[tcpm] draft-ietf-tcpm-tcp-ao-algs

"Bonica, Ron" <ronald.bonica@hpe.com> Mon, 04 May 2026 14:14 UTC

Return-Path: <ronald.bonica@hpe.com>
X-Original-To: tcpm@mail2.ietf.org
Delivered-To: tcpm@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7AFA5E8C3295 for <tcpm@mail2.ietf.org>; Mon, 4 May 2026 07:14:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1777904059; bh=d67fimVFprqL78Y0UsGVo4QmJbSPO3awrONqQBd8Am8=; h=From:To:CC:Subject:Date; b=ofQ4PPZYYhAbZGHv7q2tpuSiZAv8kaZjjJE2VL7fW8rh2K8/YoJdPcVcRfWY0+SNB EGjdUcXcuwfoIM7axnzkEuOjqa8dDxylK6G5MMp2iIwNp8ywVsR7HSqztg+ncbsFXJ 00lRPGiHiTv2912TKx4MjuYF3bdrLYuOhOSNyfOI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.794
X-Spam-Level:
X-Spam-Status: No, score=-2.794 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=hpe.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wHLdAv72IgfG for <tcpm@mail2.ietf.org>; Mon, 4 May 2026 07:14:18 -0700 (PDT)
Received: from mx0b-002e3701.pphosted.com (mx0b-002e3701.pphosted.com [148.163.143.35]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 7F842E8C328E for <tcpm@ietf.org>; Mon, 4 May 2026 07:14:15 -0700 (PDT)
Received: from pps.filterd (m0150245.ppops.net [127.0.0.1]) by mx0b-002e3701.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 644A3Bo92240749; Mon, 4 May 2026 14:14:14 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hpe.com; h=cc :content-type:date:from:message-id:mime-version:subject:to; s= pps0720; bh=8BVMCtS1hV66b3FPZ+pxuDB7PEi7THgJ+w05eWeGJtM=; b=WrDU cU1dixhomGJUxHdLpP8G+soK7hk4fXIhWrcsYhSD5ANNcj890kJpk/HKegR8oYXA G9OWisrKMamcPvhR+E+97OUntYx23aE+Kv34Hi0JTMIIFsMEXULJi43aT1dX4H3m l7w7D42y9Jsn+4Zn68OedWJQ2MAZi0bhlzuGSd2WZdFV3RqS/k3VGEZGoul8geAB Gse4qiGN0okj1P7EODesg3d5mt2QstrZLYQWe0Inhz47wgTTqIBap3eauruzkhzH QFJd18pLLSGx9EySEYU3VTcvRvQaZ+KsJNoJ74FnXItPLWgz4JkSJA92f16f+Toz 3wh7RG2IXXPbmvb0bA==
Received: from p1lg14881.it.hpe.com (p1lg14881.it.hpe.com [16.230.97.202]) by mx0b-002e3701.pphosted.com (PPS) with ESMTPS id 4dxmn8x0bj-1 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Mon, 04 May 2026 14:14:13 +0000 (GMT)
Received: from p1wg14924.americas.hpqcorp.net (unknown [10.119.18.113]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by p1lg14881.it.hpe.com (Postfix) with ESMTPS id 3D90D800EB7; Mon, 4 May 2026 14:14:13 +0000 (UTC)
Received: from p1wg14926.americas.hpqcorp.net (10.119.18.115) by p1wg14924.americas.hpqcorp.net (10.119.18.113) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.17; Mon, 4 May 2026 02:14:07 -1200
Received: from p1wg14920.americas.hpqcorp.net (16.230.19.123) by p1wg14926.americas.hpqcorp.net (10.119.18.115) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.17 via Frontend Transport; Mon, 4 May 2026 02:14:07 -1200
Received: from BYAPR08CU003.outbound.protection.outlook.com (192.58.206.35) by edge.it.hpe.com (16.230.19.123) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.17; Mon, 4 May 2026 02:14:07 -1200
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=BHeEUkO2jT+ejhhgIyBa9Mo9kSilwwbI1uzTBMpL+lzrFddDJdeKXuvgVOONqhH0cYAKVobnQV591bkXk80o+7jOzL/f2Sg0/5iQWvd49i3xoXX3G4N7Bxj/QQU14Aiyd5ZvDYoyUrwtt5OA0wZgIHYDt/hPsKhvnxb95hjDKDv8a2P0k5gXsqVkL4J7GVT6VRkIU86AmJVtGL6CYLBDevQcBWFqqH1a8ziVYNTYsHx8x9MLWYrupkcLv4Tlpj52hwo1+zG2fj94w2dGZIxcpxUr/gQrAhoALaAV0YzoKHKCEov/wuppOyLkV2m8pHKRka8Xe8ztt4d5oh0P9vOT5A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=8BVMCtS1hV66b3FPZ+pxuDB7PEi7THgJ+w05eWeGJtM=; b=YOdASI8mT30wZPKb9StVv5KeRbud/FJvI/X0eG88DJIz3h16KoPdBNhpOZDPRuFjj7PznyjUvWsaBPlSj0yMxS2HH7dxRMJBHgw2TJfsHp2uYXFLZmExtkC3oTS2vqAGD56GyqI6a/T8lPCaNILXxLx920kOvjtmwiuS+Qb6I+lTTTitURheRsAAAIUZl9aEOICbPWT9Ai4OM8NnY7/2OgnGS+bU2bdjIm4MpXpu1dWDAFwZeaozkrWa2qbXA07ztYPIiT2djf67YMuEiNiwfA+77qOYmNPGWiFjD7HwCqoGa9BYZcHwM1/ss56qmSebbaQIGCdxxYO47iI2iOK9Sg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=hpe.com; dmarc=pass action=none header.from=hpe.com; dkim=pass header.d=hpe.com; arc=none
Received: from DM4PR84MB2310.NAMPRD84.PROD.OUTLOOK.COM (2603:10b6:8:51::18) by MW5PR84MB1572.NAMPRD84.PROD.OUTLOOK.COM (2603:10b6:303:1c2::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9891.13; Mon, 4 May 2026 14:14:05 +0000
Received: from DM4PR84MB2310.NAMPRD84.PROD.OUTLOOK.COM ([fe80::f9b2:4189:25fa:bd66]) by DM4PR84MB2310.NAMPRD84.PROD.OUTLOOK.COM ([fe80::f9b2:4189:25fa:bd66%3]) with mapi id 15.20.9891.008; Mon, 4 May 2026 14:13:58 +0000
From: "Bonica, Ron" <ronald.bonica@hpe.com>
To: "tcpm@ietf.org Extensions" <tcpm@ietf.org>
Thread-Topic: draft-ietf-tcpm-tcp-ao-algs
Thread-Index: AQHc283BmTLvaKZt6k2bsPsTXrjXkA==
Date: Mon, 04 May 2026 14:13:58 +0000
Message-ID: <DM4PR84MB231064D793297D5150FF47CFF4312@DM4PR84MB2310.NAMPRD84.PROD.OUTLOOK.COM>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM4PR84MB2310:EE_|MW5PR84MB1572:EE_
x-ms-office365-filtering-correlation-id: d3b963f9-3e91-4336-c3db-08dea9e7620e
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|1800799024|366016|56012099003|8096899003|18002099003|38070700021;
x-microsoft-antispam-message-info: 7HuGBHbxEKjiXmRTo6GUg8KTCBYICcnpsxuNV9aFjw/q20NY7BdBR3kjWUGS2vcQ18NmdnBBHef68aMVqMUTE9ec8epiQKNzZ1iJOLl2Ve/oFmOTtat2c6100Jx61iJ01vcZbEZ7PEgIE18nL54NjJDzqMV3a3Zjb1EpniComQ4QTNhJ5bc0oVrKtagx40AjquGBoCS2ZqJ+GxZFC7snWtuqjEiEMuxQk/TkumwlZnM7mvDca+VKBECJDHnBCZOmE2JkZNK4PYMuJu9KZH7+WIUUSJ4cMF1Pk7YSE01KQaEuC+JoYwxGWkh3P1ElnNFGW8OMD1WyEX0Zp6TLD+iBAd87CtHPt7PAGPv8W4yE9RzfEQ0WRL7K2EA6mJcrtfGkPd/nDKPVebdepwm11fqP4bzufxPhTayjApzF8BGjKUlbwTRapBGuIHNcKYjIwgAc1UN5j/JvDssHvEayYbaRzJtStO0dxl6uOMxezKX2vTXEUjlyBx5QwuewVfOEHfyS4y5ZvFQkkoQnsDDXvFPXy8ifajLuM6VQEjX8JqBu1sOXoOK9uWWPU+REHhLDqydXE59PCA+qg9dzY98M4pbpafMoFUFnjJwAinrwPojFzj+wNBB1z2q+csdMlzBL1jQPP2MYgF+0qjl6ALEjTWzzLqkLK/OFhcFiK+KvZM5NMGai5Wk3VqbqB+ctSHui+gqUT6EG2d/5kLosg5bUekpfZ0CD9cujkk98iJiSU2y9m9BqgmVgctguxz5j+WsU6UW0
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DM4PR84MB2310.NAMPRD84.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(1800799024)(366016)(56012099003)(8096899003)(18002099003)(38070700021);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: rya4EqRj/cWFf5veNWEEO9ttFUe2VDCIokhVVEf9LYJzsHryefDOrPVwNK79UNi4xb+ma9Kc5MLCFmypIU+BgLiM6VC0GEQrXJ54KeWQOiOR6zBrC0w2aZtwqpwSFeuDuWrqa8zDyasRNcpvVqB+G1IbIeBLGCCYVK16ONtXGOeugOdedzSIlAKVvyhHPikAiv1YOtnUkU46zwTWHVm2OBPA2J+0/7ik975iXArZhZI63TckDkUDmExFWe4kgnm+PgctiA1UaH+ZUm+ezW2iLP1+xloMoKZ+VpuBqTQmgbjMS98R9Pn4FYJIFkttvB4LwFE8xWOMv5fyYJTtIZdYnPVFZK3kvPIuSZVLHYLZd31F/tg4vuDumOXACCT4A0vvSx7aOU+Vwj1KNORshI8KlYrQnLzkhHGZneYKsdd5LjFSxCP5cs/JTehMDup/CJ+mNmutWSqT16BoftEZBuDI9wP6eoCNykjxTj65iGeL3/rWnnttpQQZrwCSdYm5vRWLJ5lai/9gtvel7Eo0kAoLtzBwb8i/JZxBRbODaA0wnDxKHGBIzLJ0ecDqqPLYSGn8Xh5D20uMBuWEjlwG4nVQhqMkD65LzWLrk9eenbO/ghXy7bQ+ATaKUQRtJiYH3qaC6YhPbzLG0Je+PdgavtIb4BJbZiNya3VBN15pq3v7VqJbr0FSK/TFyIFjWVqafWh04XmsgCt3xdzJMup8QDpQ5EO0wLZpru8wNV4aZN1CEdCLfGr7XuMC4jRY2GtawkRkPq1m9lpKizIp0yxoT3nnumgwxU3ZOkManj56Ww7u9YxH76z/X+avjgqes0Tm9Y1ppGIn7Q/SznWGwWGhY2f8wVxBBciXEePUY9gcYbiRXltPod2F+lsiNkl8nQn4qP1754lWcp9mSQoSmMQzpJkMPnrY6agathdoaAoMJvjxkEdjK45xIoOrpQRhlc/iFAwOolNcAL7k2O2VTuLcKXzkSvHjHE4wHLZY8GHcu0G47SDBiink0EJ4/i1Yv+YSLiS5jTm7lwheG14A1yJoFVKl+b0QDUkiVWqu8AmXBUP51LqwxajGdIoB29BpCD0hz1iC0kIPJt29DFYhxjJURaIYPd6ctxB52EJb9mhjesWlb08jbv/AZrVneJ6v43XN1bWaOA/+hoSqmVbHFCRQkE/qQb1sxSNqU7iicb4f1haC2dTH1jVOI+6uu/QG/kw9ItNylFY96Pk+G+wYpTIgebc/XyJGxMz8Fi6lcUUoKSXb2/tVT2yxTa46ml+eSsSCZFL0cBcTcD8RLDHfISUIFueWvckNjwTn8f7ruFcAOHAhcgNSo+n+25lnH2Ji9XQLbwzxGKMz0hxSy/QnPadL93ZnstgfQ8kuQhI+NTBQ4fYu4xQy62oB3Ahhv2J9yyI2aSpxp+s/lhDEMKXyJsSI0t8jp09ydMF2L2xuSaudKZEsZIT4YWxThUMOTTIZr4C5CwoCMLmVTzaNlS5eNI/Gfo8a9G9b0WcQF1DMUy4frnk5yu2pD/xiVtWli4ZZJhc567l4Y/NuBIXQaI8wxW7XNUGiFqkk+zF3ZVVuJ8wQrLWJ851usRuLye+R0TyuTbhuGA/2HVUcBv0yozItS7WJ53roJJjGYPpCOd68vxMx0vfyq6gQewLh7uNihLfCmkVs0t/WfVCVV/MYB4zyA4W4s9aLxuxom7LKOUxG66o6mSd+B5/EEperT4IBUhjscCiRLheK
Content-Type: multipart/alternative; boundary="_000_DM4PR84MB231064D793297D5150FF47CFF4312DM4PR84MB2310NAMP_"
MIME-Version: 1.0
X-Exchange-RoutingPolicyChecked: lsVt2ExS6AQn2UQWh/5A1hnrplbHVAMXDNiBjgrain1ZLJZTJyl+dGk9Fe7R53lQ8V6wvaIXkzm4WA/xWLaOXNrtWys1Tl9xIQQBASlyw4c2jXajt3glLDoI3WByXoIDm+UCVOI28QPC0534ZTqHg3FDgrMJj7AaKnCb5tcYA0a/avEf94gf2pPZdxCT7xBR7IkWBUYKQsW0N8Tgkci1m4NNOvzKaHQAK0YuUI70zGeWum4G3G2ey5hX/4hxNlgkW18mu81BWQ+Nv4plf40c4qI9e/ztos6q51WU7Z0cskNGmfiOh6vqPyYj6P3fr1Dj1BjniquYGutih0AlUqRZqA==
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM4PR84MB2310.NAMPRD84.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: d3b963f9-3e91-4336-c3db-08dea9e7620e
X-MS-Exchange-CrossTenant-originalarrivaltime: 04 May 2026 14:13:58.0644 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 105b2061-b669-4b31-92ac-24d304d195dc
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: NzHWDKF8LxRoYUuKjJM+Qg6jXHzvOKdTogf+J6EuXtR3+ko5DhzMQa6M+nOBfDEIa19spPzjN+6gUM3TXLmQ0Q==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW5PR84MB1572
X-OriginatorOrg: hpe.com
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNTA0MDE0OCBTYWx0ZWRfX7njSiaghsYZw ZXx++4h/IFtI+fQc4qRXV8plfXKF5c3WtoI69+vDOF4nuUE37tdVKvyGT3CA9QwxNmxz4s5HTej 2UwSEsYAmIggs6E4JTWWy62bRWHP34i2d6mrIOq1ikbAsKjKe7kpLasuagfG9pPG6vy7WXwzpuW JEN9spnBs4MxM2VPJxfZxBQYutpX20Hu7/PDowxJXPfS9gwUEpJOBx66RMWV6LUqIH8hd0uHgH7 BSR2KQY87vZvNTC0KiBgg2pmg2PRJHNKO7ofiUwVbaoOqWBrbarSW9Y6BjwUC1D3I7+/AO/nwUo A8wvH43+obG5FJF9bTL60Idre7KfqHE0ZshY27Q/AlcqZTQWUto/sFWBouPPuBVCCpr7zgT0YlI T/4FpxQdU2cBFmsRMLrysxx2RSomYnK0lKbZ9ASnI+ngJmN8LcqpC9olwTW9zM/tCVHBiniB/+Y M0V6rfHb0Q1Q1PyQxzg==
X-Proofpoint-ORIG-GUID: K5JYVxc1S9BEsszoW-TJ1JP8ofFwzTv9
X-Authority-Analysis: v=2.4 cv=N4oZ0W9B c=1 sm=1 tr=0 ts=69f8a9b5 cx=c_pps a=FAnPgvRYq/vnBSvlTDCQOQ==:117 a=FAnPgvRYq/vnBSvlTDCQOQ==:17 a=z/mQ4Ysz8XfWz/Q5cLBRGdckG28=:19 a=lCpzRmAYbLLaTzLvsPZ7Mbvzbb8=:19 a=xqWC_Br6kY4A:10 a=NGcC8JguVDcA:10 a=VkNPw1HP01LnGYTKEx00:22 a=gQcMVamqm3wCPoSYhaRC:22 a=6XKncaru_qjgLvANlS_8:22 a=Ubnf9b6nB-N69V6f-HIA:9 a=wPNLvfGTeEIA:10 a=oE-bL9if1irO6nRDaiMA:9 a=Yredg8S5_qywQ7tR:21 a=frz4AuCg-hUA:10 a=_W_S_7VecoQA:10
X-Proofpoint-GUID: K5JYVxc1S9BEsszoW-TJ1JP8ofFwzTv9
X-HPE-SCL: -1
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-05-04_04,2026-04-30_02,2025-10-01_01
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 bulkscore=0 adultscore=0 priorityscore=1501 lowpriorityscore=0 spamscore=0 suspectscore=0 clxscore=1011 impostorscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2604200000 definitions=main-2605040148
Message-ID-Hash: ZGNJACCDERS3MXK3OC2BOLMY4A2PXHD6
X-Message-ID-Hash: ZGNJACCDERS3MXK3OC2BOLMY4A2PXHD6
X-MailFrom: ronald.bonica@hpe.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tcpm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "ebiggers@google.com" <ebiggers@google.com>, "Li, Tony" <anthony.li@hpe.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [tcpm] draft-ietf-tcpm-tcp-ao-algs
List-Id: TCP Maintenance and Minor Extensions Working Group <tcpm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tcpm/bLkg4jn-dEUZWf-Xws-8ExeA62A>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tcpm>
List-Help: <mailto:tcpm-request@ietf.org?subject=help>
List-Owner: <mailto:tcpm-owner@ietf.org>
List-Post: <mailto:tcpm@ietf.org>
List-Subscribe: <mailto:tcpm-join@ietf.org>
List-Unsubscribe: <mailto:tcpm-leave@ietf.org>

Folks,

In a series of off-line discussions, Eric Biggers and I have agreed that the draft should include only the following KDFs:


  *

KDF_HMAC_SHA256

  *
KDF_AES_256_CMAC

And the following MACs:


  *

KDF-HMAC-SHA256-128

  *
KDF-AES-256-CMAC-128


Does everybody agree? If so, I will update the draft accordingly.

                                                                                             Ron