[lamps] Re: I-D Action: draft-ietf-lamps-pq-composite-kem-12.txt
Russ Housley <housley@vigilsec.com> Mon, 09 March 2026 21:23 UTC
Return-Path: <housley@vigilsec.com>
X-Original-To: spasm@mail2.ietf.org
Delivered-To: spasm@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 2D2A0C72C036 for <spasm@mail2.ietf.org>; Mon, 9 Mar 2026 14:23:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.799
X-Spam-Level:
X-Spam-Status: No, score=-2.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=vigilsec.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dEdq9tPDqs43 for <spasm@mail2.ietf.org>; Mon, 9 Mar 2026 14:23:32 -0700 (PDT)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id C629BC72C031 for <spasm@ietf.org>; Mon, 9 Mar 2026 14:23:32 -0700 (PDT)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id AA9171A08D0 for <spasm@ietf.org>; Mon, 9 Mar 2026 17:23:32 -0400 (EDT)
Received: from smtpclient.apple (pool-96-255-71-95.washdc.fios.verizon.net [96.255.71.95]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id 9B4341A1D31 for <spasm@ietf.org>; Mon, 9 Mar 2026 17:23:32 -0400 (EDT)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.400.21\))
Date: Mon, 09 Mar 2026 17:23:22 -0400
References: <176784783112.3939517.13561401651567448441@dt-datatracker-5656579b89-p6k4r> <6427208A-A863-4378-94F0-601604082E52@vigilsec.com>
To: IETF LAMPS <spasm@ietf.org>
In-Reply-To: <6427208A-A863-4378-94F0-601604082E52@vigilsec.com>
Message-Id: <9844A0CB-CFE7-48B4-B5A5-F1C2BD4C70A9@vigilsec.com>
X-Mailer: Apple Mail (2.3864.400.21)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vigilsec.com; h=from:content-type:content-transfer-encoding:mime-version:subject:date:references:to:in-reply-to:message-id; s=pair-202402141609; bh=W6ybK6jklaTZ6NTRD5nQSMtoNEWRPSQlLrhNSUpW1Yk=; b=ZnoKDGE58mhLPKUHolLClYtnhQvpPD9FEmecqp3sqmYZpQmZtvggiCFDVj1edLA/v+QPgDAvG0lLAV1hvaqJQssh4/ijYqSekpJbxBqXtrQUbF9EeTk9l28ueSCJrw/MSQ33MoBP4+h9vWy1W+vrOZ6ZknfMT1wm2Hv0d3v3cLpnDVaB3k0KV+yklZtbcW+X3wG2y60pKKwqAwFhR8z9fLqwpSZquf0nPdT/R1+OBuCyRzKre3Yf5wmXO+0id4cSNQ61bQoSuCjERbN5AuzTQ9Zwzc76346Li/7sySCegn4rmpN96T01XhZAZfHVTox0oOrCRjo0FMD6RudUeO7khw==
X-Scanned-By: mailmunge 3.09
Message-ID-Hash: KUQB4YCPKS72DDJWCWOMLQ75HRS55WYN
X-Message-ID-Hash: KUQB4YCPKS72DDJWCWOMLQ75HRS55WYN
X-MailFrom: housley@vigilsec.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spasm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [lamps] Re: I-D Action: draft-ietf-lamps-pq-composite-kem-12.txt
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/poDP1WQmzkMpzuDb3YrdT7d-8Ns>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>
I am concerned with this paragraph:
* *ECDH*: public key MUST be encoded as an uncompressed X9.62
[X9.62_2005], including the leading byte 0x04 indicating
uncompressed. This is consistent with the encoding of ECPoint as
specified in section 2.2 of [RFC5480] when no ASN.1 OCTET STRING
wrapping is present. The private key MUST be encoded as
ECPrivateKey specified in [RFC5915] with 'NamedCurve' parameter
set to the OID of the curve, but without the 'publicKey' field.
The ciphertext MUST be encoded in the same manner as the public
key.
The MUST statement refers to [X9.62_2005], which is not a readily available specification.
I suggest that the MUST statement point to Section 2.2 of [RFC5480], and then provide an informative statement that it is consistent with [X9.62_2005]. In this way, all normative references are publicly available.
Russ
> On Mar 9, 2026, at 5:07 PM, Russ Housley <housley@vigilsec.com> wrote:
>
> Unused Reference to 'Aviram22'; please remove it.
> Obsolete informational reference to RFC 4210; it is Obsoleted by RFC 9810.
>
> Obsolete informational reference RFC 5990; it is Obsoleted by RFC 9690.
> Reference to RFC 8411 should be informative, not normative.
> Russ
>
>
>> On Jan 7, 2026, at 11:50 PM, internet-drafts@ietf.org wrote:
>>
>> Internet-Draft draft-ietf-lamps-pq-composite-kem-12.txt is now available. It
>> is a work item of the Limited Additional Mechanisms for PKIX and SMIME (LAMPS)
>> WG of the IETF.
>>
>> Title: Composite ML-KEM for use in X.509 Public Key Infrastructure
>> Authors: Mike Ounsworth
>> John Gray
>> Massimiliano Pala
>> Jan Klaussner
>> Scott Fluhrer
>> Name: draft-ietf-lamps-pq-composite-kem-12.txt
>> Pages: 109
>> Dates: 2026-01-07
>>
>> Abstract:
>>
>> This document defines combinations of US NIST ML-KEM [FIPS.203] in
>> hybrid with traditional algorithms RSA-OAEP, ECDH, X25519, and X448.
>> These combinations are tailored to meet security best practices and
>> regulatory guidelines. Composite ML-KEM is applicable in any
>> application that uses X.509 or PKIX data structures that accept ML-
>> KEM, but where the operator wants extra protection against breaks or
>> catastrophic bugs in ML-KEM.
>>
>> The IETF datatracker status page for this Internet-Draft is:
>> https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-kem/
>>
>> There is also an HTMLized version available at:
>> https://datatracker.ietf.org/doc/html/draft-ietf-lamps-pq-composite-kem-12
>>
>> A diff from the previous version is available at:
>> https://author-tools.ietf.org/iddiff?url2=draft-ietf-lamps-pq-composite-kem-12
>>
>> Internet-Drafts are also available by rsync at:
>> rsync.ietf.org::internet-drafts
>>
>>
>> _______________________________________________
>> Spasm mailing list -- spasm@ietf.org
>> To unsubscribe send an email to spasm-leave@ietf.org
>
- [lamps] I-D Action: draft-ietf-lamps-pq-composite… internet-drafts
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Russ Housley
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Mike Ounsworth
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Russ Housley
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Carl Wallace
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Russ Housley
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Russ Housley
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Klaußner, Jan
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Russ Housley
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Mike Ounsworth
- [lamps] Re: I-D Action: draft-ietf-lamps-pq-compo… Mike Ounsworth