[IPsec] Re: Call for adoption: draft-wang-ipsecme-hybrid-kem-ikev2-frodo-03 (Ends 2026-02-09)
"Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com> Fri, 23 January 2026 13:05 UTC
Return-Path: <sfluhrer@cisco.com>
X-Original-To: ipsec@mail2.ietf.org
Delivered-To: ipsec@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1F165ABF5353 for <ipsec@mail2.ietf.org>; Fri, 23 Jan 2026 05:05:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -11.886
X-Spam-Level:
X-Spam-Status: No, score=-11.886 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_NONE=0.001, T_SPF_HELO_PERMERROR=0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cisco.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id O2MXGeJDBfE0 for <ipsec@mail2.ietf.org>; Fri, 23 Jan 2026 05:05:42 -0800 (PST)
Received: from aer-iport-7.cisco.com (aer-iport-7.cisco.com [173.38.203.69]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 47E70ABF5112 for <ipsec@ietf.org>; Fri, 23 Jan 2026 05:05:31 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=27662; q=dns/txt; s=iport01; t=1769173531; x=1770383131; h=from:to:subject:date:message-id:references:in-reply-to: mime-version; bh=bH2Oaqd6BdOT0+3QufCfZGFE3emkKE329v7sQRsbnkg=; b=Hma6jsg2zxZ3JdO5CVO2B0NfK7midxmV56+qB6YgjukUrHAHjyFjsGl8 hK2xXmzJYsisGzs793PJrzIyBShc1WR4bWC2XJNy0fZDNY9qlqM7XUn1O z6NlXQeuMnSTTlEgzscC2kKUU09SnaPQICd7oHhHrJqEkwEVmZY2cqcUz 5ZiGvZH42eZNnpFc1SRzCEDgTZ6JherhdHpgQSAD0G22p7tqcO0HFL7dE BR5FcxGpwykGhIlbx4oPKGM4ws/7kxYHSVGDp1zVUA3U+1nRe9m6ne/wx aFuOfUbQlhA6oac8tU4tw2+u5V7/vBRW3eANMINcAcRp8XNVNpPK78HJa Q==;
X-CSE-ConnectionGUID: L/2ZH2qsTGWV1Gt2Hrdbow==
X-CSE-MsgGUID: Je87XCZASCmsEAuwvAegjg==
X-IPAS-Result: A0CfCgCecXNp/9JK/pBagQklgSuBPTFTB34CeClJiCMDhSyGWIIhA54ugWsPAQEBD0QNBAEBghOCdAKNCgImNwYOAQIEAQEBAQMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWgEBAQECARILMR0DEAcEAgEIEQMBAQEBIAcHMAEUCQgCBAEHCwgTAgQBgmGCHRYZJwMBAg4GpBYBgUACiit4gTSBAeAoBoFNhTuDFwEBKoE0glqBHhk7gx6BHycbgUlEgRVCgmg+gQWBXASBKQESAQccBRgBFoNfgi8EggkEFVIoCgoSCw8/BQYvQwcBATEBPYFcBAMRAiuEMIFYVCWBC0eGMlJySzMsAVUTFwsHBYEjEDMDIAovLQIUDRASDwQWBS0dcAwnEg8dFxMfWBsHBRMjMQUaBhwSAgMBAgI6UwyBdQICBIITe4FmGw+HBIEABS5vGg4iAiwVA1sqAwttPTcGDhsDBIE1BY4KW0SBPBFbBj4mBCIhEBQMAlkRDBwRIAVCBpMfS49jg1aJepVfCoQcog4Xm2uOGWeZBiKodAIEAgQFAhABAQaBfiZpcHAVGiGCZ1IZD45fiFW+R3gCAQE4AgcBCgEBAwmTZwEB
IronPort-PHdr: A9a23:kmqqjBEGz0i28IeFpAYNpZ1GfhMY04WdBeZdwoAsh7QLdbys4NG7e kfe/v5qylTOWNaT5/FFjr/Ourv7ESwb4JmHuWwfapEESRIfiMsXkgBhSM6IAEH2NrjrOgQxH d9JUxlu+HTTDA==
IronPort-Data: A9a23:Etadeqmm7TqpO350M8s46mXo5gzFJ0RdPkR7XQ2eYbSJt1+Wr1Gzt xIZUW/Ua/eKYmemc90gbdiz80xX7MCDy9JiGVA4rXpmFVtH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaC4E/raf658SUUOZigHtLUEPTDNj16WThqQSIgjQMLs+Mii+aEu/Dha++2k Y20+ZS31GONgWYubDpNsfnb8XuDgdyr0N8mlg1mDRx0lAe2e0k9VPo3Oay3Jn3kdYhYdsbSb /rD1ryw4lTC9B4rDN6/+p6jGqHdauePVeQmoiM+t5mK2nCulARrukoIHKZ0hXNsttm8t4sZJ OOhGnCHYVxB0qXkwIzxWvTDes10FfUuFLTveRBTvSEPpqHLWyOE/hlgMK05FalfoNRXW3hVy dMnFmkickqjne68x63uH4GAhux7RCXqFIoSoDRkiDreF/tjGcGFSKTR7tge1zA17ixMNa+CO 4xDNGYpM0iGOUQXUrsUIMpWcOOAnXf7bj1CpUi9rqss6G+Vxwt0uFToGIaPK4bbHJQN9qqej kDLrzvJKSMzD/ea0hes722yr+LAnyyuDer+E5X9rJaGmma7x3QIBRY+VFanr7++kEHWZj5EA 0UZ4G8q6KM17kHuFoi7VByjq3nCtRkZMzZNL9AHBMi24vO8yy6SB3MPSXhKb9lOiSP8bWVCO oOh9z8xOQFSjQ==
IronPort-HdrOrdr: A9a23:p56DV6v4N5Ksgd/04KdfaVdh7skCP4Aji2hC6mlwRA09TyXGrb HMoB1L73/JYWgqOU3IwerwR5VoIUmxyXcH2/huAV7CZnirhILGFvAY0WKP+UyFJ8S6zJ8g6U 4CSdkwNDSTNykBsS+S2mDReLhQoqjjzEnrv5ai854Hd3ANV0gU1XYANu/tKDwOeOApP+tfKL OsouB8i36Lf3MRYs6nBn8DcdTiirTw/q7OUFotPTJizBOBow+JxdfBfiRw2C1wbxp/hZMZtU TVmQ3w4auu99uhzAXH6mPV55NK3PP819pqHqW3+4koAwSprjztSJVqWrWEsjxwivqo8kwWnN 7FpAplF9hv6knWYnq+rXLWqkndOXcVmjzfIG2j8D7eSP/CNXYH4g169MVkmy7imggdVRdHoe R2NiyixsNq5Fj77VXADpDzJmFXfwyP0DQfeSp5tQ0FbWPYA4Uh9bD28C5uYeQ9NTO/54Y9HO Z0CsbAoP5QbFOBdnjc+nJi2dq2Qx0Ib1y7q2U5y4WoOgJt7ThE5lpdwNZakmYL9Zo7RZUB7+ PYMr5wnLULSsMNd6pyCOoIXMPyUwX2MF/xGXPXJU6iGLAMOnrLpZKy6LIp5PuycJhNyJcpgp zOXF5RqGZ3cUPzDs+F2oFN73n2MS+AdCWoztsb64lyu7X6SrauOSqfSEo2m8/luPkbCt2zYY fEBHuXOY6VEYLDI/c84+SlYeghFZA3arxhhuoG
X-Talos-CUID: 9a23:J0XlRWowb5eV0qlHY3BmJtDmUeRiKE/9lm7LH2CHNz9GVOe1U1Oa/7wxxg==
X-Talos-MUID: 9a23:D+LYBAwTAj8tF11cnFTvdVLkVxOaqIajWB89uqcvgOKBLgFZJiiDpTm4QIByfw==
X-IronPort-Anti-Spam-Filtered: true
Received: from aer-l-core-09.cisco.com ([144.254.74.210]) by aer-iport-7.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 23 Jan 2026 13:05:30 +0000
Received: from rcdn-opgw-1.cisco.com (rcdn-opgw-1.cisco.com [72.163.7.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by aer-l-core-09.cisco.com (Postfix) with ESMTPS id 4F4B518000121 for <ipsec@ietf.org>; Fri, 23 Jan 2026 13:05:29 +0000 (GMT)
X-CSE-ConnectionGUID: d6jshxjFSdKFCpLeUw89uQ==
X-CSE-MsgGUID: hVK3WkLVTRmPYvbzwbF3hA==
Authentication-Results: rcdn-opgw-1.cisco.com; dkim=pass (signature verified) header.i=@cisco.com
X-IronPort-AV: E=Sophos;i="6.21,248,1763424000"; d="scan'208,217";a="44002570"
Received: from mail-ph0pr07cu00606.outbound.protection.outlook.com (HELO PH0PR07CU006.outbound.protection.outlook.com) ([40.93.23.94]) by rcdn-opgw-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 23 Jan 2026 13:05:27 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=jxHvWkRXrXTYmM3JCXz0fdnC2nmVmNCGf43ePu89yPw8qS3gfaNcTw297AsdxHAabBIvLk6lstSZc76tjqByPWkGYLSJ7EB4vilM4ao6B406BliGXP75G2+dTVfSIAGK/a7j08RKfsEqn7ERKn4no4u3xHeQ9omfxGqyGUtYwycPcRzGIIK+rgjPaxC/DowCejcfYu/3BniK+EIBi9ksytyInvonT4ozWzeX5LSvTcpkOvrcXaPxkt1QSUIXZ9yRWRYJuzG8B5NnR6OFnpxQDWNfwYrrwZyO4j2zqeJl2OHpCu9NMTm1aLeYiYZ7Uxcb0FyLLbyerOxvBK9/WY5F7Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=bH2Oaqd6BdOT0+3QufCfZGFE3emkKE329v7sQRsbnkg=; b=JxLEOyFQKN1ke0JpqY2TKZbjnmGhEEZQxLgLgVqMKT3IN6P7OTtSvkwRgapwKdnJR8a0QgGfAsawMyh0J8T+7SATLRtDUUxMOclmyaQrIUBcSJ9M6pxDb28OpOE0gOFMEv1Zw56ODvG5y78xXt5hsXikre/dj8wrBVBqa0gRz8+kjaHyDbFMr+lFZ9Fo4mhZ9J55vFhHfRguFCOz1gOyIm7KvIvEgiUWv/8vsTHGOl6oXxtwHD3DfDMJ4VH/n48b3jwEfu9nZL/ftWX9zudqyGI3NkrKW9GtWVvfvT6NVTqbf59f5f8exBmvRlqrB6UTr6141MPFKZ93d83PyMiiAw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from PH3PPFA3FE8A23F.namprd11.prod.outlook.com (2603:10b6:518:1::d3f) by PH7PR11MB6355.namprd11.prod.outlook.com (2603:10b6:510:1fd::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9542.11; Fri, 23 Jan 2026 13:05:25 +0000
Received: from PH3PPFA3FE8A23F.namprd11.prod.outlook.com ([fe80::16d:bbc8:851e:5217]) by PH3PPFA3FE8A23F.namprd11.prod.outlook.com ([fe80::16d:bbc8:851e:5217%8]) with mapi id 15.20.9542.010; Fri, 23 Jan 2026 13:05:25 +0000
From: "Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com>
To: Wang Guilin <Wang.Guilin=40huawei.com@dmarc.ietf.org>, John Mattsson <john.mattsson@ericsson.com>, Ben S3 <ben.s3=40ncsc.gov.uk@dmarc.ietf.org>, Michael Richardson <mcr+ietf@sandelman.ca>, Thom Wiggers <thom@thomwiggers.nl>, "ipsec@ietf.org" <ipsec@ietf.org>
Thread-Topic: [IPsec] Re: Call for adoption: draft-wang-ipsecme-hybrid-kem-ikev2-frodo-03 (Ends 2026-02-09)
Thread-Index: AQHci/dpHQ/njf+Mx0iie+u8O+J7/rVfZ+8AgAAQ4ACAAA5DAIAABjMAgAAp1hE=
Date: Fri, 23 Jan 2026 13:05:24 +0000
Message-ID: <PH3PPFA3FE8A23FA3FD8DE50FFD8EE8E4A8C194A@PH3PPFA3FE8A23F.namprd11.prod.outlook.com>
References: <176824138819.764059.17372501962377307239@dt-datatracker-5656579b89-r5kdq> <064BDB29-C00E-43D1-ACD2-542ACFF0311F@thomwiggers.nl> <20460.1769116002@obiwan.sandelman.ca> <CWLP123MB34104BE8D2E872E42DD32A348094A@CWLP123MB3410.GBRP123.PROD.OUTLOOK.COM> <19ca7ee7354e4135b655cd7a6cae864d@huawei.com> <AS5PR07MB10596B07938131FB9C63EED078994A@AS5PR07MB10596.eurprd07.prod.outlook.com> <f98414802a064539879bbc711bc920cc@huawei.com>
In-Reply-To: <f98414802a064539879bbc711bc920cc@huawei.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH3PPFA3FE8A23F:EE_|PH7PR11MB6355:EE_
x-ms-office365-filtering-correlation-id: afd40e51-f834-4f77-b695-08de5a8012ba
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|4022899009|10070799003|376014|366016|7053199007|38070700021|8096899003|13003099007;
x-microsoft-antispam-message-info: 5V/oRrUz5ShJh1qzsq3d9iwVfdZwSQVaPnga3B3qqCpaWpYpV572WPErnxX39RVh9z+6UDn6l/Cvc8dTrTIwP4fY/I6PPPzz1wEfB6b0Ka9QAe08F7jVw42znPNmnFr0KUGonO7gdk5sQtAZ9g/XxkVU7+/J0iVsOWaxxT+mkIYFExuYKJGAT2EwivCEDzTNXb83zg6K+QKqXHFisz79laJKKoE4zDypk2o/PoHDq9IlJjmyo2ibB25+Kiadkw/enmP2U2lOnRod5JRt7ocVritZg6gf0OXc9HsClJwcr3MBNNuwKJ8i8i+R7y/cMLpb8ivd+AmKdMB0epLzo3ZbuunmuCSKelciBC3ijuG/DdPsXmVWjDEa8YFeEEerCpifAFxCr59xpEq9XfMneeEYBfOhCt3aCFsUJ9QpV6pNxVqvvDrfFHwnGZzcyFBJ2JbiXEgotfOtdq/Pj0DMVgolRDBN158YJZtEGB7ytj0+nCSt84gRH4xz0jXRlAeorb+tmmF2MkYAm1H98wShJsC5u9i+nnefZhxXGGdcfbtBei1WA3If/GeTKImKROwbs4O/n6lCdXsitXcF8UiEBGNw2UH7tp3hPbqd6cqfVfmrPbIL/fy4Dr+owHpvRMhR13Em9EPluBi58c6m5zUUECheZD/kWYx6Eh+rd9j6MxlH2y20xVX60d4YgWnlJz16JnMT7ccaxT2YNi3SIyyVbzJJzW+Vgv6TF9/QFDMUiyu1wN5SELejzv9dvxYwJmDg6o/IpCvzluk63Z7P2ZT5tfjUwW1ZWG+kemi7g+kbdY78tDIuVW7pTKoj5wTnVMRnqUT73/gJQ0ENIs5DRQygz6r4xl5ZNkOiuhKPM7Rc7+RkuV/0BVlJt7dwrh41NBTTDRJDVxC0PRoMNicDxJRLdXUEz1aRoswTGYfrHciGbo0RoOHRtUf7nq6Pav5cUMpp+cbPSsLnHJRr6CM9mnxZRSopSr23V8nrGvF8bPlxF21iW+xsPrNpoprD22ABxx8NdMstDLMctOPTabhkl16G/hBydUoNR2lM70sHfXm9Yu2aUVp72NK4CDfG4sgGKm9F8dErRFv5aHsQ58K4na/l/iA3ahz81EpzuPcNbWUM1IJPABitDrrPkaYuTPwzfuexCD5D5wg2LW6EZGaFEduww5xbrQPTy9rd/Or5wUD1ayQPUq4JCMF1BICVy0OG3qymf2tqZaBQxpaeKTLD3OEBpLhcrq4+4lSZ0S/IyqflVfZhoq+ZRJ15jetQFOEV3+R4XIlfvW4y+gWyJ0VHlThq4NF7vMy8TfoZQYdkRfafHu08J1pJtY6+Zo0mTOXqOkmR/2YKdLQuXmF6+iFF9tyxmM/V5nZUy9BTVCACRxZr0ns3JyjyyuaRWe4OVYJsqPh1Sm0Q3RcMBRsVCcp9R8LCKhyIDtJzucYEElnd5mfG3+mvx0FuUTNNKH0JfGqX4E0f3wqCHStsNpaC2hZ/+eBC+vNsOtHurmTlH7p3PDTATnL6b8UV56+IfPZaDiEx6DZgdbrNtV7twtbQ9J0ZTKPEe8ceZcZYUuHZ637iTR2dd2g1E4ZVgpzVZZJttG+Xhs1tWxyUTqIK8FP4mg+fyyEdT6yp7Hjj2Gmthbwc+CmXhcpprfg=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PH3PPFA3FE8A23F.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(4022899009)(10070799003)(376014)(366016)(7053199007)(38070700021)(8096899003)(13003099007);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: PQd4ubNVx8cEdGUNs4v1cjUwqr1zNBclsyBifKRgpl89QVodnPBTaB9S32m1iW5C2vMmZrd/G1NS2bJaX2vFQBFEc3E8OmQeZQFXTl2HERYcCad9zQQWLMLsc3DxFNO9qaIRWzUxmWcj3ZM1buoA1kNcqJM2brz87ekhqY7FeZV3mnS1++MJroVS00sowC3FY3ba6CqV4XyQF4vAJnmAXvicmFLXVNbeEsB2jo0r06j7g0if2u8d0bpHYukgNbIRARmL69xxHM60yHpHLONlzmsGqIhgMVGUQlyUY/F0cAUPoPWURni1zvjfg9pJQSFM6mxxUo3ktz7hB66Ti1g1hL4q60nEbVdYohofgTqO9LcVPBxYkZWACi1Cr9C6+mW8jZRwuvyPgDmArkI8hwwQbgRAMAufTB9RVXhUguO+3FP5ckp5fpPXgV9YzIDpveVmy2oeNtYfq/e86UK/ap+3DaU/z29/h0rDKBSCyfeiDu3g+rRA3T82+Y074yBhzXjdljB3TNLBtQeP1vkjIvMVGOCloe6xub1swtk48CTBzzIILU7TULRtEa9EUNHVeyot50Lx4by4Py0xPdutggXwRAvc5J96Xqyuuu7biskQxTUAxi/G/Lec4UKnsUqqwK7q8NRxah/dGJa+977OipgqecIUHb/AdNYGbfZzwhDxj4/B1yqwGkv1J0hsuqx6S6ciNKYx5GNjP7pft4cNduhlVhqvBliKrf18QhoiMvw5Swf4JZCUWGlZxcycgu1LM3ziWy1nRC66bVeUm6NUuBuAvcGR1KkRhRMsKWcGJAqmWM3ojTh6H4T4OmC9sfJUyY43/hYve9o+Dfd7MMDYKPdIhfKTkR9dRs1jh0L4S0uZ/VeIlms+psl1V6r4Oftq6CzcXW7JKcB/dJwsOlxjw6SB9T9zuZubUi3JKrNLuEdajs4LTv7hJIf8j/xb3dtzce1PNHhOTP4JwuPu0oZt4tRfcSVhu94ikxvWxQeenNk7H7DQKf9Msfe5tbA/EWvx+qJl2vNpQ7K3fM6FWcdhLqcVJ8k3d5J6hDFNVzDOQWCKX/wnUvlW3Cr/sGBc1VL+0QGmu7g2GP6BRoRNmT5d7fFyX5zjBFsepsElY/dC9iPK5wBoYkU9Frub+k6Vyz4FA1L6c12zkkea50VAcPvEkYp3YMtoid4zKEXGHGMpaCtv807rSvpiNADpdTiWbVWFWHsy+/y5gsPZIWwjn3SpIE/vIYFG4Ox2QaCf7I59EvKsCqP8PUuv8QdJfSO+8bWG9ALLJzYgSjrXSWaFbDoWtbg8DAy8sqL2O5/NMeLS7ip+/v1D3OW8u1qx/62YUZo0npCZBdV/fq1DFa65IpqUl58hSSk2hiiPn7W24r1WYNzDEQ/xe3akeqXyEzYV0O5oAwBrHmtrBM16hVHRfDEzkdeo75jvizZTjHPx6rZFAhFSRW4uVR97z8Hg+dBSyJ85JcPKMzgbJDfMwsLH6PT3TfdMepuGhoc33btLTVkRCmDHm2LqrJ+M9KFJz9z6ylNkuZF2AwtItN9y1tfuYZm23k+N1MQpL3+Ww4YWlxqKBz1b8QuJiZliIwk4bhNC48Il7LyNBVAftgiCfDkvqPwNlPXxhE9XL77m+vrgt7oanLTrWnlCcr1Bp/451TJav+t7mia1uT2P+smy/MNtKb9Q7wWrGlggu7/1juLSLDZq83rRqmviOEUXcCCiGUptG/2vE72Rdxb4gTrl8HuOIAfgXhbekTVo0+4r9ID/9EcaCKbpW4OzbFuuuFXrBy8oQ6KK5vxC
Content-Type: multipart/alternative; boundary="_000_PH3PPFA3FE8A23FA3FD8DE50FFD8EE8E4A8C194APH3PPFA3FE8A23F_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH3PPFA3FE8A23F.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: afd40e51-f834-4f77-b695-08de5a8012ba
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Jan 2026 13:05:24.9197 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: UG65Oh4jNv2t/O2VaFUrrYfPA09kAvGk46U49LVtPwaGcEMBCNrerTlS4ot59TTp7kYCJ0LMbzBtLepSLtx8Mw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH7PR11MB6355
X-Outbound-SMTP-Client: 72.163.7.162, rcdn-opgw-1.cisco.com
X-Outbound-Node: aer-l-core-09.cisco.com
Message-ID-Hash: XOJTJ2KP7XCMIBIW22XHFMPWCD5KSTXK
X-Message-ID-Hash: XOJTJ2KP7XCMIBIW22XHFMPWCD5KSTXK
X-MailFrom: sfluhrer@cisco.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ipsec.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [IPsec] Re: Call for adoption: draft-wang-ipsecme-hybrid-kem-ikev2-frodo-03 (Ends 2026-02-09)
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/KlS8BcyHDcwuGPplX972-NM04UU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Owner: <mailto:ipsec-owner@ietf.org>
List-Post: <mailto:ipsec@ietf.org>
List-Subscribe: <mailto:ipsec-join@ietf.org>
List-Unsubscribe: <mailto:ipsec-leave@ietf.org>
The option you suggest below of negotiating "NONE" as the first key exchange is (IMHO) Evil, and I would call for it to be rejected. If you want to do FrodoKEM only (and you don't have MTU concerns, either because you're going over TLS, or your L2 protocol has a large MTU size), then make FrodoKEM as your first (and only) key exchange - problem solved. ________________________________ From: Wang Guilin <Wang.Guilin=40huawei.com@dmarc.ietf.org> Sent: Friday, January 23, 2026 5:25 AM To: John Mattsson <john.mattsson@ericsson.com>; Wang Guilin <Wang.Guilin=40huawei.com@dmarc.ietf.org>; Ben S3 <ben.s3=40ncsc.gov.uk@dmarc.ietf.org>; Michael Richardson <mcr+ietf@sandelman.ca>; Thom Wiggers <thom@thomwiggers.nl>; ipsec@ietf.org <ipsec@ietf.org> Subject: [IPsec] Re: Call for adoption: draft-wang-ipsecme-hybrid-kem-ikev2-frodo-03 (Ends 2026-02-09) I see. But the draft is not restricting how implementations are using FrodoKEM. Instead, we are considering to expend the draft for running pure FrodoKEM over TLS, as suggested by Scott. This case is not covered in the current version 03. Also, I am think if we can run pure FrodoKEM (or any PQ KEM) in IKEv2 under the framework of RFC 9370 as follows. * In IKE_SA_INIT, KE payload includes NONE as the traditional KE. Note that NONE, no KE at all, has 0 as its KE Method Transform ID, according to the IANA IKEv2 parameters, https://www.iana.org/assignments/ikev2-parameters/ikev2-parameters.xhtml. * Later, run Intermediate exchange to exchange the public key and ciphertext of FrodoKEM via ADDKE, as specified by FRC 9370. * Namely, the means NONE+FrodoKEM=FrodoKEM. * Not sure if this works and is good in IKEv2 practice? Guilin From: John Mattsson <john.mattsson@ericsson.com> Sent: Friday, 23 January 2026 6:03 pm To: Wang Guilin <Wang.Guilin=40huawei.com@dmarc.ietf.org>; Ben S3 <ben.s3=40ncsc.gov.uk@dmarc.ietf.org>; Michael Richardson <mcr+ietf@sandelman.ca>; Thom Wiggers <thom@thomwiggers.nl>; ipsec@ietf.org Cc: Wang Guilin <Wang.Guilin@huawei.com> Subject: Re: [IPsec] Re: Call for adoption: draft-wang-ipsecme-hybrid-kem-ikev2-frodo-03 (Ends 2026-02-09) >- Still, the main part for our draft is about how to use FrodoKEM in hybrid way (traditional KE+FrodoKEM), though more PQ KEMs can be added by following RFC 9370. I disagree with this, I think the main part of IPSECME’s draft should be to register code points for FrodoKEM without restricting how implementations are using FrodoKEM. John From: Wang Guilin <Wang.Guilin=40huawei.com@dmarc.ietf.org<mailto:Wang.Guilin=40huawei.com@dmarc.ietf.org>> Date: Friday, 23 January 2026 at 10:12 To: Ben S3 <ben.s3=40ncsc.gov.uk@dmarc.ietf.org<mailto:ben.s3=40ncsc.gov.uk@dmarc.ietf.org>>, Michael Richardson <mcr+ietf@sandelman.ca<mailto:mcr+ietf@sandelman.ca>>, Thom Wiggers <thom@thomwiggers.nl<mailto:thom@thomwiggers.nl>>, ipsec@ietf.org<mailto:ipsec@ietf.org> <ipsec@ietf.org<mailto:ipsec@ietf.org>> Cc: Wang Guilin <Wang.Guilin@huawei.com<mailto:Wang.Guilin@huawei.com>> Subject: [IPsec] Re: Call for adoption: draft-wang-ipsecme-hybrid-kem-ikev2-frodo-03 (Ends 2026-02-09) Yes, this true. Also considering what a better name for our draft draft-wang-ipsecme-hybrid-kem-ikev2-frodo. And this may also indicate similar issue for draft-ietf-ipsecme-ikev2-mlkem. For draft-wang-ipsecme-hybrid-kem-ikev2-frodo-03: - Current title: "Post-quantum Hybrid Key Exchange in IKEv2 with FrodoKEM" - Michael Richardson: "Using FrodoKEM in Multiple IKEv2 Key Exchanges" - Thom Wiggers: “FrodoKEM for IKE_INTERMEDIATE IKEv2 Key Exchanges - Scott Fluhrer: No exact name suggested, but commented: "I would recommend that this draft should back off from assuming that Frodo can be used only in the "Classical+Frodo" combination." For me, I like the current one or that from Michael. A few reasons: - Still, the main part for our draft is about how to use FrodoKEM in hybrid way (traditional KE+FrodoKEM), though more PQ KEMs can be added by following RFC 9370. - The draft can describe how to run pure FrodoKEM over TLS, as Scott suggested. But this is a smaller case in the draft. - For my understanding, hybrid is more general than just T/PQ. It refers two or more crypto component algorithms are combined to achieve a security purpose. (Also, how to combine the component algorithms and how strong the resulting solution are further issues.) - RFC 9794 seems not giving definition for "hybrid", but mentions that it can be used for T/PQ (like hybrid KE defined by ETSI) or a more general concept (like hybrid KE defined by NIST). Details can be found in Section 1 of RFC 9794. draft-ietf-ipsecme-ikev2-mlkem: - Current title: "Post-quantum Hybrid Key Exchange with ML-KEM in the Internet Key Exchange Protocol Version 2 (IKEv2)" This WG document does specify how to use pure ML-KEM in IKEv2. Abstract tells "This draft specifies how to use ML-KEM by itself or as an additional key exchange in IKEv2 along with a traditional key exchange." Guilin -----Original Message----- From: Ben S3 <ben.s3=40ncsc.gov.uk@dmarc.ietf.org<mailto:ben.s3=40ncsc.gov.uk@dmarc.ietf.org>> Sent: Friday, 23 January 2026 4:12 pm To: Michael Richardson <mcr+ietf@sandelman.ca<mailto:mcr+ietf@sandelman.ca>>; Thom Wiggers <thom@thomwiggers.nl<mailto:thom@thomwiggers.nl>>; ipsec@ietf.org<mailto:ipsec@ietf.org> Subject: [IPsec] Re: Call for adoption: draft-wang-ipsecme-hybrid-kem-ikev2-frodo-03 (Ends 2026-02-09) OFFICIAL Without stating an opinion either way, I’ll note that the title of this draft is consistent with the title of draft-ietf-ipsecme-ikev2-mlkem, which also assumes hybrid. Of course, the solution here might be “change the name of the ML-KEM draft too”. Ben OFFICIAL -----Original Message----- From: Michael Richardson <mcr+ietf@sandelman.ca<mailto:mcr+ietf@sandelman.ca>> Sent: 22 January 2026 21:07 To: Thom Wiggers <thom@thomwiggers.nl<mailto:thom@thomwiggers.nl>>; ipsec@ietf.org<mailto:ipsec@ietf.org> Subject: [IPsec] Re: Call for adoption: draft-wang-ipsecme-hybrid-kem-ikev2-frodo-03 (Ends 2026-02-09) Thom Wiggers <thom@thomwiggers.nl<mailto:thom@thomwiggers.nl>> wrote: > Title: > I do strongly feel that “hybrid” should be removed from the title of > the draft, because I think it will lead to confusion on what this draft > achieves in terms of security. Namely, “hybrid” commonly means PQ/T > hybrids, but this draft can be used perfectly fine with ML-KEM-512 in > the IKE_SA_INIT key exchange. While I do agree that this would still > give us a (PQ/PQ) “hybrid”, I don’t think that this matches > expectations surrounding the word “hybrid”. I agree strongly. RFC9370 defines multiple key exchanges, so linking it in that way makes more sense. > I don’t think “hybrid” adds much either, other than (to experts) > hinting that this needs to be done in IKE_INTERMEDIATE exchanges. So if > that is the intended message, I suggest renaming the draft to something > like “FrodoKEM for IKE_INTERMEDIATE IKEv2 Key Exchanges”. Or, maybe "Using FrodoKEM in Multiple IKEv2 Key Exchanges" -- Michael Richardson <mcr+IETF@sandelman.ca<mailto:mcr+IETF@sandelman.ca>> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ IPsec mailing list -- ipsec@ietf.org<mailto:ipsec@ietf.org> To unsubscribe send an email to ipsec-leave@ietf.org<mailto:ipsec-leave@ietf.org> _______________________________________________ IPsec mailing list -- ipsec@ietf.org<mailto:ipsec@ietf.org> To unsubscribe send an email to ipsec-leave@ietf.org<mailto:ipsec-leave@ietf.org>
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… chenmeiling@chinamobile.com
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Call for adoption: draft-wang-ipsecme-hyb… Tero Kivinen via Datatracker
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… tirumal reddy
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Antony Antony
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Liuchunchi(Peter)
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Steffen Klassert
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Jun Hu (Nokia)
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Tobias Brunner
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Michael Richardson
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Thom Wiggers
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… John Mattsson
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Scott Fluhrer (sfluhrer)
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… John Mattsson
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Michael Richardson
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Ben S3
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… John Mattsson
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… John Mattsson
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Scott Fluhrer (sfluhrer)
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Wang Guilin
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Michael Richardson
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Loganaden Velvindron
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… tirumal reddy
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Marc Penninga
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Panwei (William)
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Michael Richardson
- [IPsec] Re: Call for adoption: draft-wang-ipsecme… Jean-Michel Combes