[TLS] Re: [EXTERNAL] Re: Fwd: New Version Notification for draft-yusef-tls-pqt-dual-certs-02.txt
Ilari Liusvaara <ilariliusvaara@welho.com> Wed, 15 July 2026 06:23 UTC
Return-Path: <ilariliusvaara@welho.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id AA440117041D6 for <tls@mail2.ietf.org>; Tue, 14 Jul 2026 23:23:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784096632; bh=p2xgAQELWmiCuVTkBZHlCVqNspVKWLmUeIZclSVpu5Q=; h=Date:From:To:Subject:References:In-Reply-To; b=lT6v7wxd/gMe5s9EOabF7qHv+hWT/uSQKpypEbH8QrmTecCdHEnDDzVuG3HbUA3VV 3AW3/zUneeqZ8sQALdI88P+a3lcn7EPhdVbifI52PcRjdB5VQXYkx/ZPkFy0PGfd06 fdlqgAcyRCaHTW6jH1KvxwKT0gdQBaWPqlfaJdqk=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=welho.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PWxU4QjtxGxh for <tls@mail2.ietf.org>; Tue, 14 Jul 2026 23:23:51 -0700 (PDT)
Received: from smtp.dnamail.fi (sender103.dnamail.fi [83.102.40.157]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id C51B1117041CE for <tls@ietf.org>; Tue, 14 Jul 2026 23:23:51 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by smtp.dnamail.fi (Postfix) with ESMTP id 774E640978C6 for <tls@ietf.org>; Wed, 15 Jul 2026 09:23:50 +0300 (EEST)
X-Virus-Scanned: X-Virus-Scanned: amavis at smtp.dnamail.fi
Received: from smtp.dnamail.fi ([83.102.40.157]) by localhost (dmail-psmtp02.s.dnaip.fi [127.0.0.1]) (amavis, port 10024) with ESMTP id G0eP_Wa2lRqP for <tls@ietf.org>; Wed, 15 Jul 2026 09:23:49 +0300 (EEST)
Received: from LK-Perkele-VII2 (87-92-117-27.bb.dnainternet.fi [87.92.117.27]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: hliusvaa@dnamail.internal) by smtp.dnamail.fi (Postfix) with ESMTPSA id D856F40979CD for <tls@ietf.org>; Wed, 15 Jul 2026 09:23:49 +0300 (EEST)
DKIM-Filter: OpenDKIM Filter v2.11.0 smtp.dnamail.fi D856F40979CD
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=welho.com; s=2025-03; t=1784096629; bh=3Zzt3ynCEDSPWpS1Du4UxklXzYRRiTit8ML7VFvNcLY=; h=Date:From:To:Subject:References:In-Reply-To:From; b=QI4/gIjea0i8evjAXaKzmQN0U9y9XNVwwApMrDDcnytasbPUi/29w165cNPsfZoT8 dew6LxOX3cEy2n7FzZd8cQcU/i4uYrFCUVfqXXdK4ipwf6EGrshVLbX6lK1QeHuI5F ov4zwJqqbhVFCzYVpZJZIB2S8px74MPhjnh1gYWE0BB2Ye0mmf6SN/43i+sbNuUhxX 96gdprwIB8IoFKu7uJHZbMMfEqdaPMdi1A9/9RDdZtxhGi5pI5oeR9M5NeMJhNwuLo B2vMy+pq6NfVkzOuSx9JMl6dijK9ShcTcs/9tfl8DZ5UVH7oqgAv3wg5/lJtvuxaw8 /n/gQfDbJNg4w==
Date: Wed, 15 Jul 2026 09:23:45 +0300
From: Ilari Liusvaara <ilariliusvaara@welho.com>
To: "<tls@ietf.org>" <tls@ietf.org>
Message-ID: <alcncU1LPzCRB0Xw@LK-Perkele-VII2.locald>
References: <178228974031.1336043.8757141113647810543@dt-datatracker-f9b87776f-xzl65> <CAFpG3gcOChbpjRMAJhwErFRoFcJgtf=C9d0KLeAoQGxG+OxFgA@mail.gmail.com> <CABcZeBPo0Z4YFAR7Gmeo0xWpEscEXt+Do25n7Pxga5zOwULf0A@mail.gmail.com> <CADNypP-8c1+Zqo1SVjyz1MHWeAWzd7keX-W2tjz-vFj6JnZ8wA@mail.gmail.com> <CABcZeBOu5HU-Mcrepz-VzOuuBCP=chhPZFbGLwT9XQeAi91QyA@mail.gmail.com> <alZ1jj4wZbP_bL2v@LK-Perkele-VII2.locald> <PH3PPFA3FE8A23FB757085EDC789AED320FC1F92@PH3PPFA3FE8A23F.namprd11.prod.outlook.com> <alaX9QaSjTlJpIWy@LK-Perkele-VII2.locald> <CHAPR11MB9631A945EE35E1629FDD396BEAF92@CHAPR11MB9631.namprd11.prod.outlook.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
In-Reply-To: <CHAPR11MB9631A945EE35E1629FDD396BEAF92@CHAPR11MB9631.namprd11.prod.outlook.com>
Sender: ilariliusvaara@welho.com
Message-ID-Hash: 7PMDPER7YJU6Y74MPU26ZZNT6KB6DO5T
X-Message-ID-Hash: 7PMDPER7YJU6Y74MPU26ZZNT6KB6DO5T
X-MailFrom: ilariliusvaara@welho.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [EXTERNAL] Re: Fwd: New Version Notification for draft-yusef-tls-pqt-dual-certs-02.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/1YAIQUVHODWhQPVoxCurpbeSmMs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Tue, Jul 14, 2026 at 09:10:43PM +0000, John Gray wrote: > We need to support composite authentication in private PKI use-cases. > In a private PKI, it is easy for us to issue composite certificates. > We have business to business applications which communicate via TLS > and they make use our PKI issued certificates. We need to be able > to use composite authentication between them. Sure, if the private PKI has associated security profile standard, that should work. > >With composite certificates, the combinatorial explosion occurs directly > >in certificates, which is the absolutely worst place to have that in. > > As Scott said, Composite signatures are just a signature algorithm, > and they already have IANA registered OIDs. At the certificate level, > they are just a signature. The certificate logic doesn't need any > changes. The issue is not in implementation, but in operations. > By the way, I'm not against the multi-certificates draft either. I > don't agree that there has to be 3 PKI's in a transition... > Traditional - > PQ/T -> PQ. Once you are on a PQ/T, you don't > need to be in a hurry to migrate away from it. If EC/RSA is broken > by a CRQQ, then composite ML-DSA is close to as good as pure ML-DSA > at that point, so why would you need to expend the effort to move to > the pure ML-DSA when you are already essentially there? Unfortunately, there is the zombie crypto risk. > A word of caution: When we originally designed composite signatures > back in 2019, we tried to make it flexible in a similar way as > multi-certs. We defined s structure called composite that specified > the algorithm identifiers for the algorithms that make up the > composite. The LAMPS working group told us it was a "foot canon" and > that implementors would choose the worst possible Insecure > combinations, and that we needed to take the choice away. While that sort of design seems very problematic for other reasons (which do not apply to dual certs), it is not because of folks picking insecure combinations. In practice, insecure combinations seem to be extremely rare at worst. -Ilari
- [TLS] Fwd: New Version Notification for draft-yus… tirumal reddy
- [TLS] Re: Fwd: New Version Notification for draft… Songbo Bu
- [TLS] Re: Fwd: New Version Notification for draft… tirumal reddy
- [TLS] Re: Fwd: New Version Notification for draft… Eric Rescorla
- [TLS] Re: [EXTERNAL] Re: Fwd: New Version Notific… Andrei Popov
- [TLS] Re: Fwd: New Version Notification for draft… Muhammad Usama Sardar
- [TLS] Re: Fwd: New Version Notification for draft… Rifaat Shekh-Yusef
- [TLS] Re: Fwd: New Version Notification for draft… Eric Rescorla
- [TLS] Re: Fwd: New Version Notification for draft… Rifaat Shekh-Yusef
- [TLS] Re: Fwd: New Version Notification for draft… Ilari Liusvaara
- [TLS] Re: Fwd: New Version Notification for draft… Scott Fluhrer (sfluhrer)
- [TLS] Re: Fwd: New Version Notification for draft… Ilari Liusvaara
- [TLS] Re: Fwd: New Version Notification for draft… Scott Fluhrer (sfluhrer)
- [TLS] Re: Fwd: New Version Notification for draft… John Mattsson
- [TLS] Re: Fwd: New Version Notification for draft… Scott Fluhrer (sfluhrer)
- [TLS] Re: Fwd: New Version Notification for draft… John Mattsson
- [TLS] Re: Fwd: New Version Notification for draft… Deirdre Connolly
- [TLS] Re: Fwd: New Version Notification for draft… Bas Westerbaan
- [TLS] Re: Fwd: New Version Notification for draft… John Mattsson
- [TLS] Re: Fwd: New Version Notification for draft… Rifaat Shekh-Yusef
- [TLS] Re: Fwd: New Version Notification for draft… Ilari Liusvaara
- [TLS] Re: [EXTERNAL] Re: Fwd: New Version Notific… John Gray
- [TLS] Re: [EXTERNAL] Re: Fwd: New Version Notific… Rifaat Shekh-Yusef
- [TLS] Re: [EXTERNAL] Re: Fwd: New Version Notific… Ilari Liusvaara
- [TLS] Re: Fwd: New Version Notification for draft… Erwin Hoffmann
- [TLS] Re: Fwd: New Version Notification for draft… Rifaat Shekh-Yusef
- [TLS] Re: Fwd: New Version Notification for draft… Erwin Hoffmann
- [TLS] Re: Fwd: New Version Notification for draft… Rifaat Shekh-Yusef
- [TLS] Re: Fwd: New Version Notification for draft… Erwin Hoffmann
- [TLS] Re: Fwd: New Version Notification for draft… Stephen Farrell
- [TLS] Re: Fwd: New Version Notification for draft… Erwin Hoffmann
- [TLS] Re: Fwd: New Version Notification for draft… Stephen Farrell
- [TLS] Re: Fwd: New Version Notification for draft… Rifaat Shekh-Yusef
- [TLS] Re: Fwd: New Version Notification for draft… Ilari Liusvaara
- [TLS] Re: Fwd: New Version Notification for draft… Watson Ladd