Document Action: 'Use of ML-DSA in TLS 1.3' to Informational RFC (draft-ietf-tls-mldsa-05.txt)

The IESG <iesg-secretary@ietf.org> Wed, 08 July 2026 18:54 UTC

Return-Path: <iesg-secretary@ietf.org>
X-Original-To: ietf-announce@ietf.org
Delivered-To: ietf-announce@mail2.ietf.org
Received: from [10.244.21.96] (gaia.k8s.ietf.org [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 2079E1133CF2A; Wed, 8 Jul 2026 11:54:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783536868; bh=WinrcTysxozBxogZQCz6GAKz5gi53GQ056eZpY9YfqQ=; h=From:To:Subject:Cc:Date; b=rNnuhlrrB0ngbYn1M3tKM9bUfxYRU0RzwtGlRg/Geh8P63QA6FmBLbt+/aSaK9G3h pR6RaffSI47NdnQDq8iFs8iMGHXX2UabslxSdYO7gkrB0/TNBFImwKCghar64f0eaz V+18YAV4rqHbZi6u2wO5QW26r3KOCT6gHdvxWdYE=
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
Subject: Document Action: 'Use of ML-DSA in TLS 1.3' to Informational RFC (draft-ietf-tls-mldsa-05.txt)
X-Test-IDTracker: no
X-IETF-IDTracker: 12.68.0
Auto-Submitted: auto-generated
Precedence: bulk
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <178353686804.520243.15764925856379514554@dt-datatracker-57b5d8f849-v5cht>
Date: Wed, 08 Jul 2026 11:54:28 -0700
Message-ID-Hash: ATQZCGSRDSRNAKO4VPRQSP67NOMOHFEO
X-Message-ID-Hash: ATQZCGSRDSRNAKO4VPRQSP67NOMOHFEO
X-MailFrom: iesg-secretary@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ietf-announce.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: The IESG <iesg@ietf.org>, draft-ietf-tls-mldsa@ietf.org, rfc-editor@rfc-editor.org, tls-chairs@ietf.org, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
List-Id: "IETF announcement list. No discussions." <ietf-announce.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-announce/bgutjvlVskoO871L7gPkaBOCHL0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-announce>
List-Help: <mailto:ietf-announce-request@ietf.org?subject=help>
List-Owner: <mailto:ietf-announce-owner@ietf.org>
List-Post: <mailto:ietf-announce@ietf.org>
List-Subscribe: <mailto:ietf-announce-join@ietf.org>
List-Unsubscribe: <mailto:ietf-announce-leave@ietf.org>

The IESG has approved the following document:
- 'Use of ML-DSA in TLS 1.3'
  (draft-ietf-tls-mldsa-05.txt) as Informational RFC

This document is the product of the Transport Layer Security Working Group.

The IESG contact persons are Christopher Inacio and Deb Cooley.

A URL of this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-tls-mldsa/




Technical Summary

   This memo specifies how the post-quantum signature scheme ML-DSA
   (FIPS 204) is used for authentication in TLS 1.3.

Working Group Summary

There is consensus to move this document forward - a ratio of 4:1. The message count 
is at ~275 messages. Some of those messages were off topic, there were many repeats, 
but a fair number of people expressed their views.

The controversy is related to the status of pure ML-DSA vs composite ML-DSA with ECC.  The
opinions included: 
 - we should not publish a pure ML-DSA specification, 
 - we should recommend composites over pure ML-DSA, 
 - we should publish the composite and pure specifications concurrently.

Appeals were both submitted and threatened.  The submitted appeal against publication was rejected 
due to a derivative work notice.  Private threats of appeal were made if the specification was not published.

IETF Last Call raised two additional opinions:
- improve the clarity of Security Considerations (done)
- publish an external guidance document explaining the issues (obviously out of scope)

Document Quality

No special reviews - MIB, Media Type, Yang, etc. are required.

Existing implementations include (but are not limited to):
- OpenSSL
- BoringSSL
- Rustls (via rustls-post-quantum)
- s2n-tls
- WolfSSL
- BouncyCastle
- GnuTLS

Currently, the I-D refers to RFC 8446, -rfc8446bis is currently in AUTH48 and
this document will be updated to refer to -rfc8446bis prior to publication.

Personnel

   The Document Shepherd for this document is Sean Turner. The Responsible
   Area Director is Deb Cooley.