[IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-mlkem-02 (Ends 2025-09-05)

"Kampanakis, Panos" <kpanos@amazon.com> Tue, 09 September 2025 04:14 UTC

Return-Path: <prvs=340318360=kpanos@amazon.com>
X-Original-To: ipsec@mail2.ietf.org
Delivered-To: ipsec@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 5E76A5F976DB; Mon, 8 Sep 2025 21:14:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=amazon.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id f5Hj-Fg316-S; Mon, 8 Sep 2025 21:14:13 -0700 (PDT)
Received: from iad-out-015.esa.us-east-1.outbound.mail-perimeter.amazon.com (iad-out-015.esa.us-east-1.outbound.mail-perimeter.amazon.com [44.210.169.44]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 8B6765F976D1; Mon, 8 Sep 2025 21:14:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazoncorp2; t=1757391253; x=1788927253; h=from:to:date:message-id:references:in-reply-to: mime-version:subject; bh=XkJ9RCBbvGSn5imetGhJSOOnW+Lzxi7tOIDJg9sg0Io=; b=dCAte+ASbPSoZ8yR1Upr6Drf7Gt0iB9zlPB/gxaq+gY/pTSDW86Qt7L7 fe2T9cGn2LX98VSzUbRPGrJIxOT9eThnpt+QJefXMTQ7gDLvH+rA3Hl06 ckplwDrX4WypTZN6zofSHlQiC6nybQgrkz0F2Fa+Kqos/PiST3DREtlf4 UCMUC41PZ8IVPakd+0kFFMdEf/Xjp2vYSPo4BmEHzYLAGJgHJeSWojvyz D/NcW3vw1FsipylI0AwHtGQ0J2/1H2t0uKstDNBW38FVXg0K1d3rNEiAU wt34UzvB3yxv9D45XPABJGtlfV3130G7ULCss2K+epZc8QYL9v1a3eXGc Q==;
X-CSE-ConnectionGUID: oF2alZwWRDeofUy+izO/ag==
X-CSE-MsgGUID: tP3bEBkxQvi7izwaK5YRHg==
X-IronPort-AV: E=Sophos;i="6.18,250,1751241600"; d="scan'208,217";a="1704270"
Thread-Topic: [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-mlkem-02 (Ends 2025-09-05)
Received: from ip-10-4-17-41.ec2.internal (HELO smtpout.naws.us-east-1.prod.farcaster.email.amazon.dev) ([10.4.17.41]) by internal-iad-out-015.esa.us-east-1.outbound.mail-perimeter.amazon.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 Sep 2025 04:14:11 +0000
Received: from EX19MTAUEB001.ant.amazon.com [10.0.29.78:65518] by smtpin.naws.us-east-1.prod.farcaster.email.amazon.dev [10.0.63.199:2525] with esmtp (Farcaster) id 5992aa36-87c8-4509-88b3-c09830462446; Tue, 9 Sep 2025 04:14:11 +0000 (UTC)
X-Farcaster-Flow-ID: 5992aa36-87c8-4509-88b3-c09830462446
Received: from EX19EXOUEB002.ant.amazon.com (10.252.135.74) by EX19MTAUEB001.ant.amazon.com (10.252.135.108) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20; Tue, 9 Sep 2025 04:14:11 +0000
Received: from EX19EXOUEB001.ant.amazon.com (10.252.135.46) by EX19EXOUEB002.ant.amazon.com (10.252.135.74) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20; Tue, 9 Sep 2025 04:14:10 +0000
Received: from NAM12-DM6-obe.outbound.protection.outlook.com (10.252.134.239) by EX19EXOUEB001.ant.amazon.com (10.252.135.46) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20 via Frontend Transport; Tue, 9 Sep 2025 04:14:10 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=JdOc+5tExk6hQRBd06J+opDJww3EOKAG2Tj/nfc7+9KStq8NsK0qW69kVbN5ZBtTDGME/TD2D6nt6qv+qqjIqv6iqoI+bwOtBGPl3pnmkCRQBlDoJeIkuzGIILQh3wKigZMWRLmJMRAg/wegVGG1QMQG6vRIejBG+M2hH/BkLfX8ISSxibObT9ZesnctvKC+Eugi0489TJS/fiygfFTdQIyZz+MzdNNjG3G/fBhO88iUTAeN5/vxuOkkNAvT8XTKr1aZE5Kbhm65NnOqGD8xMtJGvEmGDlR8gODn3TLtQQbJNjVgAlxSUqLWAD68TpwobYNZ8Rt/nI6I3FjvypdSBQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=XkJ9RCBbvGSn5imetGhJSOOnW+Lzxi7tOIDJg9sg0Io=; b=eAzqFFy/Z4y/mzSBAYnnXnfCTKqyU6yKzpJgiinZ3+Me9qbqgvSsG1pcn0kHJIl/GwKcQajbZPIdlnb+F0wfVNZgbTXmFU080+Eo9J7nvHPxRYkLeJtemsNT7s13lnkzS1msd5q38tJyuLY531RN6SwvlMWWhTLSaG4ckeRPf/3Vt2AihUHp5Scvsc8HUR8rvoQUpShlakvHcKHUK3b56Fa/yeLIoavRJokAY5vbi1HNAjO5izP9jin7h8dnGFCGqbTjk5D/9mUJQVHsTGY/vnRcBrY5wAuhAftcZoK4kIS/1lMEzcz5qGj3gQoyReXAmol1KOAaQnBYC6Fdf6/G6Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amazon.com; dmarc=pass action=none header.from=amazon.com; dkim=pass header.d=amazon.com; arc=none
Received: from DM5PR18MB2326.namprd18.prod.outlook.com (2603:10b6:4:b9::33) by MW3PR18MB3674.namprd18.prod.outlook.com (2603:10b6:303:56::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9094.22; Tue, 9 Sep 2025 04:14:08 +0000
Received: from DM5PR18MB2326.namprd18.prod.outlook.com ([fe80::6dd6:86fd:258:83be]) by DM5PR18MB2326.namprd18.prod.outlook.com ([fe80::6dd6:86fd:258:83be%4]) with mapi id 15.20.9073.026; Tue, 9 Sep 2025 04:14:08 +0000
From: "Kampanakis, Panos" <kpanos@amazon.com>
To: John Mattsson <john.mattsson@ericsson.com>, ipsec <ipsec@ietf.org>, ipsecme-chairs <ipsecme-chairs@ietf.org>
Thread-Index: AQHcGQTgfyBm1/5lbEemb7wbq7CaT7R6oqoAgA+qiaA=
Date: Tue, 09 Sep 2025 04:14:08 +0000
Message-ID: <DM5PR18MB2326CDBA1CF3531A3D32612DAB0FA@DM5PR18MB2326.namprd18.prod.outlook.com>
References: <175588193630.673.16768596589388372792@dt-datatracker-d58f77799-v4mr8>, <BL0PR18MB2324317798A092B5A96B4ACDAB3CA@BL0PR18MB2324.namprd18.prod.outlook.com> 9D6A05E0-A624-4E6B-90AC-EF3678A98ABF <GVXPR07MB96783F31F8AFC4310550B7948905A@GVXPR07MB9678.eurprd07.prod.outlook.com>
In-Reply-To: <GVXPR07MB96783F31F8AFC4310550B7948905A@GVXPR07MB9678.eurprd07.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=amazon.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM5PR18MB2326:EE_|MW3PR18MB3674:EE_
x-ms-office365-filtering-correlation-id: 2bf48ea2-6c6f-4fa2-9f90-08ddef575288
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|10070799003|366016|4022899009|1800799024|376014|38070700021|8096899003|13003099007|7053199007;
x-microsoft-antispam-message-info: 7/YLYjF+9my6gxBgYQhRRDnAR4DSgjdygcCbh7B53ny2fNxevb/UabfJHENqZ7R5wVy79c30jxJtcwCkCe81+veZ0/0aHtv5Gi9uqTDGGRIfBkkDGuBncbt0db/trrOT9Q+SAWQYSNpdwasWHQuPKm0gEXGCtg8SwFdFngF7mLY9XSqd4Qg05tH2bSw+fP7/U/0TPORpS0OcA7XiH+ia638JDeo3oPMcrdmaeNiTVUoBnxov7w1QOlAbTBvpgoyWJ+ca2t1+bBeZZTCyo5h11h6Jyiu0a31TQXpz4QptI4EbYnc27Lxs/aKi+CKeKOHmNkYdvyrJjOcs349/+7z1d5Egch19xaTEnpgaMg+bJaXiSMvZFa17OZbhjviPV8TsL9gC+nKinZJ4XE+tHUk0qk2JpzA1osjyZfZ8CYtdewmU/2klkjPQxrFUelhnCyW04zzu/Sj0WOh0x0/dB3kvvxu4526HZd1zycJkzZM/Ph9SIYy+3QG1jLaFDLrUEHs0bu9BFxxLySqIKyLIjF/Sy5gNiC/P9E3AH++Q7WsaZUbmBCb88+ruAZlimshcOY2Pt98xm+oDne+ALHWyZx0uMiaLfVjoYr+W1QThGliEjLHrJZq+wZqnZ3PE92hyAmLPBBlXfU9yZCSka/NCiB4bmC5dZFDbqk7MzGOnJdp4efwdxzCUThFQdZQgIsBbMAGeg3texEx2oEd5VDiuObcJRGfowR0v+FpGYj69hzDxOswOMattN1TY1Egyj3G+DzqbiD8BQtuv+NgjUIhDBKOpJGdibP/qSyf4lkjP2wj0btdgXmp6GQeazz8GaPdvdqSfPqoxe5ACrqs/ZKo6sd589/dxoqzFV9mqrHJeg+SSNAOQJ0lg+6WqIcLfUkzCJv9U12OaGgOjTHG+xiOndgjMbu4jfnN4sCzXQ1yRYA5Bp4Mqju0rrGPeBhpJHRMIkBXjAE5uYc5OafPOwU67XuOjynmcEbReyP4+O02Xwwtox1EQrlkPcNYMNJP4d86tSXVqk/lobVQbJo1cIRIdczAmVb6A4poqUlfcxe7cA/jPHkxwdNgK8ck60XAF85eabQTAVNYMHcucP4tfJqsAzVTnQ1VeJIlfGgQKc3WJBA0XUAokMqGLx2UncqjduyAWxjMm6QZKHn1UKQi8ERrhrEJA3cwj8/kW6qcsGPuTrY2zCkl8xjRMs6hOs4EaeU5q9JRjqlL9GjKkYee3Ow9HxYrRvkM+El6Bx8gHAqu52W50Eou5nxckSuEJiRbNbvnw3OtCuNjshqL9LifUquXDgbfpQwL4DYih2O09JLU+g7H+iEzI/GdVVIqH4gqnHkOknjxJFd8G591h7aUr7eJKbqKCGJ8P+Mz9OG1DB7bvag5g9SeuuqmEnIZY0ttDLXVUdPiJ/URD+HwL/ppIHm7OB8sA1zRV5M/LsjhSrXq/9chKQn5D38uGNouIe20lNyiXNXNGur+P7djbBnA1XSXZZvYibc7GSy9fI+5vDaPcvqXV6A8=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DM5PR18MB2326.namprd18.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(10070799003)(366016)(4022899009)(1800799024)(376014)(38070700021)(8096899003)(13003099007)(7053199007);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: zPezZrBYBT/ULu9W9cc9fcv21M/FMRqNr+K27cKqc2cpvfIKvBc493ztjFkuzoHyzlebqKFVSYlgdVgFGWJ4a2HhxWA7MtfuxLptCGg9SHDu+xeTYAKD68Rzq5HfM4j2h0xLsNp4SZ1HVfK/3EtjZ5Mr3w4FwHYt8Bt/URTA6ALaBtWq+fQwtM+JXUjT3KF2L2DAbWeNCQkNluI3uss6b+XxANmxvGo0UUYRp2Ar7gOUwAwNUwza4ZLNo+9TA0XX6zO2xOTgo4YMm0yfL9Uju67gmp8Bx75mAka4fh/tgIzDp67QM5La7R6DumrjitKUhUOq7iCp6OtDw9e7PuTMJ07GGS0rSuWCMvsV1Eh1iOD5mWk0/J0Gia5iaaWzVoGevI24JIyAPWoAEgZWZxh+vo2HdvhdUBoXs1Y4DhJQkF9UmP8oMULTJH9Jx4LDcheOWw2z9ysBxP0qsbS8qrhb1UqJdOgj/UZme9bvrAsTp1NcCy2O7Mv2wNUxU6VkCLZ/S1+3oZn+AtHjrHtjrWM1YlcGyiGDcMpsSZ8VLpNffpAZe7Xll0xh3hhMz9Dj2kUd3dT1IIKgceG0uAbqiSfxIPgyAGnCR1jWcNVdvhloY+Rc88SZBIWi0vayKgLH+RM1ql8eT0VEHXrG4UUlv0Xh0Ithy+02pHkQmar9K2em/cXSvFCFIvRHfimADBQg2G/lXP/zE9MkYOa3ihv30p+Ugr3BIeByLnp4icOnCcnAoc4ICkVxSEiL1hrjt4S8en7dUJZe4pFeEU0faEGgSW+FPlkJ3inMncCUYeyiIEZOIO2w5OiypdoZK3Y72rdYsLDBhV0e1oRGy+EvXkrecuEoBpc6gBijJQM7vkzsSCFwXM0TQcsOnYfyU+Yjpwdtn+yTbp3v7pROIs71tyoqdvYm+2slCMHATKLTJQck5ZNS+JZO3VIcrdeBTqe0jtyUQwsgMWY4Ym/OnEgoqI1gj9ELnk1+SDBtb770VfQak0o3e+HP8LP5pCsYyhm3f+KAyTc7NN0hHZOh2JwowQT6ioclHazZmTIdLOT5vcNWy0yotbwwm0Nu6gPC2IN2SbbGmMU8IbCojVOvPc/z7+TaSHoEGvRupoBJHNAEgU7Xqgxlk7LczjXs9DoDkiM1ROLs5g8ZfyQhx2ErwuJcx39yCNYPSwvLdeopjahuTs8AEewHLbt3PbeKoaQrtCeqTPpzE5LYegNLbx4r/8GpNtH7DYWYcepijrOZIq4lP/t+tidQS8FnKCtTQvWpA3Vj0/ZR5XCUo/f/DUKIdfTQ3reQDXzLQ23BeOW29FGPuR80/MVCphbIc8AEDu9eLusFfPHMpk1X3E6r0/lwJHWcNyd8fy5J/N9vwxhXxkIao3CGpKXOxqeIP00JighXUBSZH6P0iyMxXJupzT08qy3lMvvvCmldTXA/RsaV4lrzge2zvze6qbWp6tAKoiT7sNtu7Y0uVnrqML+wpaK6jpk8sZooOkaCcEx7uBJp3lF1JMC1aFoYPSRsb57wYIr4bL1uNK7Xs8E4lGE+PaujF3b9GQvLZN7Mf6Qat4/rOrA4MGZcc1o+ZHZf5Iz3EsTSgqNXECveyxJ/wmXm8f2Ys6PNPSM5698+0kiSz0+JSufbTEK5+XWQpOs=
Content-Type: multipart/alternative; boundary="_000_DM5PR18MB2326CDBA1CF3531A3D32612DAB0FADM5PR18MB2326namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM5PR18MB2326.namprd18.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 2bf48ea2-6c6f-4fa2-9f90-08ddef575288
X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Sep 2025 04:14:08.1723 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5280104a-472d-4538-9ccf-1e1d0efe8b1b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: xCiCsy4rfbJ/dt80MPjwYLYIO/hAaztZyoR/n4TZ9r/FB0CFZzILDbQeG9MwYjYULHO6Ku9wmaumCjZhi5EJQQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW3PR18MB3674
X-OriginatorOrg: amazon.com
Message-ID-Hash: PIJY4AVV5ERB7IAHMF35M7SSGY43CHRB
X-Message-ID-Hash: PIJY4AVV5ERB7IAHMF35M7SSGY43CHRB
X-MailFrom: prvs=340318360=kpanos@amazon.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ipsec.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-mlkem-02 (Ends 2025-09-05)
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/J-x5UaHHObtJRm969eMZVe2a6AQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Owner: <mailto:ipsec-owner@ietf.org>
List-Post: <mailto:ipsec@ietf.org>
List-Subscribe: <mailto:ipsec-join@ietf.org>
List-Unsubscribe: <mailto:ipsec-leave@ietf.org>

Hi John,
Thank you for the feedback. These were addressed in https://github.com/csosto-pk/pq-mlkem-ikev2/commit/fa5dd8bd441c9f277bdc232c6eb4abe4b78762a0 The normative MUSTs regarding ephemeral exchanges were updated in a previous fix.


From: John Mattsson <john.mattsson@ericsson.com>
Sent: Saturday, August 30, 2025 12:56 AM
To: Wang Guilin <Wang.Guilin=40huawei.com@dmarc.ietf.org>; Kampanakis, Panos <kpanos=40amazon.com@dmarc.ietf.org>; Tero Kivinen <kivinen@iki.fi>; draft-ietf-ipsecme-ikev2-mlkem <draft-ietf-ipsecme-ikev2-mlkem@ietf.org>; ipsec <ipsec@ietf.org>; ipsecme-chairs <ipsecme-chairs@ietf.org>
Cc: Wang Guilin <Wang.Guilin@huawei.com>
Subject: RE: [EXTERNAL] [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-mlkem-02 (Ends 2025-09-05)


CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe.

Hi,

I support publication. This is already implemented in several libraries. As Panos writes, this is very straightforward. If there is any disagreement of any text, I would suggest just deleting the text. Much of the text is not required for this simple code point registration. In general, I think less text would have been better.

Comments:

- "This draft specifies how to use ML-KEM as an additional key exchange in
IKEv2 along with traditional key exchanges."

I think "with a traditional key exchange" would be better here.

- "and theoretical weaknesses in ML-KEM."

My view is that the major reason to use a PQ/T hybrid is implementation bugs like side-channels in early implementations. ANSSI that requires hybridization of ML-KEM says that they have the highest confidence in ML-KEM and states that hybridization will likely be optional at some point in the future.

- "At the end of Round 3, they picked Kyber as the first Key Encapsulation Mechanism (KEM) for standardization [I-D.draft-cfrg-schwabe-kyber-04]."

I see no reason to refer to this expired draft. I would suggest removing the whole sentence as this history is not relevent for this specification.

- "ML-KEM-768 and ML-KEM-1024 public key and ciphertext sizes can exceed the typical network MTU"

I think this should be "sizes can exceed the network MTU" or "sizes exceed the typical network MTU"

- this document focuses on using ML-KEM as the second key exchange in a PQ/T Hybrid KEM [I-D.ietf-pquip-pqt-hybrid-terminology-04] scenario

[I-D.ietf-pquip-pqt-hybrid-terminology-04] is now RFC 9794. I would also remove “second”, as that is not discussed elsewhere. ML-KEM could be key exchange 1-8.

- "Receiving and handling of malformed ML-KEM public keys or ciphertexts SHOULD follow the input validation described in the Module-Lattice-Based KEM standard [FIPS203]."

"Initiators SHOULD perform the Ciphertext type check specified in section 7.3 of the Module-Lattice-Based KEM standard [FIPS203] before the Decaps(sk, ct) operation."

"Responders SHOULD perform the checks specified in section 7.2 of the Module-Lattice-Based KEM standard [FIPS203] before the Encaps(pk) operation."

This seems to violate FIPS 203, which says: "This algorithm requires input checking, as specified below", "ML-KEM.Decaps shall not be run with a decapsulation key or a ciphertext unless both have been checked.".

I am against violating FIPS 203. I suggest MUST or just removing the text.

- "IND-CCA2 corresponds to security against an active attacker, and the public key / secret key pair can be treated as a long-term key or reused"

This sentence about static keys is not relevant for IKEv2. I suggest removing it.

- "Generating an ephemeral key exchange keypair for ECDH and ML-KEM is REQUIRED per connection by this specification, as is common practice for (EC)DH keys today."

NIST forbids reuse of ephemeral (EC)DH keys and plan to do the same for ML-KEM. Any IKEv2 implementation reusing the ephemeral (EC)DH keys are not compliant with NIST. The main reason why reuse is and should be forbidden is to make session keys independent of each other. Reuse of ephemeral (EC)DH keys in combination with other implementation bugs has practically led to complete breach of connections.

- "mlkem-512", "mlkem-768", and "mlkem-1024"
The names are not aligning with the table and the current IANA registrations.

- "38-1023 | Unassigned"
I don't think this row should be in the document.

Cheers,
John

From: Wang Guilin <Wang.Guilin=40huawei.com@dmarc.ietf.org<mailto:Wang.Guilin=40huawei.com@dmarc.ietf.org>>
Date: Friday, 29 August 2025 at 18:48
To: Kampanakis, Panos <kpanos=40amazon.com@dmarc.ietf.org<mailto:kpanos=40amazon.com@dmarc.ietf.org>>, Tero Kivinen <kivinen@iki.fi<mailto:kivinen@iki.fi>>, draft-ietf-ipsecme-ikev2-mlkem <draft-ietf-ipsecme-ikev2-mlkem@ietf.org<mailto:draft-ietf-ipsecme-ikev2-mlkem@ietf.org>>, ipsec <ipsec@ietf.org<mailto:ipsec@ietf.org>>, ipsecme-chairs <ipsecme-chairs@ietf.org<mailto:ipsecme-chairs@ietf.org>>
Cc: Wang Guilin <Wang.Guilin@huawei.com<mailto:Wang.Guilin@huawei.com>>
Subject: [IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-mlkem-02 (Ends 2025-09-05)

I support adoption. The draft is well prepared.

Guilin

发件人:Kampanakis, Panos <kpanos=40amazon.com@dmarc.ietf.org<mailto:kpanos=40amazon.com@dmarc.ietf.org>>
收件人:Tero Kivinen <kivinen@iki.fi<mailto:kivinen@iki.fi>>;draft-ietf-ipsecme-ikev2-mlkem <draft-ietf-ipsecme-ikev2-mlkem@ietf.org<mailto:draft-ietf-ipsecme-ikev2-mlkem@ietf.org>>;ipsec <ipsec@ietf.org<mailto:ipsec@ietf.org>>;ipsecme-chairs <ipsecme-chairs@ietf.org<mailto:ipsecme-chairs@ietf.org>>
时 间:2025-08-23 11:05:18
主 题:[IPsec] Re: WG Last Call: draft-ietf-ipsecme-ikev2-mlkem-02 (Ends 2025-09-05)

As an author, I naturally support WGLC. I have addressed comments in the list so far and added a couple of paragraphs about downgrades. It is a straightforward draft that does not introduce any changes other than getting IANA identifiers and summarizing how ML-KEM can be used with rfc9370.
Thx

-----Original Message-----
From: Tero Kivinen via Datatracker <noreply@ietf.org<mailto:noreply@ietf.org>>
Sent: Friday, August 22, 2025 12:59 PM
To: draft-ietf-ipsecme-ikev2-mlkem@ietf.org<mailto:draft-ietf-ipsecme-ikev2-mlkem@ietf.org>; ipsec@ietf.org<mailto:ipsec@ietf.org>; ipsecme-chairs@ietf.org<mailto:ipsecme-chairs@ietf.org>
Subject: [EXTERNAL] WG Last Call: draft-ietf-ipsecme-ikev2-mlkem-02 (Ends 2025-09-05)

CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe.



Subject: WG Last Call: draft-ietf-ipsecme-ikev2-mlkem-02 (Ends 2025-09-05)

This message starts a 2-week WG Last Call for this document.

Abstract:
   NIST recently standardized ML-KEM, a new key encapsulation mechanism,
   which can be used for quantum-resistant key establishment.  This
   draft specifies how to use ML-KEM as an additional key exchange in
   IKEv2 along with traditional key exchanges.  This Post-Quantum
   Traditional Hybrid Key Encapsulation Mechanism approach allows for
   negotiating IKE and Child SA keys which are safe against
   cryptanalytically-relevant quantum computers and theoretical
   weaknesses in ML-KEM.

File can be retrieved from:
https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-mlkem/

Please review and indicate your support or objection to proceed with the publication of this document by replying to this email keeping ipsec@ietf.org<mailto:ipsec@ietf.org> in copy. Objections should be motivated and suggestions to resolve them are highly appreciated.

Authors, and WG participants in general, are reminded again of the Intellectual Property Rights (IPR) disclosure obligations described in BCP 79 [1]. Appropriate IPR disclosures required for full conformance with the provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. Sanctions available for application to violators of IETF IPR Policy can be found at [3].

Thank you.

[1] https://datatracker.ietf.org/doc/bcp78/
[2] https://datatracker.ietf.org/doc/bcp79/
[3] https://datatracker.ietf.org/doc/rfc6701/



_______________________________________________
IPsec mailing list -- ipsec@ietf.org<mailto:ipsec@ietf.org>
To unsubscribe send an email to ipsec-leave@ietf.org<mailto:ipsec-leave@ietf.org>