[lamps] Re: WG Last Call: draft-ietf-lamps-pq-composite-sigs-08 (Ends 2025-10-06)

tirumal reddy <kondtir@gmail.com> Wed, 24 September 2025 06:36 UTC

Return-Path: <kondtir@gmail.com>
X-Original-To: spasm@mail2.ietf.org
Delivered-To: spasm@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id BEFB967E3460 for <spasm@mail2.ietf.org>; Tue, 23 Sep 2025 23:36:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LXcb6zMvuDIp for <spasm@mail2.ietf.org>; Tue, 23 Sep 2025 23:36:53 -0700 (PDT)
Received: from mail-ed1-x52b.google.com (mail-ed1-x52b.google.com [IPv6:2a00:1450:4864:20::52b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4A1BF67E3455 for <spasm@ietf.org>; Tue, 23 Sep 2025 23:36:53 -0700 (PDT)
Received: by mail-ed1-x52b.google.com with SMTP id 4fb4d7f45d1cf-62fa8d732daso10133292a12.3 for <spasm@ietf.org>; Tue, 23 Sep 2025 23:36:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1758695812; x=1759300612; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=IY+/2KFxwed7IpioOF2t7nnuNhaUSz6rR0RBUU89bzU=; b=JtJIL5nubn8s/3WqqyVxsF0trj7u6R6iCDjoYXYJDvaWRqhlSWI7ZLm5hA9SnzuQRe c9U/MsS+G7hmiUS4FOtzSWZtEAMKxg5wWXPpv2o8pPIKvoObufg5nD5sOPQL4/PNiWpr A2JzpF+EqcYoMgF77/603Xm7QnDARVr9KMM8oCpuvrjKuQKAhrstnEBg92ocCNo5HDy2 /PnFdtHaPukZb4berdFGJUuyTBkPMKztl6sCEmyeQ63BX3ZYwCV77r9sf16Bl7ZhgLSf ueawKCMxHObx26rid4B2g3UIfocOifa70W9Le2fuXwcfRybtObeDrrudVaeMuHxq1lbI 18Mg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1758695812; x=1759300612; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=IY+/2KFxwed7IpioOF2t7nnuNhaUSz6rR0RBUU89bzU=; b=Lvdujn7aH7z2gby056O7NST5oZZlCtw35C9GSNozV4R98tEzWE0Mp/roXUZ2zuS+Fb xs3JMu8wIOSEB/sc4KF7y5/beiswiyFFzShiJWoT4icMYpTsg1bwtegsoXYbG95DTODS 4vJMgk7se//NZzkxRoatsgY2TcBqswVrTR52OqJi6E74j6tw8cblurvF3yRxoh5EA0+w Ahk8HjNUyF/8eI0xStkvlPHFO+8Pv8Y59aarDSJjkspk+m5htk8gxqJkW4Wec3HJOPiR ydMnv5B9JND0Z2rAHNw6Ri0HV0cDZi3w1UgipBLEBHt525BV7K0wcSIQqnfAGL4b51HJ ZVdQ==
X-Gm-Message-State: AOJu0YyMBgyt1WazBkwj0TD9EmBSo7MuB4xNrLgQyCtSnufii8EU3PTt 0VZ8n7/GQ6ZWGpYUPWlZWja+bgb3VZi5AbnIlr6N/5kAY36nEG8pMZ/+hztgwYsYJzPmfZGGfhP GM6AyNQ56ZbtcaDnJr6A0AakuTmeoTMY=
X-Gm-Gg: ASbGnctoP97uEpdKZXO0RqjJc++K76VwMYRYvdbaxcLRdGkDFngP9v4I8WdP+67sh01 I7nbOerxrIVZDrOh+PBPWUnwdC6NkM7kbfAZd97jytevEHWuU2JjIdWACr3tWnVjx/lN2BmCj4c YWa+hksOJRGZG5mCLDFVQbizd464RoHgSDUxE2Vuytx4rtMpQ4DmyZpZ+5K9ApEDxoMg6E6Ke9H G3pR184oA==
X-Google-Smtp-Source: AGHT+IGTpCRW1ZHezUrFhF8joHBwaFEjfdoHuke0/l2rc2muyyNhi4wquwfi/6mLyxF7oY6PU0uQ0+O+rDqpTtW+Z4A=
X-Received: by 2002:a05:6402:234b:b0:62f:64b0:9cc2 with SMTP id 4fb4d7f45d1cf-634677b6e57mr5055217a12.16.1758695811813; Tue, 23 Sep 2025 23:36:51 -0700 (PDT)
MIME-Version: 1.0
References: <175855620751.648048.16646357165291761730@dt-datatracker-6c6cdf7f94-h6rnn> <88B43AFC-A176-4125-93D0-2A724D6603C4@vigilsec.com>
In-Reply-To: <88B43AFC-A176-4125-93D0-2A724D6603C4@vigilsec.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Wed, 24 Sep 2025 12:06:14 +0530
X-Gm-Features: AS18NWDYAIKBdbQQqNXX82aybuM5Yj7bHYcDvF9h5gZBZMT34UfqJ3E2GPuLML8
Message-ID: <CAFpG3gcP761Q4C+t4C90+umjZUNpKo=9ZdzJ5dREAhKfeMeXxg@mail.gmail.com>
To: Russ Housley <housley@vigilsec.com>
Content-Type: multipart/alternative; boundary="000000000000219538063f8647ff"
Message-ID-Hash: JR62D6BTYAMRACIRXQYAYCAO7FFPDYHA
X-Message-ID-Hash: JR62D6BTYAMRACIRXQYAYCAO7FFPDYHA
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spasm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: spasm@ietf.org, draft-ietf-lamps-pq-composite-sigs@ietf.org, lamps-chairs@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [lamps] Re: WG Last Call: draft-ietf-lamps-pq-composite-sigs-08 (Ends 2025-10-06)
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/h1FrvGuz2eiRat5xtdWoj6KzhK4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>

Hi,

I am reviewing IPR disclosure 4761
<https://datatracker.ietf.org/ipr/4761/?utm_source=chatgpt.com> related to
Composite ML-DSA. I would like to understand whether the licensing terms
allow implementations in open source projects. From my reading, the
disclosure appears to provide a commitment that is conditional.

Does this IPR declaration permit open source implementations without the
need for individual agreements with CableLabs ?

Your clarification will help assess whether Composite ML-DSA can be adopted
in open source cryptographic libraries and security protocols (use of
composite ML-DSA is proposed in TLS, IKEv2 and JOSE).

-Tiru
On Mon, 22 Sept 2025 at 21:23, Russ Housley <housley@vigilsec.com> wrote:

> As part of this WG Last Call, be aware that this IPR disclosure was
> submitted four years ago:
> https://datatracker.ietf.org/ipr/4761/
>
> Russ
>
>
> On Sep 22, 2025, at 11:50 AM, Russ Housley via Datatracker <
> noreply@ietf.org> wrote:
>
>
> Subject: WG Last Call: draft-ietf-lamps-pq-composite-sigs-08 (Ends
> 2025-10-06)
>
> This message starts a 2-week WG Last Call for this document.
>
> Abstract:
>   This document defines combinations of ML-DSA [FIPS.204] in hybrid
>   with traditional algorithms RSASSA-PKCS1-v1.5, RSASSA-PSS, ECDSA,
>   Ed25519, and Ed448.  These combinations are tailored to meet security
>   best practices and regulatory guidelines.  Composite ML-DSA is
>   applicable in any application that uses X.509 or PKIX data structures
>   that accept ML-DSA, but where the operator wants extra protection
>   against breaks or catastrophic bugs in ML-DSA.
>
> File can be retrieved from:
> https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-sigs/
>
> Please review and indicate your support or objection to proceed with the
> publication of this document by replying to this email keeping
> spasm@ietf.org
> in copy. Objections should be motivated and suggestions to resolve them are
> highly appreciated.
>
> Authors, and WG participants in general, are reminded again of the
> Intellectual Property Rights (IPR) disclosure obligations described in BCP
> 79
> [1]. Appropriate IPR disclosures required for full conformance with the
> provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of
> any. Sanctions available for application to violators of IETF IPR Policy
> can
> be found at [3].
>
> Thank you.
>
> [1] https://datatracker.ietf.org/doc/bcp78/
> [2] https://datatracker.ietf.org/doc/bcp79/
> [3] https://datatracker.ietf.org/doc/rfc6701/
>
>
>
>
> _______________________________________________
> Spasm mailing list -- spasm@ietf.org
> To unsubscribe send an email to spasm-leave@ietf.org
>