[km-fs-pcs] Re: DRAFT BOF Request

Carlos Aguilar Melchor <carlos.aguilar.1998@polytechnique.org> Fri, 22 May 2026 08:22 UTC

Return-Path: <carlos.aguilar.1998@polytechnique.org>
X-Original-To: km-fs-pcs@mail2.ietf.org
Delivered-To: km-fs-pcs@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 21E22F3111A5 for <km-fs-pcs@mail2.ietf.org>; Fri, 22 May 2026 01:22:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779438164; bh=k07zST/RHx0VtRcpXZ4nB6FRhF6pyeuK/Ocjb7om644=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=bTL057O+bfsI9gyNuvW/URn46dj0JAmrZzDLwBNT0d2V0261a+CaCL6nxpym4FkXN S3RLdIS1NHWBjlXPEWqyUx5TgXCB2ZADMCG29VmlG/J3jpxE2P4j+TctTqGS+Xx973 g2yVJHua/nzqagcl98jdPaoSbZZ2XtnlRP5Eb7Is=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=polytechnique.org
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DQRgApOhCpEH for <km-fs-pcs@mail2.ietf.org>; Fri, 22 May 2026 01:22:42 -0700 (PDT)
Received: from mail-pj1-x102e.google.com (mail-pj1-x102e.google.com [IPv6:2607:f8b0:4864:20::102e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4B5B8F3110F2 for <km-fs-pcs@ietf.org>; Fri, 22 May 2026 01:22:07 -0700 (PDT)
Received: by mail-pj1-x102e.google.com with SMTP id 98e67ed59e1d1-36643b96b99so6551200a91.0 for <km-fs-pcs@ietf.org>; Fri, 22 May 2026 01:22:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1779438127; cv=none; d=google.com; s=arc-20240605; b=S/vO480ZcJ+6J2wyTrax+eG+6tuK9g2IsJ4k2238DlFu2JUMi9PpMoIak0Db2+fTD4 vqu1OVZuOaPg3Bbz1KTQdpRI/HNbJ9V8emugLhFmZYPMxWo++Ot65Zysea22rZjHDssD 4tABOJwBeBImJik8OwoXhBwiUdCulU7YI7WcE7lHDhkfAEiVyNdjstrVsO+T6SwHsxZ5 vMcl9ef65eqPlEa/KBPwNlApsYKT3tktNa6M76qi+WLfOQLvMgG4OhfI7NBxI9oSw3Bu F4M25RW9MQbiQ7XUqq+Im7vNd6vrg66GK6YcUf/uzgRtuhcUptgAmZftZlai/oX4l2QZ cuqQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=E5q54Z1KPIILpotYjXrlKZxx8pN7uqVLokxbsEjTDOo=; fh=+GiWIy3SpO8FdEG+yKaNr5tYCv9y3gJr3dz2X0/6yNc=; b=dZM+bhIQlPsUgI+DF+YQWMAs9UzpmbwhjIeeWOXAQ1KynJwEYT6A0wUi3K/A34cuTh 0qUCGQWt/RJEY8mBt2EGzPfkPL4hcqVmQpkSzpWVQkCmg6wjUjQ+5DB3ZcnNHm5UKqs+ UtTYCyrE2qhsya/l4Wb7YTj9aDVgSBVhP6RW+AAIeFckEzciMt3MVLqHFemN1sCPiBuD itVvVr0abO93ZLuVUxWs3qI3L+/5tAgU1EYQYRPQeinq/fO4/Cor2NqQ2smgAKlcV/QH T4NKsIeIKM/xweG53fWDFkpXeG93kY2+mT6RDbd9+NBOdNjeGFaQC3vfDZZcrLd1uNzN QmhA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=polytechnique.org; s=gapps; t=1779438127; x=1780042927; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=E5q54Z1KPIILpotYjXrlKZxx8pN7uqVLokxbsEjTDOo=; b=B38QCVuILhx+UEj3clylQ79tCJgsj+HkduBjVx9bg02dU3LcF/T+2sjIsVuGDWuodM m6e4wrh9/FOLvr5KenBmUZjlBiW86BvkMXlSjWj+A0icsGEwavYqmdcUHnZ0pICPcj20 FQpTXHaeMWLzB1Gr5tzC0da2WGHNP/J71CMJM=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779438127; x=1780042927; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=E5q54Z1KPIILpotYjXrlKZxx8pN7uqVLokxbsEjTDOo=; b=EvLDW2mIGc0aVtnakknY54I4+Va5/68/JSqxgCYQ3bHhgIRtkpkeXq6XwWvFPePsX0 5eDkXY9HkAOPdXWYqz1qjgVZE4ztlVa0CbdrTXBMpyTeb+HNZ7BYGNHWGJmnmur9WgCf 3uyDqdxghsLboD8t5RX1st0l7nAvC+23T7GFdRRXA9K5pJ+wx4S/tpvCpL8uOIsZrcxt /swbfi7KBraojZlmkiUdTe/wCy+1sxc/idncL9M1EM6YPIYFmTvY46hcfKrS++pMngin ZxlpjjPFqsjkF/fEdmd8nU2kQMdBW39ZuOeiFe6aYPtVhAYLn3S/1eUgU7NsogIYVeq/ ytKA==
X-Gm-Message-State: AOJu0YzODgj0gLoUHHqHsScoQwdyVlXKg5AtwxSX7a1XgOgTeucfNOvu kHQx3DRXVM8og5CfmKzPOpy3VtIuyhwnuY5kNrFIe4Kr4Qn45J09w2mm11piuVCG8q14hbKDI5H XDPtCFNKho5VDfhBQ11hYSYMlXCRSnjS78oaV3Jv3e0Jkma1iqDBh
X-Gm-Gg: Acq92OFw1IJps3GokGf1H5LutWzDOWocGSJlLfwtgBHX0AdghentQ8t8x2hm38gymQe 62IurQ8n9owvzfLH+TBVU9Xe0gRVV55/5ioZE1HLyqq0/E/rA5XMjg9IrMqH7BhFXGvf6sK12kD MdDXQlPsd7/F4gCGM9MQiEcBddEtn+RVCPKYon+ONO5vSf9Ra4WlxNBbSsgv6p3+dI+GnIxojHY pa26HsTqMILFzcSd1cJM8vULkAe1yBZXyYYpZsSJizgiL+CSWjDZQko+e+D4LGaye52juo7METB MOP+FogEnGtHJkKCSig5wiNLrauV1kN0neYdYdQ=
X-Received: by 2002:a17:903:24c:b0:2b2:4bf9:1766 with SMTP id d9443c01a7336-2beb06cb229mr26531825ad.33.1779438126915; Fri, 22 May 2026 01:22:06 -0700 (PDT)
MIME-Version: 1.0
References: <FF0C4275-FF7B-4D21-98F4-1D4C1B9A2F91@vigilsec.com> <82346D00-9D5D-4564-BE84-1ACEE7627CFF@vigilsec.com>
In-Reply-To: <82346D00-9D5D-4564-BE84-1ACEE7627CFF@vigilsec.com>
From: Carlos Aguilar Melchor <carlos.aguilar.1998@polytechnique.org>
Date: Fri, 22 May 2026 10:21:55 +0200
X-Gm-Features: AVHnY4JnD82BJqqKb_XWliz-EYhbpBlfIa4gHBIsyuWKWW3SqBaX3cPDhhIltbM
Message-ID: <CAMYgedkE8PTLnZn3nk3gEV862gezQV_aiT5KhD5fNWroxvpL2w@mail.gmail.com>
To: Russ Housley <housley@vigilsec.com>
Content-Type: multipart/alternative; boundary="000000000000747058065263b9ea"
Message-ID-Hash: WQSQBMLDX4ZA2Z2L52PTE7HEZ2I3JPL7
X-Message-ID-Hash: WQSQBMLDX4ZA2Z2L52PTE7HEZ2I3JPL7
X-MailFrom: carlos.aguilar.1998@polytechnique.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: km-fs-pcs@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [km-fs-pcs] Re: DRAFT BOF Request
List-Id: Key management that provides forward security and post compromise security <km-fs-pcs.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/km-fs-pcs/jabZJCJQ-B-L3jFhx-syx_GdA80>
List-Archive: <https://mailarchive.ietf.org/arch/browse/km-fs-pcs>
List-Help: <mailto:km-fs-pcs-request@ietf.org?subject=help>
List-Owner: <mailto:km-fs-pcs-owner@ietf.org>
List-Post: <mailto:km-fs-pcs@ietf.org>
List-Subscribe: <mailto:km-fs-pcs-join@ietf.org>
List-Unsubscribe: <mailto:km-fs-pcs-leave@ietf.org>

I would vote against it. I don't think there is consensus on what current
(or future) good property is the main reason for the group to exist. There
are many reasons to want MLS channels, not one:
  * membership integrity
  * PCS
  * Async handshakes and in general async nature of everything
  * log scaling
  * native agility
So explicitly putting one in the title will reduce focus unnecessarily.

BTW I would prefer MLS Channels to MLS Channel...

Carlos

On Thu, May 21, 2026 at 8:37 PM Russ Housley <housley@vigilsec.com> wrote:

> I got a comment off list.  The suggestion was for a more descriptive name,
> such as "Asynchronous Channel", "Flexible Transport Security", or similar.
> Thoughts?
>
> Russ
>
> > Name:  MLS Channel (mlschannel)
> >
> > Description
> >
> > Define a two-party protocol that uses MLS for the key management.  Once
> the key is established, the TLS Record protocol seems to meet the needs for
> protected traffic, so it will be used unless some unexpected shortcoming is
> discovered.
> >
> > MLS key management provides asynchronous key updates, forward secrecy
> (FS), and post-compromise security (PCS).  In addition, MLS supports
> asynchronous communication and both traditional cryptography and
> Post-Quantum Cryptography (PQC).  Further, the formal analysis tha was
> conducted on the MLS provides confidence in the design.
> >
> > Required Details
> >
> >   Status: WG forming
> >   Responsible AD: Deb Cooley
> >   BOF proponents:
> >
> > Russ Housley <housley@vigilsec.com>
> > Sean Turner <sean@sn3rd.com>
> > John Mattsson <john.mattsson@ericsson.com>
> > Raphael Robert <ietf@raphaelrobert.com>
> > Konrad Kohbrok <konrad.kohbrok@datashrine.de>
> > Xisen Tian <xisen.tian.mil@us.navy.mil>
> >
> >   Number of people expected to attend: 150
> >   Length of session (1 or usually 2 hours): 1 hour
> >   Conflicts (whole Areas and/or WGs)
> >   Chair Conflicts: lamps, sidrops, stir, rswg
> >   Technology Overlap: mls, ipsecme, tls, quic
> >   Key Participant Conflict: <same as BOF proponents above>
> >
> > Information for IAB/IESG
> >
> > To allow evaluation of your proposal, please include the following items:
> >
> >   Any protocols or practices that already exist in this space:
> >
> > There are suggestions for use of MLS key management with IPsec for
> multicast traffic (draft-kohbrok-ipsecme-mls-gike) and the use of MLS key
> management with QUIC (draft-tian-quic-quicmls).  This work has a home in
> the IPSECME and QUIC working groups, respectively.  However, the use of MLS
> key management with the TLS Record protocol does not fit in the TLS working
> group because it requires the replacement of the entire handshake.  This
> BOF is to find a home for this security protocol work.
> >
> >   Which (if any) modifications to existing protocols or practices are
> required:
> >
> > No.
> >
> >   Which (if any) entirely new protocols or practices are required:
> >
> > Yes.  A new protocol that runs on new port numbers is envisioned.
> >
> >   Open source projects (if any) implementing this work:
> >
> > One proof-of-concept project so far:
> https://github.com/phnx-im/mls-tls-protocol
> >
> > Agenda
> >
> > 1. What has happened since the SECDISPATCH presentation at IETF 125.
> > 2. Use Cases
> > 3. Draft charter
> >
> > Links to the mailing list, draft charter if any (for WG-forming BoF),
> relevant Internet-Drafts, etc.
> >
> >   Mailing List: https://www.ietf.org/mailman/listinfo/km-fs-pcs
> >   Draft charter: TBD
> >   Relevant Internet-Drafts:
> >
> > https://datatracker.ietf.org/doc/draft-kohbrok-mls-tls/
> > https://datatracker.ietf.org/doc/draft-kohbrok-mls-two-party-profile/
> > https://datatracker.ietf.org/doc/draft-housley-tls-using-mls-handshake/
> > https://datatracker.ietf.org/doc/draft-tian-quic-quicmls/
> > https://datatracker.ietf.org/doc/draft-kohbrok-ipsecme-mls-gike/
> > https://datatracker.ietf.org/doc/draft-liu-agent-protocol-over-moq/
>
> _______________________________________________
> km-fs-pcs mailing list -- km-fs-pcs@ietf.org
> To unsubscribe send an email to km-fs-pcs-leave@ietf.org
>