[lamps] Re: WG Last Call for draft-ietf-lamps-kyber-certificates-07

"D. J. Bernstein" <djb@cr.yp.to> Fri, 10 January 2025 19:54 UTC

Return-Path: <djb-dsn2-1406711340.7506@cr.yp.to>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 44697C1DA1D9 for <spasm@ietfa.amsl.com>; Fri, 10 Jan 2025 11:54:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I33MAUDs9z2h for <spasm@ietfa.amsl.com>; Fri, 10 Jan 2025 11:54:07 -0800 (PST)
Received: from salsa.cs.uic.edu (salsa.cs.uic.edu [131.193.32.108]) by ietfa.amsl.com (Postfix) with SMTP id 3C05FC1D61F7 for <spasm@ietf.org>; Fri, 10 Jan 2025 11:54:06 -0800 (PST)
Received: (qmail 20865 invoked by uid 1010); 10 Jan 2025 19:54:06 -0000
Received: from unknown (unknown) by unknown with QMTP; 10 Jan 2025 19:54:06 -0000
Received: (qmail 96675 invoked by uid 1000); 10 Jan 2025 19:53:58 -0000
Date: Fri, 10 Jan 2025 19:53:58 -0000
Message-ID: <20250110195358.96673.qmail@cr.yp.to>
From: "D. J. Bernstein" <djb@cr.yp.to>
To: spasm@ietf.org
Mail-Followup-To: spasm@ietf.org
In-Reply-To: <DEA6B07F-B236-45F2-AA45-5ED910818DF9@akamai.com>
Message-ID-Hash: I7HWON3YXM6DMLO6WAOV3Q7QKGOXHML3
X-Message-ID-Hash: I7HWON3YXM6DMLO6WAOV3Q7QKGOXHML3
X-MailFrom: djb-dsn2-1406711340.7506@cr.yp.to
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spasm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [lamps] Re: WG Last Call for draft-ietf-lamps-kyber-certificates-07
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/zaRuZPUFmwg94y4FLgaib501CkI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>

> > One can't implement draft-ietf-lamps-kyber-certificates-07 without
> > implementing Kyber. The Zhao claim that "Kyber is covered by our
> > patents" is a known IPR claim regarding Kyber. Consequently, before
> > becoming an IETF RFC, the draft should be modified to allow alternatives
> > to Kyber.
> Or keep working as we are doing under the belief that there will be a
> royalty-free license before RFC publication.
> I am not advocating one position or another, just pointing out a flaw
> in your reasoning.

I don't see a basis for believing that there will be such a license. I
also don't see how such a belief is contradicting anything I said.

My understanding is that you're commenting on who's responsible for
achieving the results required by BCP 79. In particular, I think you're
suggesting that IETF WGs are free to ignore patent claims, shifting
responsibility to later stages of the IETF publication process to
enforce the BCP 79 requirements.

This, however, is contradicted by the introductory sentence of this
section of BCP 79, which assigns responsibility directly to WGs: "In
general, IETF working groups prefer technologies with no known IPR
claims or, for technologies with claims against them, an offer of
royalty-free licensing."

It's also part of the job of ADs to check whether WGs are following the
rules. This doesn't mean that the WGs are free to ignore the rules.
Please also note that any efforts to evade IETF rules are contrary to

    https://www.ietf.org/blog/ietf-llc-statement-competition-law-issues/

which, as part of arguing that IETF complies with antitrust law, claims
that IETF's procedural rules are "rigorously followed".

---D. J. Bernstein