoCyJTwMlHC4ZZTI12O1tKDt0CMhLzTMgUx2voY/Tu6gepqoYFsyWeVqbZo+z7roHg05T6IFfGGEItTuJp70S4fmkKYEZJOsS1JCL2emee+VpgVgQurDcSIIKTKu5a1YwwRZ8zHUhn6wirCyhVc0/KbIFkjR4KL3nxJNI71QE7nuF19gc17THy1Aj18kU/w5bydh2DTBhOpt03bkAQ44+KXzI5+6OmeDBgqllBDLI5owX8XfQn1Z8/LQ3PxMQpE5U1bFZ2juc1RIbbKEsBRcawngfKvcnNRIo6BBM5FqwzJ1MLd+MYLRrFjO21PeAt568kbtK3jPv1FFh7lgQiQ/hIBwHouY2N1Z+Sjcg1w7cKeGiJYhpaSAnF/pmxV+uGDLIsMnvq3RMA+HgA24yuIwbwr47yIOtONC8UBIoXP8FBWV+1Rp6WC/TMNt31o4uF1bn+rw3QVS776izqQKzwCKJIp+inQT6JlnX8Sq/Wymx8d7QJpcHMFkUMyT+1BI5eKIpqAPKD4vsUg02r7vJD/nwx8Sgf5ZOW1jnDFT7Efrk7e5GKhWBmGboUZ0dLwr/JDvUy4rc416loUZqxnoOc16or8yybI09UyKlh+HOooGvpgfMt8v7ZPAPA34swsb/NK/nRBLZDzznEYme11JlN4d6rLeIVGir6AZuQ/i3y6IWY7VRDMGcnRQ0gQcKL+5o4VwzHY4YwO1LPTuWuNDU7iIq56HhixBA5Zf2m67U=
Content-Type: multipart/alternative; boundary="_000_7EF6D99569C74C78825403DAD9B12888uwaterlooca_"
MIME-Version: 1.0
X-Exchange-RoutingPolicyChecked: QDcvxd4/FnCR9aXu/668sBjq3cNsqk+EytzuXwB2uem+pjKpnDs+8qj3Y0X9RYMPO537pkBg00d5am3kThU6NM6MVGkBpYDCJoUGTUQhc+mi7/M3+fD/OKZToSW3bcugBUeCX+hj6nzhKDtKT2cfmMhcqINB1xxebqkF2lJUzpc1KSAQWOsTgsvVxe2cg6HW2tmKiWQeGEZatdJGgiKSlQumubtroufoVnk23mQ30O2jVvzRz7h/84HWV50pBSh+SNfQF4SBXocAi2MZ1FiktPDFuYFoKi+rSDjocI1iaDUZH54mFQcXsWDK6Go0xZk8W/JywA7lmnShFDBEl71ydw==
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-0: Amrv7it6gG7/DUdU8DQnoUs8CGdEASltb+iVO9xm8IsrWfmM/jp7fpDsh/nn/hX7rpAB6d6qKFKHaHHGeh0+hb2cy4q5nEgnkNF/j2beXsV2pAokgWnysNjvlX0FoYD+RpPJum7RvIIHh7RX4CsmwGDmUNxNY6b7B5aawDXyDEYy2j3L6zgRuPPgyc4V7MwfhEN6rwuOgWkVo1dL3I32/WzHGZ4kpSmkjPTwhyWjoFmlJsTHL4wcHSFDqnH3GXX7va41kBQ5T/kcHtsJgbnanhHvk8jDIpgxf92e1hkecoGm3WucQ1DJG4e2Uoz86v65eXrR9alNYdlZRMHnnHtptt9UktlQ0uzFcODaNO96l74wwEfeKhfW3N8oenWWm8AJnFg2O3ap+c98TWX17EJ7EdHJl82KH99A5KkR3gRVXwqRaxjwMbbzVDPiIf+aMkx6/3xMH7jdsHruF+1pvXaH3YinRNew7uvfjWRoaMnqXqQ7EWxoAvTXNi7On2GQXiAgZGedLUgefvp6irTO04E4dTZ3SfXIS57H3ufbsdDlZy6xVpYqht/0sqJ1VUl6ES274IvdpNjWnmHcQLQTgt1B5TCP33DKBCVa4om5/3EY6T5IUBqVLob97WoJDnCRRAB5
X-OriginatorOrg: uwaterloo.ca
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: YT2PPF7545EB94C.CANPRD01.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 48940a5c-cb49-42e7-7245-08df05251bac
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Aug 2026 16:55:04.5991 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 723a5a87-f39a-4a22-9247-3fc240c01396
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: sGVL8xvavjp6SKCPAX8P46rY3I8JvdPt5nFZ+E9IPPyt8buKFkIcTHpCOmKFoZukQzQQL4iFtVjOV1LXfin0eQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: QB1PPF80340BAD8
Message-ID-Hash: KLCSNZUPTZAYMD5UX6CUA6LBRZFMDKU2
X-Message-ID-Hash: KLCSNZUPTZAYMD5UX6CUA6LBRZFMDKU2
X-MailFrom: prvs=6938b231c=dstebila@uwaterloo.ca
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "Kampanakis, Panos" <kpanos@amazon.com>, Kaelin Foody <kfoody@staff.rfc-editor.org>, "rfc-editor@rfc-editor.org" <rfc-editor@rfc-editor.org>, "auth48archive@rfc-editor.org" <auth48archive@rfc-editor.org>, "sec-ads@ietf.org" <sec-ads@ietf.org>, "stndrds-inacio@andrew.cmu.edu" <stndrds-inacio@andrew.cmu.edu>, "stephen.farrell@cs.tcd.ie" <stephen.farrell@cs.tcd.ie>, "debcooley1@gmail.com" <debcooley1@gmail.com>, "sshm-chairs@ietf.org" <sshm-chairs@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [auth48] Re: Final Review: RFC-to-be 10042 (draft-ietf-sshm-mlkem-hybrid-kex) in XML
List-Id: "Archiving AUTH48 exchanges between the RFC Production Center, the authors, and other related parties" <auth48archive.rfc-editor.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/auth48archive/WvzsWD9bCI7JOGcR8VKz_FGaXPI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/auth48archive>
List-Help: <mailto:auth48archive-request@rfc-editor.org?subject=help>
List-Owner: <mailto:auth48archive-owner@rfc-editor.org>
List-Post: <mailto:auth48archive@rfc-editor.org>
List-Subscribe: <mailto:auth48archive-join@rfc-editor.org>
List-Unsubscribe: <mailto:auth48archive-leave@rfc-editor.org>
I approve. Thanks all! Douglas On Aug 28, 2026, at 9:55 AM, Hansen, Torben <htorben@amazon.com> wrote: Approved Thanks! /Torben From: Kampanakis, Panos <kpanos@amazon.com> Date: Thursday, August 27, 2026 at 8:21 PM To: Kaelin Foody <kfoody@staff.rfc-editor.org>; rfc-editor@rfc-editor.org <rfc-editor@rfc-editor.org>; dstebila@uwaterloo.ca <dstebila@uwaterloo.ca>; Hansen, Torben <htorben@amazon.com> Cc: auth48archive@rfc-editor.org <auth48archive@rfc-editor.org>; sec-ads@ietf.org <sec-ads@ietf.org>; stndrds-inacio@andrew.cmu.edu <stndrds-inacio@andrew.cmu.edu>; stephen.farrell@cs.tcd.ie <stephen.farrell@cs.tcd.ie>; debcooley1@gmail.com <debcooley1@gmail.com>; sshm-chairs@ietf.org <sshm-chairs@ietf.org> Subject: RE: [EXTERNAL] Final Review: RFC-to-be 10042 (draft-ietf-sshm-mlkem-hybrid-kex) in XML Hi Kaelin, All the changes look fine. Approved from my side. Torben, Douglas? -----Original Message----- From: Kaelin Foody <kfoody@staff.rfc-editor.org> Sent: Thursday, August 27, 2026 2:51 PM To: Kampanakis, Panos <kpanos@amazon.com>; rfc-editor@rfc-editor.org; dstebila@uwaterloo.ca; Hansen, Torben <htorben@amazon.com> Cc: auth48archive@rfc-editor.org; sec-ads@ietf.org; stndrds-inacio@andrew.cmu.edu; stephen.farrell@cs.tcd.ie; debcooley1@gmail.com; sshm-chairs@ietf.org Subject: RE: [EXTERNAL] Final Review: RFC-to-be 10042 (draft-ietf-sshm-mlkem-hybrid-kex) in XML CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. Hi authors, Thank you for your reply. We have updated the files accordingly and posted them at the end of this email. Upon careful review, please contact us with any further updates or with your approval of the document in its current form. We will await approvals from each party listed on the Final Review status page for this document prior to moving forward in the publication process. The Final Review status of your document is available here: https://queue.rfc-editor.org/final-review/rfc10042 -- FILES (please refresh): -- The updated files have been posted here: https://www.rfc-editor.org/authors/rfc10042.txt https://www.rfc-editor.org/authors/rfc10042.pdf https://www.rfc-editor.org/authors/rfc10042.html https://www.rfc-editor.org/authors/rfc10042.xml Diff files showing changes made during Final Review: https://www.rfc-editor.org/authors/rfc10042-auth48diff.html https://www.rfc-editor.org/authors/rfc10042-auth48rfcdiff.html (side by side) Diff files showing all changes: https://www.rfc-editor.org/authors/rfc10042-diff.html https://www.rfc-editor.org/authors/rfc10042-rfcdiff.html (side by side) Thank you, Kaelin Foody RFC Production Center On 8/24/26 11:27 PM, Kampanakis, Panos wrote: > Dear RFC Production Center, > > Answers in line with PK> > > Thank you > > > -----Original Message----- > From: rfc-editor@rfc-editor.org <rfc-editor@rfc-editor.org> > Sent: Monday, August 24, 2026 6:20 PM > To: Kampanakis, Panos <kpanos@amazon.com>; dstebila@uwaterloo.ca; > Hansen, Torben <htorben@amazon.com> > Cc: auth48archive@rfc-editor.org; rfc-editor@rfc-editor.org; > sec-ads@ietf.org; stndrds-inacio@andrew.cmu.edu; > stephen.farrell@cs.tcd.ie; debcooley1@gmail.com; sshm-chairs@ietf.org > Subject: RE: [EXTERNAL] Final Review: RFC-to-be 10042 > (draft-ietf-sshm-mlkem-hybrid-kex) in XML > > CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. > > > > Authors, > > While reviewing this document during Final Review, please resolve (as necessary) the following questions, which are also in the source file. > > 1) <!-- [rfced] Per Section 3.6 of RFC 7322 ("RFC Style Guide"), abbreviations should be expanded in titles of RFCs when possible. Can any abbreviations be expanded in the title below? > > Original: > PQ/T Hybrid Key Exchange with ML-KEM in SSH > > Perhaps: > Post-Quantum/Traditional (PQ/T) Hybrid Key Exchange with > the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) for > Use in SSH > --> > > PK> Yes, but I suggest removing the text in parenthesis to keep it shorter. The abbreviations are defined in the text as well. > > 2) <!-- [rfced] We note that the reference [I-D.ietf-pquip-pqc-engineers] (now published as RFC 9958) uses "harvest now, decrypt later" rather than "harvest-now-decrypt-later". May we update for consistency? > > Original: > This kind of attack is known as a 'harvest-now-decrypt-later' attack > [I-D.ietf-pquip-pqc-engineers]. > > Perhaps: > This kind of attack is known as a 'harvest now, decrypt later' attack > [RFC9958]. > --> > > PK> Yes > > 3) <!-- [rfced] We have updated this list to be a bulleted list. It was originally included as artwork. Please review and let us know if any updates are needed. > > <artwork align="left" name="" type="" alt=""><![CDATA[ > mlkem768nistp256-sha256 > mlkem1024nistp384-sha384 > mlkem768x25519-sha256 > ]]></artwork> > --> > > PK> That is fine. > > 4) <!-- [rfced] May we add "that is" to the text below (to appear before "always big-endian")? > > Original: > Specifically for K_CL, the conversion from mpint to a byte array is done by > taking the mpint that the corresponding standalone key exchange method > would have output and re-encoding it as a fixed-size (32 bytes for > Curve25519 and secp256r1 or 48 bytes for secp384r1) byte array always big- > endian. > > Perhaps: > Specifically for K_CL, the conversion from mpint to a byte array is done by > taking the mpint that the corresponding standalone key exchange method > would have output and re-encoding it as a fixed-size (32 bytes for > Curve25519 and secp256r1 or 48 bytes for secp384r1) byte array that is > always big-endian. > --> > > PK> That looks fine. > > 5) <!-- [rfced] We updated the IANA Considerations to include a table showing the values being registered. Please review and let us know if you prefer otherwise. > > Original: > 5. IANA Considerations > > This memo requests IANA to register new method names > "mlkem768nistp256-sha256", "mlkem1024nistp384-sha384", and > "mlkem768x25519-sha256" in the "Key Exchange Method Names" registry > for SSH [IANA-SSH] with a "Reference" field to this RFC and the "OK > to implement" field of "SHOULD". > > Current (horizontal lines removed so this text could be included in comments): > IANA has registered the following method names in the "Key Exchange > Method Names" registry within the "Secure Shell (SSH) Protocol > Parameters" registry group. > > +==========================+===========+=================+ > | Method Name | Reference | OK to Implement | > +==========================+===========+=================+ > | mlkem768nistp256-sha256 | RFC 10042 | SHOULD | > > | mlkem1024nistp384-sha384 | RFC 10042 | SHOULD | > > | mlkem768x25519-sha256 | RFC 10042 | SHOULD | > > Table 1: New Key Exchange Method Names > --> > > PK> That is fine. > > 6) <!-- [rfced] May we add "to be" to appear before "IND-CPA and IND-CCA2 secure" in the text below? > > Original: > [PQ-PROOF2] discusses how the key combination to > derive K and the derivation of SSH symmetric keys in this document > can be proven IND-CPA and IND-CCA2 secure with some assumptions. > > Perhaps: > [PQ-PROOF2] discusses how the key combination > to derive K and the derivation of SSH symmetric keys in this document > can be proven to be IND-CPA and IND-CCA2 secure with some assumptions. > --> > > PK> That is fine. > > 7) <!-- [rfced] References: > > a) We note that [I-D.hoffman-c2pq] and [RFC4086] are included in the References section, but are not cited in the text of this document. Should these two references be removed? > > PK> Yes, please remove them. > > b) FYI - We updated the date for the reference [NIST_PQ] to match what the date provided at the URL. > Please review and let us know any objections. > > PK> Should it be 2026? > PK> https://csrc.nist.gov/projects/post-quantum-cryptography > > c) FYI - The original URL for the reference [NIST-SP800-186] pointed to a withdrawn draft. We have updated it to the correct final publication URL. > --> > > PK> That is great. > > > 8) <!-- [rfced] Some author comments are present in the XML. Please confirm that no updates related to these comments are outstanding. Note that the comments will be deleted prior to publication. > --> > > PK> Yes, all EDNOTEs are old and addressed. > > 9) <!-- [rfced] Please review each instance of the artwork and sourcecode element in this document. In some cases, we updated artwork to sourcecode to match handling in other documents. However, in cases where we were unsure, we left the item marked as artwork (e.g., Section 2.5). > > Please consider whether any artwork or sourcecode element should be (re)tagged. In addition, if sourcecode is correct, please let us know if a type should be set (see the list of types defined to date at https://www.rfc-editor.org/rpc/wiki/doku.php?id=sourcecode-types) Note that it is acceptable for the type to be empty (i.e., type=""). > --> > > PK> They look fine, but > > string V_C, client identification string (CR and LF excluded) [...] > > Should also be sourcecode, not artwork to match the rest. > > > 10) <!-- [rfced] Please review the "Inclusive Language" portion of the > online Style Guide > <https://www.rfc-editor.org/styleguide/part2/#inclusive_language> > and let us know if any changes are needed. Updates of this nature typically result in more precise language, which is helpful for readers. > > Relatedly, please consider whether instances of "tradition" > ("traditionally", "traditional", etc.) should be updated for clarity. > While the NIST website > <https://web.archive.org/web/20250214092458/https://www.nist.gov/nist- > research-library/nist-technical-series-publications-author-instruction > s#table1> indicated that this term is potentially biased, it is also > ambiguous. > "Tradition" is a subjective term, as it is not the same for everyone. > --> > > PK> Nothing else is necessary. > > > Thank you. > > RFC Production Center > > > > On Aug 24, 2026, at 3:10 PM, rfc-editor@rfc-editor.org wrote: > > *****IMPORTANT***** > > RFC Author(s): > -------------- > > Final Review for RFC-to-be 10042 <draft-ietf-sshm-mlkem-hybrid-kex> > > Your document is now available for Final Review (previously AUTH48). Once it has been reviewed and approved by you and all coauthors, it will be published as an RFC. > If an author is no longer available, there are several remedies; see the Unavailable Authors section (https://authors.ietf.org/rfc-publication-process#unavailable-authors) > > You and you coauthors are responsible for engaging other parties (e.g., Contributors or Working Group) as necessary before providing your approval. > > Planning your review > --------------------- > > Please review the following aspects of your document: > > * RFC Editor questions > > Please review and resolve any questions raised by the RFC Editor > that have been included in the XML file as comments marked as > follows: > > <!-- [rfced] ... --> > > These questions will also be sent in a subsequent email. > > * Changes submitted by coauthors > > Please ensure that you review any changes submitted by your > coauthors. We assume that if you do not speak up that you > agree to changes submitted by your coauthors. > > * Content > > Please review the full content of the document, as this cannot > change once the RFC is published. Please pay particular attention to: > - IANA considerations updates (if applicable) > - contact information > - references > > * Copyright notices and legends > > Please review the copyright notice and legends as defined in > RFC 5378 and the Trust Legal Provisions > (TLP – https://trustee.ietf.org/license-info) > > * Semantic markup > > Please review the markup in the XML file to ensure that elements of > content are correctly tagged. For example, ensure that <sourcecode> > and <artwork> are set correctly. See details at > <https://authors.ietf.org/rfcxml-vocabulary>. > > * Formatted output > > Please review the PDF, HTML, and TXT files to ensure that the > formatted output, as generated from the markup in the XML file, is > reasonable. Please note that the TXT will have formatting > limitations compared to the PDF and HTML. > > > Submitting changes > ------------------ > > To submit changes, please reply to this email using 'REPLY ALL' as all > the parties CCed on this message need to see your changes. The parties > include: > > * your coauthors > > * rfc-editor@rfc-editor.org (the RPC team) > > * other document participants, depending on the stream (e.g., > IETF Stream participants are your working group chairs, the > responsible ADs, and the document shepherd). > > * auth48archive@rfc-editor.org, which is an archival mailing list > to preserve discussion about the document while in the RPC editorial > queue; it is not an active discussion list: > > * More info: > > https://mailarchive.ietf.org/arch/msg/ietf-announce/yb6lpIGh-4Q9l2USxI > Ae6P8O4Zc > > * The archive itself: > https://mailarchive.ietf.org/arch/browse/auth48archive/ > > * Note: If only absolutely necessary, you may temporarily opt out > of the archiving of messages (e.g., to discuss a sensitive matter). > If needed, please add a note at the top of the message that you > have dropped the address. When the discussion is concluded, > auth48archive@rfc-editor.org will be re-added to the CC list and > its addition will be noted at the top of the message. > > You may submit your changes in one of two ways: > > An update to the provided XML file > — OR — > An explicit list of changes in this format > > Section # (or indicate Global) > > OLD: > old text > > NEW: > new text > > You do not need to reply with both an updated XML file and an explicit list of changes, as either form is sufficient. > > We will ask a stream manager to review and approve any changes that seem beyond editorial in nature, e.g., addition of new text, deletion of text, and technical changes. Information about stream managers can be found in the FAQ. Editorial changes do not require approval from a stream manager. > > > Approving for publication > -------------------------- > > To approve your RFC for publication, please reply to this email stating that you approve this RFC for publication. Please use 'REPLY ALL', as all the parties CCed on this message need to see your approval. > > > Files > ----- > > The files are available here: > https://www.rfc-editor.org/authors/rfc10042.xml > https://www.rfc-editor.org/authors/rfc10042.html > https://www.rfc-editor.org/authors/rfc10042.pdf > https://www.rfc-editor.org/authors/rfc10042.txt > > Diff file of the text: > https://www.rfc-editor.org/authors/rfc10042-diff.html > https://www.rfc-editor.org/authors/rfc10042-rfcdiff.html (side by > side) > > Diff of the XML: > https://www.rfc-editor.org/authors/rfc10042-xmldiff1.html > > > Tracking progress > ----------------- > > Details on the status of your Final Review are here: > https://queue.rfc-editor.org/final-review/rfc10042/ > > Please let us know if you have any questions. > > Thank you for your cooperation, > > RFC Editor > > -------------------------------------- > RFC 10042 (draft-ietf-sshm-mlkem-hybrid-kex) > > Title : PQ/T Hybrid Key Exchange with ML-KEM in SSH > Author(s) : P. Kampanakis, > D. Stebila, > T. Hansen > WG Chair(s) : Stephen Farrell, Job Snijders > Area Director(s) : Deb Cooley, Christopher Inacio
- [auth48] Final Review: RFC-to-be 10042 (draft-iet… rfc-editor
- [auth48] Re: Final Review: RFC-to-be 10042 (draft… rfc-editor
- [auth48] Re: Final Review: RFC-to-be 10042 (draft… Kampanakis, Panos
- [auth48] Re: Final Review: RFC-to-be 10042 (draft… Kaelin Foody
- [auth48] Re: Final Review: RFC-to-be 10042 (draft… Kampanakis, Panos
- [auth48] Re: Final Review: RFC-to-be 10042 (draft… Hansen, Torben
- [auth48] Re: Final Review: RFC-to-be 10042 (draft… Douglas Stebila
- [auth48] Re: Final Review: RFC-to-be 10042 (draft… Kaelin Foody