Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: spasm@mail2.ietf.org
Delivered-To: spasm@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1])
	by mail2.ietf.org (Postfix) with ESMTP id 7C3B64E28189;
	Thu, 31 Jul 2025 23:45:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.793
X-Spam-Level: 
X-Spam-Status: No, score=-2.793 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001,
	RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001,
	RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001,
	RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_NONE=0.001,
	UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key)
	header.d=orange.com
Received: from mail2.ietf.org ([166.84.6.31])
	by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 3lfUgCAiWI_Y; Thu, 31 Jul 2025 23:45:15 -0700 (PDT)
Received: from smtp-out.orange.com (smtp-out.orange.com [80.12.210.124])
	(using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by mail2.ietf.org (Postfix) with ESMTPS id D2DBE4E2817E;
	Thu, 31 Jul 2025 23:45:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
  d=orange.com; i=@orange.com; q=dns/txt; s=orange002;
  t=1754030715; x=1785566715;
  h=to:cc:subject:date:message-id:references:in-reply-to:
   mime-version:from;
  bh=DCpnniArIFrCs8JFLBP6WyyoZ7UG+tJhXwE9I5oGwys=;
  b=kD3+LCfYGlLpo57H8WdNopiyBlvGo+cddb2J1+Go9t5On3jZBflaNMTU
   L8avF43yqKpLrvac0T2Och1HjNfzsp1NWjB9mxWUFG7vx1XcSOJxHYBsq
   RxIipzbAxWNdupc4j2Welk/BP0g+4gneoI/XPgFNSi9vr+KLCXheise+W
   S/az52sdLYagC5xY7Fb+SLd6MFA0w8Nswli0bSy8cHk0AuRfcHNmSJWzC
   3FD5wf/rgtGtr9jGAgWwzjBoF8p+7y1edjb+1w4XiCEsQEprbZpR7Amhd
   uXQUG12ImubEoNm4XLUpKf2WniKcR5nvLEPQzUDsQeq4GKYyd3sn/QsWY
   w==;
X-CSE-ConnectionGUID: Z6P1/GE/SLiqHH0HXmffWQ==
X-CSE-MsgGUID: mAa7VnI0TcqFkK95O/Zo9g==
Received: from unknown (HELO opfedv3rlp0e.nor.fr.ftgroup) ([x.x.x.x]) by
 smtp-out.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384;
 01 Aug 2025 08:45:13 +0200
Received: from unknown (HELO opzinddimail7.si.fr.intraorange) ([x.x.x.x]) by
 opfedv3rlp0e.nor.fr.ftgroup with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384;
 01 Aug 2025 08:45:14 +0200
Received: from opzinddimail7.si.fr.intraorange (unknown [127.0.0.1])
	by DDEI (Postfix) with SMTP id E9EC823F7AE;
	Fri,  1 Aug 2025 08:45:12 +0200 (CEST)
Received: from opzinddimail7.si.fr.intraorange (unknown [127.0.0.1])
	by DDEI (Postfix) with ESMTP id CEED823F819;
	Fri,  1 Aug 2025 08:44:46 +0200 (CEST)
Received: from smtp-out365.orange.com (unknown [x.x.x.x])	by
 opzinddimail7.si.fr.intraorange (Postfix) with ESMTPS;
 Fri,  1 Aug 2025 08:44:46 +0200 (CEST)
Received: from mail-francecentralazlp17011027.outbound.protection.outlook.com
 (HELO PAUP264CU001.outbound.protection.outlook.com) ([40.93.76.27])
  by smtp-out365.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384;
 01 Aug 2025 08:44:47 +0200
Received: from PR0P264MB2885.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:1d0::19)
 by MR1P264MB2819.FRAP264.PROD.OUTLOOK.COM (2603:10a6:501:38::16) with
 Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8989.16; Fri, 1 Aug
 2025 06:44:45 +0000
Received: from PR0P264MB2885.FRAP264.PROD.OUTLOOK.COM
 ([fe80::d43d:e9a7:d7d8:9d33]) by PR0P264MB2885.FRAP264.PROD.OUTLOOK.COM
 ([fe80::d43d:e9a7:d7d8:9d33%5]) with mapi id 15.20.8989.015; Fri, 1 Aug 2025
 06:44:45 +0000
From: mohamed.boucadair@orange.com
X-CSE-ConnectionGUID: tInR1rJgS9qqLrIxGl56nA==
X-CSE-MsgGUID: GAiUkq3WTsqdvTySl2tnNA==
X-TM-AS-ERS: 10.218.35.128-127.9.0.1
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb
	3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
X-CSE-ConnectionGUID: hfHan6lFTSiFuoXZ48yB7Q==
X-CSE-MsgGUID: 8PJUHW+zTcyimyLp+6pYuQ==
Authentication-Results: smtp-out365.orange.com;
 dkim=none (message not signed) header.i=none
IronPort-Data: A9a23:82emNq32YoB0xTQ/o/bD5bt2kn2cJEfYwER7XKvMYLTBsI5bpzJRm
 mMZWDuCP6nbMGX0Ltx+bom0/EoPusXQx983HQplqSg9HnlHl5HIVI+TRqvS04J+DSFhoGZPt
 Zh2hgzodZhsJpPkjk7wdOCn9z8kjv3gqoPUUIbsIjp2SRJvVBAvgBdin/9RqoNziLBVOSvV0
 T/Ji5OZYQDNNwJcaDpOtvrc80o35pwehRtD1rAATaES1LPhvylNZH4vDfnZB2f1RIBSAtm7S
 47rpF1u1jqEl/uFIorNfofTKiXmcJaLVeS9oiM+t5yZv/R3jndaPpDXlhYrQRw/Zz2hx7idw
 TjW3HC6YV9B0qbkwIzxX/TEes1zFfUuxVPJHZSwmcyd70TALX/C/85vIlwxDb9EqvddXlgbo
 JT0KBhVBvyCr9qf/YrhFLVHu5x7dY/sIZ8VvWxmwXfBF/E6TJvfQqLMo9hFwDM3gcMIFvHbD
 yYbQWY3KkWbJUIRfA1IYH49tL/Aan3XdjpYoVeYqew95HXYxQB40aLFN8DcfNOHA85Smy50o
 0qXpT6hX0lFarRzzxLVylCRptCMjx/wSYMXBZmgtaBysUCqkzl75Bo+DgDh/abRZlSFc9hWM
 GQL9zEyoLI4/UWtCN/0WhDQiH+JpRE0WtdMHas98g7l4qbO6giFQ2kJUjAEbNUjrNRzRi0g2
 0XMlN7zGT1hsbacVX+G3raZsT30PjIaRUcGbCocVk4O49Diupobjx/TQJBkCqHdpsbtECr16
 zGHsCZ4gK8c5eYL0Lig+V3WqyytqZnNVQM+oA7QWwqYAhhRYYekY8mm81Hd5vtLIYCFVFCFt
 WoAg5HBtLlXVcvS0iuQXO8KAbeloe6fNyHRikJuGJ9n8Cmx/3mkfsZb5zQWyFpV3tgseTHJa
 UmNvS1t3559IXyaX/MncqjuMpF/pUT/LujNWvfRZ9tIR5F+cg6b4S1jDXJ8OUi9wCDAdolvZ
 v+mndaQMJoMNUhw5BSML9rxPJcuzyE6gG3JTJbwwh+q16aEbXqcW7MdaQTWN7lhtvzCpxjJ+
 dFCMcfM0w9YTOD1fijQ98gUMEwOKn84Q5vxrqS7l9JvwCI4SQnN6NeIm9vNnrCJeYwOx48kG
 VnmCydlJKLX3yGvFOlzQikLhEnTdZh+t2knGicnIEyl3XMuCa72s/pEJstpIud3qbE7pRKRc
 xXjU5XQahioYmSYkwnxkbGg9d08HPhWrV7QYHf9PGZjF3Keb1eWoIe/JmMDCxXi/gLs7pFi/
 NVMJyveQJEZQB9lAtqeY/W11zuMUYs1yYpPs7/zCoALIi3EqdEyQwSo16NfC59WdX3rmGDAv
 y7IWkhwmAU4i9NvmDU/rfze99/xewa/d2IGd1TmAUGeb3aBoTTznNEYD45lv1n1DQvJxUlrX
 s0Np9mUDRHNtA8iX1ZUe1qz8Z8D2g==
IronPort-HdrOrdr: A9a23:MKo5wqnpswjYyxki0d60QrH/EFLpDfI33DAbv31ZSRFFG/Fws/
 re/8jztCWVtN9/YhsdcLy7VZVoIkm8yXcW2+cs1N6ZNWGMhILCFu5fBOXZrwEIVxeOlNJg6Q
 ==
X-Talos-CUID: 9a23:kqxUC2Fw/D/DJFkeqmJn+m4dHJ4hXEHmzVnNJH+KVTZ4YuKsHAo=
X-Talos-MUID: =?us-ascii?q?9a23=3AHbhlZg4vObX1IfpBXfhArp3uxow424aTKH9Og6k?=
 =?us-ascii?q?NqsiBJAhoeGmFvSmOF9o=3D?=
X-IronPort-AV: E=Sophos;i="6.17,255,1747692000";
   d="scan'208,217";a="92205076"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;
 b=eel82qz0Y3/7ctadGuKcr9NmC4RmdERBdINaOQ1xhLGDjKr7pvK1yG9L/4Pncw7xp1YhO9fYfVEz/HN0wSL8lpOrybUF9m6yTanNYD9xH4+jUNaeKpijDs0xLwMXikWY6/r1UuMaOZMaKpl6WoCp1R8f3WawiOA/0kJp1sEumUARZ1VA7yEA/7x5TlpyfCmuvz8WsThhNraMIqxyvK0HUGYXcEGOsm4LI1r7qlIjGEEMBGTYFCcTRMiglmfFi6hhMAUnD4MiRZQ6Ny2VTTo1bPyfeYBLmdQvysyM9O+FWsvwYupFtdj/JhN3U7ZwceJxTOb2My5zvyiY+2IXaZPZGQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
 s=arcselector10001;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
 bh=f+gl7lhURzQ83zmoz1GYuhIMD1zRHqRFsXyzdBblBi8=;
 b=GzVVFfqhj5BCjCSqAbEgema0qBS0fC5UV29SAZZIgsehrgJ19tkitksVd+mPqTZutCotnZxCuvlqOCGy7Wca/LnnuMy39MVigMlAQKThHAshAvXsHWcOuvDpChAbqJHt2Bb59zcVcx7tVwjFP0gC2kvHi2wdQdgqLRVOOx6sbUKXscrY64Gjls9Zvdr8XpqedwxbjOhrtmwEN32wFOhDZAM93caZ/7cqWzRO8x9wh2hxIf7ZCrbxlBPy4VQLxQTMznX58k6AI40Gv0wsyy5lYABGStE/MM3Oy0wewgrugrxBVWvDOVBTM5Syfb1kXeU1jBQagoBfhJnEMvV/K/A0Pw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass
 smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com;
 dkim=pass header.d=orange.com; arc=none
To: Bas Westerbaan <bas@westerbaan.name>
Thread-Topic: Mohamed Boucadair's No Objection on
 draft-ietf-lamps-kyber-certificates-10: (with COMMENT)
Thread-Index: AQHb9M8Wj70OhoN3o02pfxaxhyWGVLRNdY0g
Date: Fri, 1 Aug 2025 06:44:45 +0000
Message-ID: 
 <PR0P264MB288501E17A501FEAFE65AED18826A@PR0P264MB2885.FRAP264.PROD.OUTLOOK.COM>
References: 
 <175136208695.695943.10634752263304954022@dt-datatracker-6fcb845cd4-p6tkq>
 <FD28BAFB-8B85-44C7-B3CC-E676BF12E44B@westerbaan.name>
In-Reply-To: <FD28BAFB-8B85-44C7-B3CC-E676BF12E44B@westerbaan.name>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
msip_labels: 
 MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=bf5300ac-0a10-4c32-bd07-d1b9a5f4113a;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2025-08-01T06:44:36Z;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20;MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ContentBits=0;MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Enabled=true;MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Method=Standard;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PR0P264MB2885:EE_|MR1P264MB2819:EE_
x-ms-office365-filtering-correlation-id: a9676b16-9c33-45ac-f1e0-08ddd0c6e732
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: 
 BCL:0;ARA:13230040|1800799024|366016|376014|13003099007|8096899003|7053199007|38070700018;
x-microsoft-antispam-message-info: 
 =?iso-8859-1?Q?/NYsXkxo7oiocM+ffU0pGuS/9ib/tmo8lPN22gNQ0Uz+SRBnEDU0iai87s?=
 =?iso-8859-1?Q?Xzlcy+21XsjVpxxcn0Ajp5ydpVoTzwQnndt78Nam9VRtonDw6XZgEXiv5N?=
 =?iso-8859-1?Q?Tra855mS4dQ1L1gEx4dg86D11Isxi8aNDsyfQZF9ia/okjuUiX/zEPrf1+?=
 =?iso-8859-1?Q?tQEknnpDmTkud7PK13t1IUwpn4HYTyGxDntd12y8geLx4JkbyVX6dJM8BP?=
 =?iso-8859-1?Q?xMg372ZevJa7EDCO3TmeFQD5iUIvrgU80ygeEdd1XbeWMZOT4snRyhC7TE?=
 =?iso-8859-1?Q?WBmKOW1TKfyZ4F8cnaU1/NdRafl6+yj5ZB6yvp8OzUPDfVXlgH1zra1fXp?=
 =?iso-8859-1?Q?576rUo3GJd/aPAGr5CvQN0AeMA4AeiHFhb0u3iZmQEsRhUBibbhrDsmb/j?=
 =?iso-8859-1?Q?xcxMQ3F5RBsz7Ke8Iy79LSwPlggP/X0G0cZ0E1QtOskaBTXq0LcQVxi+Zd?=
 =?iso-8859-1?Q?q0PvNThBa3cHmqpCAOAmQQwNchgk23Fl9ZZvp73EcAtqLCkF4Y9BDh0Iom?=
 =?iso-8859-1?Q?cPsXMD/oVkU69FZJvfX3ZW/wz+p341Bpi2MiL/PvgNo11d6ArPuKu4PRgY?=
 =?iso-8859-1?Q?LH3QOI6kMCCq/tTP38WZsPIEfXIj0VJrAvXAHXiesK7k8SeQTaW8oD0AL5?=
 =?iso-8859-1?Q?9mx4pBRt+wNS8TJMOaWW15LcwqH0gPPgbLGb7ELJtl75+5fo4BC7KWpfNB?=
 =?iso-8859-1?Q?QMkdTXq9/D0Bsx3EdMqGZP9GblCI5sNnyllNOukv3npDzBVrUkZ/mMoz3M?=
 =?iso-8859-1?Q?Iaz/Hr1wZx1PVkh1gLILdFwbufdXpaCXS7mZw4x0O2XpQYzDxjjM+n6TM2?=
 =?iso-8859-1?Q?voUTheIJeUPBGtjYRATyTYMuDLDrCQHNf6/lQDZ2nE0IuEoCWHnOw/NdoQ?=
 =?iso-8859-1?Q?4/KTlH4NJsCfjpxzl49XBYgY4bIOFpDRQT7Ofnb17Ypq9ycNHj1UcPEHaf?=
 =?iso-8859-1?Q?F7qIfQ9b44UYRYVtSLrllP0ncwSocMNuc6pssm1tL6WzWWgxbvJBHef8Ja?=
 =?iso-8859-1?Q?DTNoQcN6qOWpewA7kGkXCQKJv6BmmopKFENo1Wr9rJWYd3iLzF7hMekrBt?=
 =?iso-8859-1?Q?lStUDHrUeqHYHwh3m/qVZR5SJAII3Yyqahp0CimqvQ6iwJKvcw76c6a30J?=
 =?iso-8859-1?Q?BBMPPsUO83RKhd1zsgyfngn+tFur5KNrvoQ4aPwNqJDkaz2z+FLaCH19wk?=
 =?iso-8859-1?Q?Q4tb3Oorjsgps9E7Qwu/nUfIo0SZKnMFuhlts29AkcyjPm3XxYariKrXNq?=
 =?iso-8859-1?Q?7FOJ6U4zP96xKXyhsaOJmtyl7s2eGP1V2Soju7hSichAVHU0jgUiDcr3uE?=
 =?iso-8859-1?Q?/d3ga4BVDN+B2efG7bLM1uykC82M+srw8rAGuyUYY+ABI7Oe02/Enby0Ym?=
 =?iso-8859-1?Q?oeMFqVWDtPCduFIaUcysW2vdzK/+9Rdk8tP4AEcSE3iYXOwt4otnZ18Eno?=
 =?iso-8859-1?Q?7aoUk6da3EkWmxw2uoQR83gSxVskE4CkN+2nkNEVVHewD+AhalS43if1m5?=
 =?iso-8859-1?Q?Eb7vH+8+/LcVe6jFtjgblkxMCXiwvXJWh1sV1xe882ga4HHVWCWA5o0n1r?=
 =?iso-8859-1?Q?JdGTb6s=3D?=
x-forefront-antispam-report: 
 CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PR0P264MB2885.FRAP264.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(376014)(13003099007)(8096899003)(7053199007)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 
 =?iso-8859-1?Q?akgLw+49PvZeQOJjJ1W/ekcuHAyynZZQm9Ny4biUvT0SY7XkI0eTDRSxB3?=
 =?iso-8859-1?Q?+xeRtbcWnHXH3c9RaW/RuRrK2HO4yHU8xSOA0jf7imBKYOQfT4B40aXagZ?=
 =?iso-8859-1?Q?6Jj51m9vCrMJcrTwhKT41shFf0UkU2P8tMxOiZPcFaX7URaDClkk/9sQQi?=
 =?iso-8859-1?Q?elpqX4hrdSUQdygGcJlwo16SXKm2lRfO4dpITaWmgzA65maDRm9FElA1uD?=
 =?iso-8859-1?Q?6646yJ0oHgISjYHmgBztfGjGn9z2MW3Pi6TSdG89tUNNGXTDcq3AJTOuJi?=
 =?iso-8859-1?Q?QcYE6GL602+G/KvYOPxaXz0YIv4rX6eI2vW3UgF9z6vGe3v2IxmZFLZn2Q?=
 =?iso-8859-1?Q?DB3E2gkq50f4aktQ/4uyFcAqEoXC9OpeMxjSkyg03jjm8WBWTOic5Or44x?=
 =?iso-8859-1?Q?SPPRRn37yHOvK+W0Wf1tigwA3K+Yu7uGGdTW4ea05h/HG19pZ3EnBsCaaw?=
 =?iso-8859-1?Q?XDCXfKz6QNmJvIwpMfnXgLOSqUv8HA+iiFMkhU030vouWGX6yFS3Jgq+KD?=
 =?iso-8859-1?Q?+GHWZ5XKyNzVGAAarHDtzpG9TE3b8tUe/h3IJuP3dRVNsHH7RuBIlLImPJ?=
 =?iso-8859-1?Q?tr4j8UM6CDvHzXNUnuJ+b9DMLGChOfPlwVLFyKgr6JZCe5WWKMWaxjp0rg?=
 =?iso-8859-1?Q?5SNjE6VFJCgW4/LyJcAuFxlFqegPhctLC7Y+oogqDLSAttU0h2L1KSaSMq?=
 =?iso-8859-1?Q?iG9XBzxrIXf/JpJ9WVYjkAuVxblcVyrUGCb70pVgNcCO+kjb8G2vzV5/x8?=
 =?iso-8859-1?Q?+VFx+/E4Sg8JcqucB11gr1Eh7DJtVljnR1V0dOaP4SFQPPIugU0g/XMgSG?=
 =?iso-8859-1?Q?v9JR8F0BuwefToQ1gv/sDwXvCJxik9O7OQ08uBVP24zamKAVCryVeIVQuU?=
 =?iso-8859-1?Q?wTlRzLIhWyDh8o2QWtnDw47F271sJdtZ2BvPOCCpxMKpxpBVWHhx0/iiow?=
 =?iso-8859-1?Q?u0uO6KrI+CfRkh3U9BAcW5Bswm7UOk5G9jku6HYC5OxP+vzMHdqsCaV6+t?=
 =?iso-8859-1?Q?SPo3WJrWLpFGSPD3AWxPGK64eY+NMozAduq/lnI6iDCg1CDYO5owwuoaXB?=
 =?iso-8859-1?Q?VHTbU/NvGV/amjsZZX9aA1ylVzFXm87juCwoTy4li0Mq+SVocrxpRqVMSw?=
 =?iso-8859-1?Q?d4pjHLBhx27y6KPZZxQXWX0xe8ZZv8MJh21DcthYwmhPTFn9oiTYTr0iv3?=
 =?iso-8859-1?Q?9ohEzGzlLJ8dgZo9FI+iOQtjKa8rWqzhq9i1EsrLgOMbmllTJiCZ7BTv//?=
 =?iso-8859-1?Q?kNk1tVDiN9DcoGmPJhUG7GNDEP6PPVKf+j0RQTiUZvXbsxvSx53TCPFGWh?=
 =?iso-8859-1?Q?Xlr7AgzW639lHZhLGbOvPWitkORSxEfK1IFDcnFpeWEnYJSMmU/tQJuAEC?=
 =?iso-8859-1?Q?U1qL7ax4QSGqtuAEB9VGAQA/TO1GYYI/78In92u12oY7xdsKnqZ3DK3daz?=
 =?iso-8859-1?Q?HmrSEBquVSQoGlPDR6nwfeO12kV5rOOQfXGlJWYKmLERT84xNz+NyNQ8H0?=
 =?iso-8859-1?Q?YKQscE7o6IQG4fduWPYVxAkvPUh4r3H1O4cPuWiyg1BMXsyEKFg/b0EpZF?=
 =?iso-8859-1?Q?HpvbYN9rqURN7yRhd5E9lnX+ockrOu+QkWs1O1d5y6CcAHXE241YAzrdfE?=
 =?iso-8859-1?Q?ep6KZwk7R8T0s69PURgNRBlKtyMlb+oqVZlB8iMO+SVMKbsEs0XqZGiw?=
 =?iso-8859-1?Q?=3D=3D?=
Content-Type: multipart/alternative;
	boundary="_000_PR0P264MB288501E17A501FEAFE65AED18826APR0P264MB2885FRAP_"
MIME-Version: 1.0
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PR0P264MB2885.FRAP264.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 
 a9676b16-9c33-45ac-f1e0-08ddd0c6e732
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Aug 2025 06:44:45.7266
 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 
 AI8kuMef83Tz+GlTog7yivqP/DantLj5r0a84qdMafg6EC2JErBG2YYDaGjXHiCWa8BNLQIxdPj1keNRMj4z8tjYqOu2mLoSluwEnEMN+Hc=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MR1P264MB2819
X-TM-AS-ERS: 10.218.35.128-127.9.0.1
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb
	3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.1.1004-29356.005
X-TMASE-Result: 10--36.692000-10.000000
X-TMASE-MatchedRID: UEe6CCDNlZzuYusHgJkgyqUfpvLQYumSdkdJR1Ptz4nxhuT2TM8RaC77
	4nlxVOXqPvl4Qvnzd53Vm14t84/DtPknCf5Y5jPYaXmdXF2Ym8c0tugJQ9WdwyDv6zn31Uzg15k
	n6gAB1XrL2Om0HXnCJT8hXNK+3FBhnVTWWiNp+v/Exmr5hqNL1jKv4QSPP2Gxja5+Fb5ryh8hQz
	4Qjt84Y9PqUfhGuXCCe3bcH73AUEgapIb9znReA9SgyJTgyLvlqRTAHcwAECfE6/xtuKO0a+RMu
	DKelv9R+0gY6okUAw94Jmskih8hhsb6dLbgzMd5K00yXBmLMJ9lhvCMthsWGvKdDFYqj4XRvs75
	gcY5ey4Ru3AibWiOpZGxVOLhpZHWg2tpowTD9VpK/UZnhtRB4iUUHr1YHBxhhSUmXGVMhP5UOL/
	8vFzxKzuaokxWEUmpQL7lz7dw2bLmnV13DpXhG7YxxljjfMnjzf+duMCJLEyKUmaUXynhB+9Loe
	a5qi6GprgkIrBH1/utocC43nAq+7A6Z+NDfTN5guwtqyXlE6E6AZLqscyixCYiaX7LCuq+cFPEg
	DcRJ0IxOoyxLMMhEe4imrbcRTzFe015woyPLfYytf6nW43O0Cm9q5Jn7xMAVCN7HaefSl+Qdhth
	BwOYrheXF48LMwEsR1vveBQPCRfBtFDYGmaWKhrL4FDGAJ+FViIzx4LWlRz3SJvEvhvPoC7L53a
	tdQGSMypbxa6TALFvzOix9zo1q2K3N9p/OFh6z8j+bxoiWAwHAA5cb5vjSo7yQb3gCryWZQG7Vf
	QBp3P3JpeE+GdRnUUuXkWTSi/R3BZE3fQo7k9KHhaQPPG6/o5hyiW8kJaQiJtHLSORchni8zVgX
	oAltqFbwzJfLow2HRcIXG0b6Khr34lUqic7t0Uz3IJmSrUgx3Aa4oibyxm4UWwltDXjMCBuGJWw
	gxArFnn7zLfna4I=
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: fc0c5faf-52b5-4258-882f-690109493708-0-0-200-0
Message-ID-Hash: ZANHMGOJFWZ76NB4HE65VUMPEMYHCUNS
X-Message-ID-Hash: ZANHMGOJFWZ76NB4HE65VUMPEMYHCUNS
X-MailFrom: mohamed.boucadair@orange.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-spasm.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: The IESG <iesg@ietf.org>,
 "draft-ietf-lamps-kyber-certificates@ietf.org" <draft-ietf-lamps-kyber-certificates@ietf.org>,
 "lamps-chairs@ietf.org" <lamps-chairs@ietf.org>,
 "spasm@ietf.org" <spasm@ietf.org>,
 "housley@vigilsec.com" <housley@vigilsec.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5Blamps=5D_Re=3A_Mohamed_Boucadair=27s_No_Objection_on_draft-ietf?=
 =?utf-8?q?-lamps-kyber-certificates-10=3A_=28with_COMMENT=29?=
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/spasm/GS0G5uZTEDuer0eL98OdISUdJQ8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>

--_000_PR0P264MB288501E17A501FEAFE65AED18826APR0P264MB2885FRAP_
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable

Hi Bas,

Thank you for the follow-up. The changes look good to me. Thanks.

Cheers,
Med

De : Bas Westerbaan <bas@westerbaan.name>
Envoy=E9 : lundi 14 juillet 2025 16:53
=C0 : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com>
Cc : The IESG <iesg@ietf.org>; draft-ietf-lamps-kyber-certificates@ietf.org=
; lamps-chairs@ietf.org; spasm@ietf.org; housley@vigilsec.com
Objet : Re: Mohamed Boucadair's No Objection on draft-ietf-lamps-kyber-cert=
ificates-10: (with COMMENT)






On 1 Jul 2025, at 11:28, Mohamed Boucadair via Datatracker <noreply@ietf.or=
g<mailto:noreply@ietf.org>> wrote:

Mohamed Boucadair has entered the following ballot position for
draft-ietf-lamps-kyber-certificates-10: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-=
ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-lamps-kyber-certificates/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Hi Sean, Panos, Jake, and Bas,

Thank you for the work put into this specification.

I trust the ASN module and examples were validated.

Please find below some comments, fwiw:

Thank you for your detailed comments.



# NIST Size Mapping

The ciphertext values in Table 1 do not match the ones used in Table 3 of
FIPS203. Is that intended?

Oops, that is indeed an error and has been corrected<https://github.com/lam=
ps-wg/kyber-certificates/pull/127/commits/18f848556f5dcb78ae3674e9811a9af0f=
321d80b>.


# Redundant recommendation

We do say in Section 4:

  NOTE: While the private key can be stored in multiple formats, the
  seed-only format is RECOMMENDED as it is the most compact
  representation.

then restate in Section 6:

  When encoding an ML-KEM private key in a OneAsymmetricKey object, any
  of these three formats may be used, though the seed format is
  RECOMMENDED for storage efficiency.

and then in that same section:

  NOTE: While the private key can be stored in multiple formats, the
  seed-only format is RECOMMENDED as it is the most compact
  representation.

Unless there are subtleties I missed, these recommendations are identical to
me. Please keep one.

Removed one of the three occurrences. The remaining two (one of which isn't=
 quoted in your mail) are technically different as one recommends the forma=
t for use within OneAssymetricKey object and the other for outside. [1]


# Notation

Please consider making this change in Section 5

OLD: id-alg-ml-kem-* in the SubjectPublicKeyInfo, then keyEncipherment MUST=
 be

NEW: id-alg-ml-kem-* (where * is 512, 768, or 1024 - see Section 3) in the
SubjectPublicKeyInfo, then keyEncipherment MUST be

Done. [1]


# Operational Considerations

## The document includes a good discussion of operational guidance. Can we
please reorganize ops content similar to the structure followed recently in
draft-ietf-lamps-dilithium-certificates?

NEW:
  6.  Operational Considerations  . . . . . . . . . . . . . . . . .
    6.1. Private Key Format  (OLD: Section 6)
    6.2. Private Key Consistency Testing (OLD: Section 8)
    6.3. Serialization of Seed Values (OLD: Section 7)

Putting "private key format" under operational considerations doesn't seem =
right. In dilithium-certs it's also a separate section outside of operation=
al considerations. To me grouping the remaining two subsections doesn't fee=
l worthwhile. [1]


## On the encoding formats

As discussed, e.g., in [1], there might be some variation between the encod=
ing
formats. I see serialization aspects are discussed in Section 7, but I wond=
er
whether we can include an explicit statement about the alignment (or
misalignment if any) about encoding approaches.

The private key format, and any context given in this I-D, has been a hotly=
 debated topic.  Personally, I do not readily see an uncontroversial statem=
ent we could add, but I'm open to suggestions.



# Misc.

## Applicability: cite celi-wiggers-tls-authkem as an example

OLD:
  To be used in TLS, ML-KEM certificates
  could only be used as end-entity identity certificates and would
  require significant updates to the protocol; see
  [I-D.celi-wiggers-tls-authkem].

NEW:
  To be used in TLS, ML-KEM certificates
  could only be used as end-entity identity certificates and would
  require significant updates to the protocol; see, for example,
  [I-D.celi-wiggers-tls-authkem].

Done. [1]


## Should this be stated once rather than being repeated for each ASN snipp=
et?

CURRENT:
     |  NOTE: The above syntax is from [RFC5912] and is compatible with
     |  the 2021 ASN.1 syntax [X680].  See [RFC5280] for the 1988 ASN.1
     |  syntax.

Left only one. [1]


## Please consider adding a citation in Section 4 to point to Appendix B. T=
his
helpful to understand the values used in various snippets.

Done. [1]

## (nit) Missing "and" in Section 4

OLD:
  When an ML-KEM public key appears outside of a SubjectPublicKeyInfo
  type in an environment that uses ASN.1 encoding, it can be encoded as
  an OCTET STRING by using the ML-KEM-512-PublicKey, ML-KEM-
  768-PublicKey, ML-KEM-1024-PublicKey types corresponding to the
  correct key size.

NEW:
  When an ML-KEM public key appears outside of a SubjectPublicKeyInfo
  type in an environment that uses ASN.1 encoding, it can be encoded as
  an OCTET STRING by using the ML-KEM-512-PublicKey, ML-KEM-
  768-PublicKey, and ML-KEM-1024-PublicKey types corresponding to the
  correct key size.

Fixed. [1]


## (nit) an extra "the" in Section 4

OLD:
  When the ML-KEM private key appears outside of an Asymmetric Key
  Package in an environment that uses ASN.1 encoding, it can be encoded
  using one of the the ML-KEM-PrivateKey CHOICE formats defined in
  Section 6.

NEW:
  When the ML-KEM private key appears outside of an Asymmetric Key
  Package in an environment that uses ASN.1 encoding, it can be encoded
  using one of the ML-KEM-PrivateKey CHOICE formats defined in
  Section 6.

Fixed. [1]



## (nit) Section 6

OLD: a fixed 64 byte OCTET STRING (66 bytes total with

NEW: a fixed 64-byte OCTET STRING (66 bytes total with

Fixed. [1]



## (nit) Section 8

OLD: Private Key Consistency Tesing

NEW: Private Key Consistency Testing

Fixed. [1]



## Section 9

CURRENT:
  ML-KEM key generation as standardized in [FIPS203] has specific
  requirements around randomness generation, described in section 3.3,
  'Randomness generation'.

Please make it explicit this is about 3.3 of FIPS203.

Rephrased. [1]

Thanks again,

 Bas

[1] https://github.com/lamps-wg/kyber-certificates/pull/129



Thank you.

Cheers,
Med

[1] https://github.com/openssl/openssl/issues/26652 (bullet list with
seed-related discussion)



___________________________________________________________________________=
_________________________________
Ce message et ses pieces jointes peuvent contenir des informations confiden=
tielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu=
 ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages el=
ectroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou =
falsifie. Merci.

This message and its attachments may contain confidential or privileged inf=
ormation that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and dele=
te this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been =
modified, changed or falsified.
Thank you.

--_000_PR0P264MB288501E17A501FEAFE65AED18826APR0P264MB2885FRAP_
Content-Type: text/html; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:12.0pt;
	font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Courier New";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	mso-ligatures:none;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"FR" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:break-w=
ord">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Co=
urier New&quot;;mso-fareast-language:EN-US">Hi Bas,
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Co=
urier New&quot;;mso-fareast-language:EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Courier New&quot;;mso-fareast-language:EN-US">Thank you for th=
e follow-up. The changes look good to me. Thanks.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Courier New&quot;;mso-fareast-language:EN-US"><o:p>&nbsp;</o:p=
></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Courier New&quot;;mso-fareast-language:EN-US">Cheers,<o:p></o:=
p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Courier New&quot;;mso-fareast-language:EN-US">Med<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-=
family:&quot;Courier New&quot;;mso-fareast-language:EN-US"><o:p>&nbsp;</o:p=
></span></p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0cm 0cm 0cm =
4.0pt">
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span style=3D"font-size:11.0pt;font-family:&quot=
;Calibri&quot;,sans-serif">De&nbsp;:</span></b><span style=3D"font-size:11.=
0pt;font-family:&quot;Calibri&quot;,sans-serif"> Bas Westerbaan &lt;bas@wes=
terbaan.name&gt;
<br>
<b>Envoy=E9&nbsp;:</b> lundi 14 juillet 2025 16:53<br>
<b>=C0&nbsp;:</b> BOUCADAIR Mohamed INNOV/NET &lt;mohamed.boucadair@orange.=
com&gt;<br>
<b>Cc&nbsp;:</b> The IESG &lt;iesg@ietf.org&gt;; draft-ietf-lamps-kyber-cer=
tificates@ietf.org; lamps-chairs@ietf.org; spasm@ietf.org; housley@vigilsec=
.com<br>
<b>Objet&nbsp;:</b> Re: Mohamed Boucadair's No Objection on draft-ietf-lamp=
s-kyber-certificates-10: (with COMMENT)<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><br>
<br>
<br>
<o:p></o:p></p>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class=3D"MsoNormal">On 1 Jul 2025, at 11:28, Mohamed Boucadair via Datat=
racker &lt;<a href=3D"mailto:noreply@ietf.org">noreply@ietf.org</a>&gt; wro=
te:<o:p></o:p></p>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div>
<p class=3D"MsoNormal">Mohamed Boucadair has entered the following ballot p=
osition for<br>
draft-ietf-lamps-kyber-certificates-10: No Objection<br>
<br>
When responding, please keep the subject line intact and reply to all<br>
email addresses included in the To and CC lines. (Feel free to cut this<br>
introductory paragraph, however.)<br>
<br>
<br>
Please refer to <a href=3D"https://www.ietf.org/about/groups/iesg/statement=
s/handling-ballot-positions/">
https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions=
/</a> <br>
for more information about how to handle DISCUSS and COMMENT positions.<br>
<br>
<br>
The document, along with other ballot positions, can be found here:<br>
<a href=3D"https://datatracker.ietf.org/doc/draft-ietf-lamps-kyber-certific=
ates/">https://datatracker.ietf.org/doc/draft-ietf-lamps-kyber-certificates=
/</a><br>
<br>
<br>
<br>
----------------------------------------------------------------------<br>
COMMENT:<br>
----------------------------------------------------------------------<br>
<br>
Hi Sean, Panos, Jake, and Bas,<br>
<br>
Thank you for the work put into this specification.<br>
<br>
I trust the ASN module and examples were validated.<br>
<br>
Please find below some comments, fwiw:<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">Thank you for your detailed comments.<o:p></o:p></p>
</div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal"><br>
# NIST Size Mapping<br>
<br>
The ciphertext values in Table 1 do not match the ones used in Table 3 of<b=
r>
FIPS203. Is that intended?<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Oops, that is indeed an error and has been&nbsp;<a h=
ref=3D"https://github.com/lamps-wg/kyber-certificates/pull/127/commits/18f8=
48556f5dcb78ae3674e9811a9af0f321d80b">corrected</a>.<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal"># Redundant recommendation<br>
<br>
We do say in Section 4:<br>
<br>
&nbsp;&nbsp;NOTE: While the private key can be stored in multiple formats, =
the<br>
&nbsp;&nbsp;seed-only format is RECOMMENDED as it is the most compact<br>
&nbsp;&nbsp;representation.<br>
<br>
then restate in Section 6:<br>
<br>
&nbsp;&nbsp;When encoding an ML-KEM private key in a OneAsymmetricKey objec=
t, any<br>
&nbsp;&nbsp;of these three formats may be used, though the seed format is<b=
r>
&nbsp;&nbsp;RECOMMENDED for storage efficiency.<br>
<br>
and then in that same section:<br>
<br>
&nbsp;&nbsp;NOTE: While the private key can be stored in multiple formats, =
the<br>
&nbsp;&nbsp;seed-only format is RECOMMENDED as it is the most compact<br>
&nbsp;&nbsp;representation.<br>
<br>
Unless there are subtleties I missed, these recommendations are identical t=
o<br>
me. Please keep one.<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">Removed one of the three occurrences. The remaining =
two (one of which isn&#8217;t quoted in your mail) are technically differen=
t as one recommends the format for use within OneAssymetricKey object and t=
he other for outside. [1]<o:p></o:p></p>
</div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal"># Notation<br>
<br>
Please consider making this change in Section 5<br>
<br>
OLD: id-alg-ml-kem-* in the SubjectPublicKeyInfo, then keyEncipherment MUST=
 be<br>
<br>
NEW: id-alg-ml-kem-* (where * is 512, 768, or 1024 - see Section 3) in the<=
br>
SubjectPublicKeyInfo, then keyEncipherment MUST be<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Done. [1]<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal"># Operational Considerations<br>
<br>
## The document includes a good discussion of operational guidance. Can we<=
br>
please reorganize ops content similar to the structure followed recently in=
<br>
draft-ietf-lamps-dilithium-certificates?<br>
<br>
NEW:<br>
&nbsp;&nbsp;6. &nbsp;Operational Considerations &nbsp;. . . . . . . . . . .=
 . . . . . .<br>
&nbsp;&nbsp;&nbsp;&nbsp;6.1. Private Key Format &nbsp;(OLD: Section 6)<br>
&nbsp;&nbsp;&nbsp;&nbsp;6.2. Private Key Consistency Testing (OLD: Section =
8)<br>
&nbsp;&nbsp;&nbsp;&nbsp;6.3. Serialization of Seed Values (OLD: Section 7)<=
o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Putting &#8220;private key format&#8221; under opera=
tional considerations doesn&#8217;t seem right. In dilithium-certs it&#8217=
;s also a separate section outside of operational considerations. To me gro=
uping the remaining two subsections doesn&#8217;t feel worthwhile.
 [1]<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal">## On the encoding formats<br>
<br>
As discussed, e.g., in [1], there might be some variation between the encod=
ing<br>
formats. I see serialization aspects are discussed in Section 7, but I wond=
er<br>
whether we can include an explicit statement about the alignment (or<br>
misalignment if any) about encoding approaches.<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">The private key format, and any context given in thi=
s I-D, has been a hotly debated topic. &nbsp;Personally, I do not readily s=
ee an uncontroversial statement we could add, but I&#8217;m open to suggest=
ions.<o:p></o:p></p>
</div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal"><br>
# Misc.<br>
<br>
## Applicability: cite celi-wiggers-tls-authkem as an example<br>
<br>
OLD:<br>
&nbsp;&nbsp;To be used in TLS, ML-KEM certificates<br>
&nbsp;&nbsp;could only be used as end-entity identity certificates and woul=
d<br>
&nbsp;&nbsp;require significant updates to the protocol; see<br>
&nbsp;&nbsp;[I-D.celi-wiggers-tls-authkem].<br>
<br>
NEW:<br>
&nbsp;&nbsp;To be used in TLS, ML-KEM certificates<br>
&nbsp;&nbsp;could only be used as end-entity identity certificates and woul=
d<br>
&nbsp;&nbsp;require significant updates to the protocol; see, for example,<=
br>
&nbsp;&nbsp;[I-D.celi-wiggers-tls-authkem].<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Done. [1]<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal">## Should this be stated once rather than being repe=
ated for each ASN snippet?<br>
<br>
CURRENT:<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;| &nbsp;NOTE: The above syntax is from [RFC59=
12] and is compatible with<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;| &nbsp;the 2021 ASN.1 syntax [X680]. &nbsp;S=
ee [RFC5280] for the 1988 ASN.1<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;| &nbsp;syntax.<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Left only one. [1]<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal">## Please consider adding a citation in Section 4 to=
 point to Appendix B. This<br>
helpful to understand the values used in various snippets.<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Done. [1]<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal">## (nit) Missing &#8220;and&#8221; in Section 4<br>
<br>
OLD:<br>
&nbsp;&nbsp;When an ML-KEM public key appears outside of a SubjectPublicKey=
Info<br>
&nbsp;&nbsp;type in an environment that uses ASN.1 encoding, it can be enco=
ded as<br>
&nbsp;&nbsp;an OCTET STRING by using the ML-KEM-512-PublicKey, ML-KEM-<br>
&nbsp;&nbsp;768-PublicKey, ML-KEM-1024-PublicKey types corresponding to the=
<br>
&nbsp;&nbsp;correct key size.<br>
<br>
NEW:<br>
&nbsp;&nbsp;When an ML-KEM public key appears outside of a SubjectPublicKey=
Info<br>
&nbsp;&nbsp;type in an environment that uses ASN.1 encoding, it can be enco=
ded as<br>
&nbsp;&nbsp;an OCTET STRING by using the ML-KEM-512-PublicKey, ML-KEM-<br>
&nbsp;&nbsp;768-PublicKey, and ML-KEM-1024-PublicKey types corresponding to=
 the<br>
&nbsp;&nbsp;correct key size.<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Fixed. [1]<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal">## (nit) an extra &#8220;the&#8221; in Section 4<br>
<br>
OLD:<br>
&nbsp;&nbsp;When the ML-KEM private key appears outside of an Asymmetric Ke=
y<br>
&nbsp;&nbsp;Package in an environment that uses ASN.1 encoding, it can be e=
ncoded<br>
&nbsp;&nbsp;using one of the the ML-KEM-PrivateKey CHOICE formats defined i=
n<br>
&nbsp;&nbsp;Section 6.<br>
<br>
NEW:<br>
&nbsp;&nbsp;When the ML-KEM private key appears outside of an Asymmetric Ke=
y<br>
&nbsp;&nbsp;Package in an environment that uses ASN.1 encoding, it can be e=
ncoded<br>
&nbsp;&nbsp;using one of the ML-KEM-PrivateKey CHOICE formats defined in<br>
&nbsp;&nbsp;Section 6.<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Fixed. [1]<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal"><br>
## (nit) Section 6<br>
<br>
OLD: a fixed 64 byte OCTET STRING (66 bytes total with<br>
<br>
NEW: a fixed 64-byte OCTET STRING (66 bytes total with<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Fixed. [1]<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal"><br>
## (nit) Section 8<br>
<br>
OLD: Private Key Consistency Tesing<br>
<br>
NEW: Private Key Consistency Testing<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Fixed. [1]<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal"><br>
## Section 9<br>
<br>
CURRENT:<br>
&nbsp;&nbsp;ML-KEM key generation as standardized in [FIPS203] has specific=
<br>
&nbsp;&nbsp;requirements around randomness generation, described in section=
 3.3,<br>
&nbsp;&nbsp;'Randomness generation'.<br>
<br>
Please make it explicit this is about 3.3 of FIPS203.<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal">Rephrased. [1]<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">Thanks again,<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">&nbsp;Bas<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal">[1]&nbsp;<a href=3D"https://github.com/lamps-wg/kybe=
r-certificates/pull/129">https://github.com/lamps-wg/kyber-certificates/pul=
l/129</a><o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
Thank you.<br>
<br>
Cheers,<br>
Med<br>
<br>
[1] <a href=3D"https://github.com/openssl/openssl/issues/26652">https://git=
hub.com/openssl/openssl/issues/26652</a> (bullet list with<br>
seed-related discussion)<br>
<br>
<br>
<o:p></o:p></p>
</div>
</div>
</blockquote>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</div>
<pre>_________________<wbr>______________________________<wbr>_____________=
_________________<wbr>______________________________<wbr>_
Ce message et ses pieces jointes peuvent contenir des informations confiden=
tielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu=
 ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages el=
ectroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou =
falsifie. Merci.

This message and its attachments may contain confidential or privileged inf=
ormation that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and dele=
te this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been =
modified, changed or falsified.
Thank you.</pre></body>
</html>

--_000_PR0P264MB288501E17A501FEAFE65AED18826APR0P264MB2885FRAP_--



