[km-fs-pcs] MLS-TLS: how to decrypt data sent immediately after a resumption request

Gaëtan Wattiau <gaetan.wattiau@proton.me> Tue, 30 June 2026 10:47 UTC

Return-Path: <gaetan.wattiau@proton.me>
X-Original-To: km-fs-pcs@mail2.ietf.org
Delivered-To: km-fs-pcs@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E669110AA47EC for <km-fs-pcs@mail2.ietf.org>; Tue, 30 Jun 2026 03:47:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782816447; bh=toi7BXFcM6sFvyBbPz3gEI4iGLOTEHGon5brnLPebkQ=; h=Date:To:From:Subject; b=LYn8I04sakmEFq2r7/u77dTLv057BnXIZXvsXAmYssjCvD2gcT5FVdNF94GYk62nO yu3Kws2ObBlUHOP6enK/vS/dZFrlZsHP/uxiYb21punHpx7G78S23Ob88hgZiqSXk5 6VSYf9tBL2fsvEGH11wFBAp/CPJlfuY+50G5goHE=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.538
X-Spam-Level:
X-Spam-Status: No, score=-2.538 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTML_OBFUSCATE_05_10=0.26, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=proton.me
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BWL7dNHfZm-F for <km-fs-pcs@mail2.ietf.org>; Tue, 30 Jun 2026 03:47:27 -0700 (PDT)
Received: from mail-24424.protonmail.ch (mail-24424.protonmail.ch [109.224.244.24]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id E94BC10AA47E4 for <km-fs-pcs@ietf.org>; Tue, 30 Jun 2026 03:47:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=proton.me; s=protonmail; t=1782816439; x=1783075639; bh=toi7BXFcM6sFvyBbPz3gEI4iGLOTEHGon5brnLPebkQ=; h=Date:To:From:Subject:Message-ID:Feedback-ID:From:To:Cc:Date: Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector; b=dtJZBb6xvsbJxLp/pBMeWJBfPaFreDf3zMXnlopcYmMJEjWpeGadBR8xrwrrMMnBS XyS5Hq50FILtcN8HhvhRTTjlv9ACs7ooSFgnhhKWyypNDX4dVY/DQse0flXZSrkUSp NEPxeFnayYSsh/zRPSp97pxegUTikfxmWRbgt4vcGwh0t45Xa8IxNwr1d+sQYYqe8V YAibTVwrH+NvPgAZ61oqj34ZRTyO0NboG2r+Ky7sZj+Mp+g53W4imD97p0p8ftBV05 gTvrhGb/31lNjo7rP8kLkRahEWW9xAS108eDV3/kxdNLqX5G2sa3gkfMlTDWogFl0a gCX92cePnp9cQ==
Date: Tue, 30 Jun 2026 10:47:13 +0000
To: "km-fs-pcs@ietf.org" <km-fs-pcs@ietf.org>
From: Gaëtan Wattiau <gaetan.wattiau@proton.me>
Message-ID: <qjb502lZsS16EYKIz501gln7vjNYb0h8QRWwxTLf8NFiw-J6jNHj7qsZ_FBUqRcySkZ1Ult_56qe4WdeLPwYQwe88X6AzhztAVniQYbcg9U=@proton.me>
Feedback-ID: 45733869:user:proton
X-Pm-Message-ID: 14e7503b2bfe89e7dcb82ad539dcd5dc02615b04
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="b1=_tlDLiNA2vhfLtRcqoMnk7im77M2iYxtnVwBWKaks"
Message-ID-Hash: SMC524EENDG773G5DUAQDZH5G2TAKE6S
X-Message-ID-Hash: SMC524EENDG773G5DUAQDZH5G2TAKE6S
X-MailFrom: gaetan.wattiau@proton.me
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [km-fs-pcs] MLS-TLS: how to decrypt data sent immediately after a resumption request
List-Id: Key management that provides forward security and post compromise security <km-fs-pcs.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/km-fs-pcs/lPeg4yr9xDAWGfHixx7bzcbUU_0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/km-fs-pcs>
List-Help: <mailto:km-fs-pcs-request@ietf.org?subject=help>
List-Owner: <mailto:km-fs-pcs-owner@ietf.org>
List-Post: <mailto:km-fs-pcs@ietf.org>
List-Subscribe: <mailto:km-fs-pcs-join@ietf.org>
List-Unsubscribe: <mailto:km-fs-pcs-leave@ietf.org>

Hello,

The MLS-TLS draft says the following:

> Resumption, where initiator or responder can resume a previously

> interrupted connection without having to repeat phase 1,

> including the ability to send data in the first flight of
> messages.

Does that mean the initiator of the resumption can send data without waiting for the ResumptionResponse​?

If that's the case, then it's unclear how the server is meant to decrypt those as it is meant to immediately apply the commit in the ResumptionRequest​ and then create and apply a commit sent back in the ResumptionResponse​:

> The responder receiving a ResumptionRequest MUST validate and apply
> the commit in the ResumptionRequest and create a commit with
> UpdatePath to send back as part of a ResumptionResponse.

(from MLS-2-party profile)

How is the Responder meant to decrypt the data sent by the initiator before the ResumptionResponse​ was processed?

Thanks,

Gaëtan