[IPsec] Re: FW: New Version Notification for draft-sfluhrer-ipsecme-ikev2-mldsa-00.txt

"Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com> Mon, 10 February 2025 21:17 UTC

Return-Path: <sfluhrer@cisco.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 01BE8C1519A7 for <ipsec@ietfa.amsl.com>; Mon, 10 Feb 2025 13:17:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.741
X-Spam-Level:
X-Spam-Status: No, score=-9.741 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.148, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, T_SPF_HELO_PERMERROR=0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qIIvJQMzWmib for <ipsec@ietfa.amsl.com>; Mon, 10 Feb 2025 13:17:03 -0800 (PST)
Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C6186C15199C for <ipsec@ietf.org>; Mon, 10 Feb 2025 13:17:03 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=14974; q=dns/txt; s=iport; t=1739222223; x=1740431823; h=from:to:subject:date:message-id:references:in-reply-to: mime-version; bh=M4PbNO4Ko3rvVDeb8CtV2ZP4X+uasMKt62KXk7Sr7Ak=; b=AXoWaSSsg8Adq4yPRXBrlhMYxg6AEkldnFZdBrbTZSimanDFZqnrgwJP MAzj1OLFNZLvKdPoqJe6qCIclLDSJkGTJ8ihYecVXw/xm4pJxzlyaeAik tfl56nn/GVZMpqqKQlBLpP6YvNTWNqTVvlmuSfMLR1cR5yPTqSCUAQYTW g=;
X-CSE-ConnectionGUID: pi0Gk+AhRSWy/sGvIsHu2w==
X-CSE-MsgGUID: 2UrCnH9eS7KDGkw6r6l/QA==
X-IPAS-Result: A0A2AADua6pn/4oQJK1aHAEBAQEBAQcBARIBAQQEAQFlgRoHAQELAYFAMVIHdoEcSAOEUoNMA4ROX4ZTgiEDkUeFeIZVFIERA1YPAQEBDQI7CQQBAYUHAhaKbgImNAkOAQIEAQEBAQMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOFew2GWgEBAQEDEhEKISAJDgQCAQgRAwEBASgDAgICLgEUCQgCBAEHCwgVBAGCYYIcSAMBEAakMQGBQAKKK3qBMoEBg2xB228GgUgBiE4BKoEyAg6Df4R3JxuBSUSBFUKCaD6CYQEBAQEBgSgBEgEjFQkWgyU6gi8EggMRBBdgYC4BgQoCAgICAgICAgICAgICAoENJWeCAIIHAggDgWdQEnWBRIEKghQGKYEGgw+EWoErcXUBgSwCAQQ9aQaBIYckUnUiAyYzLAFVExcLBwWBKRA4Ayo2MSOBIwU0Cjc5AYINaUk6Ag0CNYIeJFiCK4IggjuBOoMJXi8DAwMDgzKCQ1GCRIISdGwDAxYTgyF4HIRSHUADC209NwYOGwUEgTUFnQc/NgE8g0+BMARRAhRsGC1iBQYLOpZbi05HoyQKhBuMGJVkF4QDpWlmmHwigjaLLJUqPQSFFQIEAgQFAg8BAQaBZzxpcHAVGiGCZ1IZD45ZiFXAP3gCAQsuAgcBCgEBAwmSIQEB
IronPort-PHdr: A9a23:LgulQB2PvZeO0jr7smDPmlBlVkEcU/3cJAUZ7N8gk71RN//l9JX5N 0uZ7vJo3xfFXoTevupNkPGe87vhVmoJ/YubvTgcfYZNWR4IhYRenwEpDMOfT0yuBPXrdCc9W s9FUTdY
IronPort-Data: A9a23:j6M/86kyCJd85B/B81bGh17o5gzHJ0RdPkR7XQ2eYbSJt1+Wr1Gzt xIYWm/TO/zbMzP9KNh1bIrj/UgF7MKHmIdlSlM6/31nEVtH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaC4E/rav658CEUOZigHtLUEPTDNj16WThqQSIgjQMLs+Mii+aEu/Dha++2k Y20+pa31GONgWYubzpOsvrb8nuDgdyr0N8mlg1mDRx0lAe2e0k9VPo3Oay3Jn3kdYhYdsbSb /rD1ryw4lTC9B4rDN6/+p6jGqHdauePVeQmoiM+t5mK2nCulARrukoIHKZ0hXNsttm8t4sZJ OOhGnCHYVxB0qXkwIzxWvTDes10FfUuFLTveRBTvSEPpqHLWyOE/hlgMK05FZUZosl0QkhOz 8cnOXcWQQ6inMKrmq3uH4GAhux7RCXqFIobvnclyXTSCuwrBMiaBa7L/tRfmjw3g6iiH96HO JFfMmQpNUqGOkYfUrsUIMpWcOOAnXf7bj1CpUi9rqss6G+Vxwt0uFToGIaPKoPXGpQIxy50o Eqcwn7SBDFLOefA6haq8W3ynLHL2hrSDdd6+LqQs6QCbEeo7m0LExAdfVq2vff/jVSxM++zM GQd/i4o6Kx3/0uxQ5ylBluzoWWPuVgXXN84//AG1TxhA5H8um6xLmMFVTVGLtchsacLqfYCj DdlQ/uB6eRTjYCo
IronPort-HdrOrdr: A9a23:M7tn3ayZD18+JHhcwaMKKrPxfugkLtp133Aq2lEZdPULSL36qy n+ppQmPEHP6Qr5AEtQ5uxoWJPtfZquz+8K3WBxB8buYOCIghrSEGgP1/qH/9SkIVyDygc/79 YtT0EdMqyLMbESt6+Ti2fIcadE/DDEytHUuQ609QYKcegeUdAZ0+4PMHfjLqQZfnggObMJUL Cnyo5soT2mdX4LbsK9KEUkcoH4zeHjpdbNWzJDIwQoxjWvoFqThYISFSL24j4uFxd0hZsy+2 nMlAL0oo+5teug9xPa32jPq7xLhdrI0LJ4dYKxo/lQDg+pphejZYxnVbHHlisyuvuT5FEjl8 SJiws8Pv5092jacgiO0FrQMkjboXYTAk3ZuB2laEjY0InErfUBeo58bLdiA1jkAowbzZZBOe xwriSkXtFsfGL9dWzGlqj1vldR5wWJSb5Iq59Ks5SZOrFuMYN5vMgR+lhYH4wHGz+/4Ic7EP N2BMWZ//pOd0iGBkqp9lWH7ebcKEjbJC32C3Qqq4iQyXxbjXp5x0wXyIgWmWoB7os0T91B6/ 7fOqplmblSRotOBJgNTtspUI+yECjAUBjMOGWdLRDuE7wGIWvEr9ry7K8u7O+ndZQUxN85mY jHUllfqWkuEnieQvGmzdlO6FTAUW+9VTPixoVX4IV4oKT1QP7xPSiKWDkV4rydSjUkc7nmst qISedr6qXYXBjT8K5yrn/DZ6U=
X-Talos-CUID: 9a23:UPxnjGjxlmQOgdZrhgP5aJq38TJuanyF43STCk+CMll4D6a6V36L2L4+jJ87
X-Talos-MUID: 9a23:/lIDVwUHdy7RIhjq/GXRnhpkFJZl2PuNJG8Ojssc5c3DDAUlbg==
X-IronPort-Anti-Spam-Filtered: true
Received: from alln-l-core-01.cisco.com ([173.36.16.138]) by alln-iport-7.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 10 Feb 2025 21:17:02 +0000
Received: from rcdn-opgw-3.cisco.com (rcdn-opgw-3.cisco.com [72.163.7.164]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-01.cisco.com (Postfix) with ESMTPS id C33F6180001A1 for <ipsec@ietf.org>; Mon, 10 Feb 2025 21:17:02 +0000 (GMT)
X-CSE-ConnectionGUID: npPckWMiTweSz026FMjHRQ==
X-CSE-MsgGUID: Wt1xGXQLQOGsF4qaCEQTMA==
Authentication-Results: rcdn-opgw-3.cisco.com; dkim=pass (signature verified) header.i=@cisco.com
X-IronPort-AV: E=Sophos;i="6.13,275,1732579200"; d="scan'208,217";a="32430453"
Received: from mail-co1nam11lp2174.outbound.protection.outlook.com (HELO NAM11-CO1-obe.outbound.protection.outlook.com) ([104.47.56.174]) by rcdn-opgw-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 10 Feb 2025 21:17:02 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=slJ/kJ1RErZ0oBVkywOti4dJK1/DS/B0zhOT4DqJedl8Z++NzmFjwfIoedZpkqKgQKsRrdg1EQpKKZJSsLrNd/sc2nuLt0n1DIA5b1uoMf7jlzzmHoAHz7d5KxcdURmMneOruyTBUsBzGzIa7DHavv/TSXbUlBYaRELI22oeCo3y0QvORtdJuoiK8JK+WSopUQIiQ5ZWBuCYnV9xl/WDeiTwEBlNsSifQyL0mNJQSjiOyOQeorLuBTE4Q1weEZSIp0BZ/UjNzpa3g9DEuDIkjRDKYJ9zcNzFMm4yzrPdOQRrVk2DmgAPtL/9xIYoEPk4rT6r6X0syumC/ftoWnDD+g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=M4PbNO4Ko3rvVDeb8CtV2ZP4X+uasMKt62KXk7Sr7Ak=; b=Qq3KOTXmGiv1bopqHXe2XFE0NCAIch1X47UYOrn2QpQZmhi/3pHf1mVHfthsoPZcxLJ3FbeOGVSQ9vaStvS590orvVfvQLKu2KxaPdOtZwD+pnZTCsXcBKXE7eR8CEuDvMrkTmmQ7dg4YeHcUE9JVlgX+o31reCLHtG5DMjH5nUIwMj08gbEQJOzNkOG2GeIUJEZVAZO8MKFm0+KZgmMV2Gs6qg3vL2bKeqjTmHUFuPX/rO/UFPMkpEd90Z8jbkgi/JNHCp7Ph3pxvO5XPzsNWEqhMFek5cRpnmPEl6SqT8MiEg2LMHX5QCupI5eEK3Oo2PY9qOS4dCL/iS6lQhmGw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from CH0PR11MB5444.namprd11.prod.outlook.com (2603:10b6:610:d3::13) by PH7PR11MB6676.namprd11.prod.outlook.com (2603:10b6:510:1ae::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8422.16; Mon, 10 Feb 2025 21:16:59 +0000
Received: from CH0PR11MB5444.namprd11.prod.outlook.com ([fe80::5f89:ba81:ff70:bace]) by CH0PR11MB5444.namprd11.prod.outlook.com ([fe80::5f89:ba81:ff70:bace%3]) with mapi id 15.20.8422.015; Mon, 10 Feb 2025 21:16:59 +0000
From: "Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com>
To: Daniel Van Geest <daniel.vangeest=40cryptonext-security.com@dmarc.ietf.org>, "ipsec@ietf.org" <ipsec@ietf.org>
Thread-Topic: [IPsec] FW: New Version Notification for draft-sfluhrer-ipsecme-ikev2-mldsa-00.txt
Thread-Index: AQHbdBKWyaMv1Nyjd0CdfV7Uih2oKLMxRzMQgA984gCAAFWHEA==
Date: Mon, 10 Feb 2025 21:16:59 +0000
Message-ID: <CH0PR11MB5444354D8BDF3A1081819F90C1F22@CH0PR11MB5444.namprd11.prod.outlook.com>
References: <173835008260.58904.3312254574955629084@dt-datatracker-6f7f8bdd64-4ngzm> <CH0PR11MB5444CA907AA74178925254C7C1E82@CH0PR11MB5444.namprd11.prod.outlook.com> <bebb222b-7a35-43f1-aaf9-c3be4ed742a2@cryptonext-security.com>
In-Reply-To: <bebb222b-7a35-43f1-aaf9-c3be4ed742a2@cryptonext-security.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CH0PR11MB5444:EE_|PH7PR11MB6676:EE_
x-ms-office365-filtering-correlation-id: 4937a891-cdb9-4187-17df-08dd4a1841af
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|4022899009|376014|10070799003|366016|8096899003|7053199007|13003099007|38070700018;
x-microsoft-antispam-message-info: oa0yEINLuqbE0CQNEr6HhaWRFLb4iiRIam45zIx1wh792XBBRqn8/i6gj/4HOYFiDO5k/rz/xpZqR26EEm2KPXiRbkv4S3ImlS8xPjNf6IKaACd3RRsaGcYIBYB4edOVpGgCpV1FWs/TAtT36qw9HREGVS4lkjEAwAQwra/9MRSKa1dCVRmPxanL27d6wNjrMfsyj1fpfJRRfUxxJx2v+0q0QGX2FCPXJ9Y/pi0SaoTPW6Y7C3w0jNFpf1xdAlA9FNcbKRzFW8pu8Mua4++0HmjiirSN3/CuDtKcVMt1eEJoMYk4xSZ3SseRxUEb0DC2w9t0I/Rar62e9r+htbxqlnhkXOhdbeOlFNweNxWnS+kuMHZ+xm6532KlHvrVBA53gY6t+HZu1DQHdrjGZtz7ep2BxfT8b9phQqk7HnLuIPvDP6SvlmV7NkbLhLAND+ZsHPkz7mcj+TBlfDFZNt1QdJXUKrCYs2gF8YB0fFi6AyD6lBBUIICxIKRHe+OElrk1cW726SbLHg0KYjU2JqOJcgy9e+jmQUBqszA63AUg4QNy6Yy6Bjqya24Q/y8IIPnSy6CCZtIuOMz6Ph3jol+rPOPmx0iZZ4BW3xidiZtOJXTpLU8JOhlRONMnp3ec7mX+/+lfbXDaigtb8p3saDQLjEeoToiblWi8cKqEUfF8jHuK/n3EeLQvjUX9t0avGbl0Nx87dMy8leP15LeOMFLw+NMrTa6YAyc9v0Wal5wsUkQ0/pxj2dsphGSI1MwC56AllL6WZNCuB0VLlbpTsQgJBjZb0M+6hCliFMBgcuTvLuBhOn2Wp4zJTPdMQJDH8P4fJ1zhJufTvt92lpKIEsVaAzYb1UZ45U7qSadrWJ3fIxFnW38pOGKSUdd6kjBJ02K4lRxQzMdM6tLwWDGE4wxWulE/48cfUBEXEX9eQ2eOnrUrDl9MZobm3oMfiEntG779MMzvkTFJ37cLkkmZcMahRgPIvo4Ff8MX5PwiVzi7JmZNsi4O4844T1djrO3x1uWJAcZlNwNhpk0BBK1vkIiuzkuEQWDUVxH033pmjK1+mjZlUOJhKf5FehuCVHaOLvHdDLN0XUh1wZiRe2lbjTywGvkW72Kx4xeJ6q/gPb1zzgiq6Qc6WL+74x83CaDY8oCPGsr9xXi6y7qeePvTWFvjMLddM1frQOlIzTMXpnzs7tmveBozhs+iNlLraIMplnWt3+pVq3ISKNSgp2kti7omkno6WqFPcwz2BsQc9XGHW5uIQD/L65FwnMk6aa3lSIT1yvxni4tEjRBMr3LYyyfm6hLoV/I55ZY7ixiYtHzUZlODoDj5ghiENFcauMYsKbggcmNKi60ZNUMsXP9H6b24VTW18bJAgJppTHkq4D30XKJRQad5rR6B5hV79Jy7y+X1t8le7ETKgJEA1iuh+05XjATIApGDX/+ukeX9dU1dgkoAPsLxYG3iH0M0uhUOiROx
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:CH0PR11MB5444.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(4022899009)(376014)(10070799003)(366016)(8096899003)(7053199007)(13003099007)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: /jtDKxJ5U2A78+eJJcw0KjlhpJnvzHfDqCKh1R9PAAoHZTRo57iYUf/citQF4i8DDKEIIIsCDixCAZywiAh0Bjfn8em+I2LQDluLPXsBBVcJEdij7YssKBOaczepy85SyHSdaMToHC+idlBhNXFXScmq5ukZ9y3zWj0WJ39/usvKmt7DY3PnoJTlipsvqvihP5MhAVVL2lHvS8EPaGWFQkoeEEoDOs7/2EB501Xqvl9dhndGz9dxcEqkz2kqVLgqiIggJ14PeO9l2hFXOjr9n1bkgtOSYOtAcGtgGkRrxjKKvrY0NRtBq5+4PyKnBpEgGIFBuKslWwSJaKBZ0vwNaHr9L7go7zp6aMYKnciWUabNtnGEDOX/nS3MCyIju9CpuJeUSHvN0QoxahvcahszzTRrpf7qED4MS291qX6bEC07c39KWBba3trt60hnPmIphLWKo0RPVy/BPNNeHrUwKIGghl5BZoBH4c3IKrze9dNILAgLuG6XCCpoVdi5tgwBP5w+lEVV1n2nnxpqUS35nHDLJPTsoat0iJE7AxhnMbjr19j/mHAaT8IjvFYr6zFd+4DugbZyxOvnLly9GDhfMWyWaoFqPQ9xBEb5wcqlbcEawOaWXAkaSikFZ8A+npuJ1Mh/W+k3UmyOjilxA437hn16MB4yXP4sW4U4hTa/D+uPmKhZiJD6NfEhNjL1eacZg1rZRtAmoWZ9Ib+f0bopzIDWW+FzrwwrJJZs5bIDJXTyHZkSwknSLh7gswFkrNKAATn9iZRRc72pZf4Ydgn1yE1lC7SLhuEGFhAhLutuZjAY89Z6F0EfclKVXxqWHgXUwW9Hw1USRcr1RVQczzchEO3CTLQXWAxy7E9nepAyFAYQXG1243qR8IrvfaNqwtDyB7vDFGnf4h3FvGIDEMTF4QMW28N26H7Thyvt9D4MIny8VhRYO6baYsuXb2S7PylSnIN1QG50rv94VIdCJuvBinK4+qHtrVKkDXWokn32lLWFNSk631EcVAGiXPJc41CowGeDZWu5VXjQpZ+nURjr0v4u7pPt04f0OLLtuJaMHtv0UP5tXerg2M2cHmW9Tgs+VbP7MAuvOY3zyJk2ao3cpUXolV6ocWKqWOllnrAeh4Duyai1qjdPw3k6c4RUi/tzQnE4eG3IorYCAThi6CGpzBIU3DEkJZZlTnjq7gfsIxI19LRhEo3vJFHsr35Cv/iyeecIdG8ycKk3JrryP5zfNvKgIffbI0UgmdTpyzXyLYsrmgvesW6P5pvasMi5o+GP32HNATPMXMGpAwKrpj0OL44lAevTSAmNipOh2mzVsfSm3+0jvPb72WSKEHAeVLLoN14OrhVpktoT1Tp4G+nESW1+RYw2invqZt2UoG7y3U9bsS/Cm/oLOwUQ8ebyDKY0uVEIFdowu22I1CfD2TQPXwgH3pkfKqoQX+eME43v0/xd0n7s2lYG5dic0Kual/Nv9dcLmXXPogIZbc7yQ89PeRF5PYJl8xZ7CEiDTc2t0mmLj+wjp4GZUtWFlpyoVjDbARKy47f+KZVQvd/lkZvukeBua82HZ1M4r9gWlih23UMqR6lAp5vyFctUTju0X0nnVmfskoyBYq7O0EQtoKWyzIB+QnEVrV5bvJgMHDKPyf0=
Content-Type: multipart/alternative; boundary="_000_CH0PR11MB5444354D8BDF3A1081819F90C1F22CH0PR11MB5444namp_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CH0PR11MB5444.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 4937a891-cdb9-4187-17df-08dd4a1841af
X-MS-Exchange-CrossTenant-originalarrivaltime: 10 Feb 2025 21:16:59.8032 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: wCJTmFFGVHlKt0K/e9ZetYntd2zJD6SI0coEyNTRdzJ5CbzTm9rKomRH3Q+/FBwKpJmLg++ZIEdtJeCV7MjEWQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH7PR11MB6676
X-Outbound-SMTP-Client: 72.163.7.164, rcdn-opgw-3.cisco.com
X-Outbound-Node: alln-l-core-01.cisco.com
Message-ID-Hash: R2KYZVVYBWWAOOWR6TRIVZJYRJEXU7WG
X-Message-ID-Hash: R2KYZVVYBWWAOOWR6TRIVZJYRJEXU7WG
X-MailFrom: sfluhrer@cisco.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ipsec.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [IPsec] Re: FW: New Version Notification for draft-sfluhrer-ipsecme-ikev2-mldsa-00.txt
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/w8YvU191Fm4SxGvofW20chGFKtc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Owner: <mailto:ipsec-owner@ietf.org>
List-Post: <mailto:ipsec@ietf.org>
List-Subscribe: <mailto:ipsec-join@ietf.org>
List-Unsubscribe: <mailto:ipsec-leave@ietf.org>

I’ve already pulled in the changes into draft-reddy-ipsecme-ikev2-pqc-auth (at least, the one in github – that update will be published Real Soon Now).

Except, one of my coauthors preferred the RFC8420 approach and no one else (including me) had an opinion, so that’s what we’ll be doing for now…


From: Daniel Van Geest <daniel.vangeest=40cryptonext-security.com@dmarc.ietf.org>
Sent: Monday, February 10, 2025 11:09 AM
To: Scott Fluhrer (sfluhrer) <sfluhrer@cisco.com>; ipsec@ietf.org
Subject: Re: [IPsec] FW: New Version Notification for draft-sfluhrer-ipsecme-ikev2-mldsa-00.txt


I support this work, but there is already a draft specifying both ML-DSA and SLH-DSA in IKEv2: https://datatracker.ietf.org/doc/draft-reddy-ipsecme-ikev2-pqc-auth/

Scott, as you're an author on both you'll have no problem reconciling the two drafts :)

Regards,
Daniel
On 2025-01-31 7:40 p.m., Scott Fluhrer (sfluhrer) wrote:

I just noticed that IKE was missing a draft to how to support pure (ML-DSA only) PQ authentication, so I threw this together.



Any comments are fine (and I expect them to range from "this is completely stupid" to "this is mostly stupid, but it might be salvageable")



-----Original Message-----

From: internet-drafts@ietf.org<mailto:internet-drafts@ietf.org> <internet-drafts@ietf.org><mailto:internet-drafts@ietf.org>

Sent: Friday, January 31, 2025 2:01 PM

To: Scott Fluhrer (sfluhrer) <sfluhrer@cisco.com><mailto:sfluhrer@cisco.com>

Subject: New Version Notification for draft-sfluhrer-ipsecme-ikev2-mldsa-00.txt



A new version of Internet-Draft draft-sfluhrer-ipsecme-ikev2-mldsa-00.txt has been successfully submitted by Scott Fluhrer and posted to the IETF repository.



Name:     draft-sfluhrer-ipsecme-ikev2-mldsa

Revision: 00

Title:    IKEv2 Support of ML-DSA

Date:     2025-01-31

Group:    Individual Submission

Pages:    8

URL:      https://www.ietf.org/archive/id/draft-sfluhrer-ipsecme-ikev2-mldsa-00.txt

Status:   https://datatracker.ietf.org/doc/draft-sfluhrer-ipsecme-ikev2-mldsa/

HTML:     https://www.ietf.org/archive/id/draft-sfluhrer-ipsecme-ikev2-mldsa-00.html

HTMLized: https://datatracker.ietf.org/doc/html/draft-sfluhrer-ipsecme-ikev2-mldsa





Abstract:



   One IPsec area that would be impacted by Cryptographically Relevant

   Quantum Computer (CRQC) is IKEv2 authentication based on traditional

   asymmetric cryptograph algorithms: e.g RSA, ECDSA; which are widely

   deployed authentication options of IKEv2.  NIST has recently

   standardized ML-DSA, which is a signature algorithm believed to be

   secure against Quantum Computers.  This document describes how to use

   ML-DSA with IKEv2 as an auhentication scheme.







The IETF Secretariat





_______________________________________________

IPsec mailing list -- ipsec@ietf.org<mailto:ipsec@ietf.org>

To unsubscribe send an email to ipsec-leave@ietf.org<mailto:ipsec-leave@ietf.org>