[lamps] [Technical Errata Reported] RFC9935 (9020)
rfc-editor@rfc-editor.org Tue, 30 June 2026 14:30 UTC
Return-Path: <rfc-editor@rfc-editor.org>
X-Original-To: spasm@ietf.org
Delivered-To: spasm@mail2.ietf.org
Received: from errata-celery-848864fbc6-zwfqr (unknown [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id AA12210AD691F; Tue, 30 Jun 2026 07:30:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782829847; bh=L7dZxThDeIuE6gUkDpoCZy9i6MXVLgU68V/udxpUyeM=; h=Subject:From:To:Cc:Date; b=o4PJZ4MIY/s/bV8bs1Qaw0Ca98LjgBHS41K6BtPwbNMaCOaJBEnpFWrEb4GgPA+UK PMU1eOC3mVSXAohn9mvffn+GbVjuFMYxzdNnMJEbcRIiluMYx6nQE2kHdLGJKewOXl CNAEBqDFWS43YU/NnWz3l9ShqoB0QwuoESuf/gvo=
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
From: rfc-editor@rfc-editor.org
To: sean@sn3rd.com, jakemas@amazon.com, stndrds-inacio@andrew.cmu.edu, housley@vigilsec.com, kpanos@amazon.com, bas@westerbaan.name, debcooley1@gmail.com
Date: Tue, 30 Jun 2026 14:30:47 -0000
message-id: <178282984757.12.10238512173917738601@rfc-editor.org>
Message-ID-Hash: N4372YK2R6WMP6TVTDEENSMONTIBMIYB
X-Message-ID-Hash: N4372YK2R6WMP6TVTDEENSMONTIBMIYB
X-MailFrom: rfc-editor@rfc-editor.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spasm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: spasm@ietf.org, chchen.scholar@gmail.com, rfc-editor@rfc-editor.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [lamps] [Technical Errata Reported] RFC9935 (9020)
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/Sc3JyH7L1TjTUXSRx7lNekZoXWg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>
The following errata report has been submitted for RFC9935, "Internet X.509 Public Key Infrastructure - Algorithm Identifiers for the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)" -------------------------------------- You may review the report below and at: https://errata.rfc-editor.org/eid9020/ -------------------------------------- Type: Technical Reported by: Abel C. H. Chen <chchen.scholar@gmail.com> Section 9 says: Original Text ------------- For more detailed ML-KEM specific security considerations regarding this, randomness, misbinding properties, decapsulation failures, key reuse, and key checks, refer to [ML-KEM-SEC-CONS]. Corrected Text -------------- For more detailed ML-KEM specific security considerations regarding this, randomness, misbinding properties, decapsulation failures, key reuse, and key checks, refer to [ML-KEM-SEC-CONS]. In the X.509 certificate, the digital signature should provide a security level equal to or higher than that of the KEM public key. Notes ----- I have observed a potential issue in some application scenarios, where the public key in the certificate may use an ML-KEM-1024 public key, while the corresponding signature is generated using ML-DSA-44. This could lead to a situation in which a lower-security-level digital signature is used to sign or endorse a higher-security-level public key. In light of this, I would respectfully suggest considering an additional clarification in Section 9. Specifically, after the sentence: “For more detailed ML-KEM specific security considerations regarding this, randomness, misbinding properties, decapsulation failures, key reuse, and key checks, refer to [ML-KEM-SEC-CONS].” It may be helpful to add the following statement: “In the X.509 certificate, the digital signature should provide a security level equal to or higher than that of the KEM public key.” Instructions: ------------- This erratum is currently posted as "Reported". Please use "Reply All" to discuss whether it should be verified or rejected. When a decision is reached, the verifying party will log in to change the status and edit the report, if necessary. -------------------------------------- RFC9935 (draft-ietf-lamps-kyber-certificates) -------------------------------------- Title : Internet X.509 Public Key Infrastructure - Algorithm Identifiers for the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) Publication Date : March 2026 Author(s) : S. Turner, P. Kampanakis, J. Massimo, B. E. Westerbaan Category : Proposed Standard Source : lamps (sec) Stream : IETF Verifying Party : IESG
- [lamps] [Technical Errata Reported] RFC9935 (9020) rfc-editor
- [lamps] Re: [Technical Errata Reported] RFC9935 (… Kampanakis, Panos
- [lamps] Re: [Technical Errata Reported] RFC9935 (… Deb Cooley