[TLS] Re: New Version Notification for draft-tls-reddy-slhdsa-00.txt
Bas Westerbaan <bas@cloudflare.com> Mon, 04 November 2024 17:37 UTC
Return-Path: <bas@cloudflare.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E9497C20C8C2 for <tls@ietfa.amsl.com>; Mon, 4 Nov 2024 09:37:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.105
X-Spam-Level:
X-Spam-Status: No, score=-2.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gOhW2AVDL4Qf for <tls@ietfa.amsl.com>; Mon, 4 Nov 2024 09:37:10 -0800 (PST)
Received: from mail-yw1-x112d.google.com (mail-yw1-x112d.google.com [IPv6:2607:f8b0:4864:20::112d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D4BA1C1DFD25 for <tls@ietf.org>; Mon, 4 Nov 2024 09:37:10 -0800 (PST)
Received: by mail-yw1-x112d.google.com with SMTP id 00721157ae682-6ea7c9226bbso21653897b3.3 for <tls@ietf.org>; Mon, 04 Nov 2024 09:37:10 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1730741830; x=1731346630; darn=ietf.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=q42LG4ykDRO0//nzTyXn2TtIIw+qX6HGaNwBVeBSTX8=; b=bTT7iHRoypBP8fR51frwuGhN8IBS9FvpUXS1STxn+OjbU6lPbF3T2cgm7jCCMwS0cy yhojDss3AzA5awtbWQfu1/Tviu3RAM/qt3ZMpyVM3I6pBHupfKomTmfaLFckDQcTS6f4 yJyd1WzLpGDT/YPNnmStQ6v05yXr9zFH8BZdjfk/0adzY8iW9YkqsxbootwwwdBJHBrK mS5jkQ+DrGky5/7HccpSLDrermw46CnkEa0nAR5AnUN+a2G6k0hz7PMLnvdPefH3H/rR TgdwAyp5fYN6p0FquB/lDkJ6uFrtesYVk5n8GCGGOV6sw41trmm0bw+/bsG8IFb3NneY D40g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1730741830; x=1731346630; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=q42LG4ykDRO0//nzTyXn2TtIIw+qX6HGaNwBVeBSTX8=; b=dR+knTcyztCFY9/0ezWr0pSq53jafawut3M2WhU8aHSXRi1NxjNR5neM0Z8ed+P9MC +TIMYsxLH0zdpcSVragwTrmcEXbL19WD7VbsiyQajw6y/vqFh5H3AS9d83m3rjiGx8bK OD0INjAdFv1tnQRh4ctvG8zVagFndnfE4hnrByeC1TxaM5rBk5pwFMdZbEBRma5LQjjw csIGdTDotRAsmpN2GMKKPW6VtnTBlFOpLwdu6dRBfrhSFAlnU3XqJ+5MsubJIRVk+knY Gk+MdY0DbkF/KhOONmFgNJZpgm9XM4fSnKTmJd3QnWIbClabLfI/Wzg+xeWgQwEoMVdQ +rYA==
X-Gm-Message-State: AOJu0YzaTclUU42xUZrtxTa0p0GGB+W+E+odStvUSc8Bc3n9mSdTIUrP rqAliPXkoGTrFGoyaH5BmcrTsHTDH0/jsO10H0ZR2hL87e9PEgkbIolXdj2nB24iwZMs32pXGRU j5vqgnezBwjjpX4kyypd+omHjVlhImrhI5u4R/umnvuCBfYYzAkM=
X-Google-Smtp-Source: AGHT+IGogxqSfCnnJRymEHpSNgR8eRGfC5Mwcz9/4dFLwrp8ADaSG69rXEZWAZDMfqJSqwvzlKuubwJcSWg/fTdWFww=
X-Received: by 2002:a05:690c:660c:b0:6b0:70fc:f6e4 with SMTP id 00721157ae682-6ea3b897484mr182797087b3.15.1730741829758; Mon, 04 Nov 2024 09:37:09 -0800 (PST)
MIME-Version: 1.0
References: <LO2P123MB7051227463A7583A1E6C023DBC502@LO2P123MB7051.GBRP123.PROD.OUTLOOK.COM> <20241104172928.395503.qmail@cr.yp.to>
In-Reply-To: <20241104172928.395503.qmail@cr.yp.to>
From: Bas Westerbaan <bas@cloudflare.com>
Date: Mon, 04 Nov 2024 18:36:58 +0100
Message-ID: <CAMjbhoWN=y=uNMSLS-Rv68fkEEvZnxW2p==24CzcARt-iSJKzQ@mail.gmail.com>
To: tls@ietf.org
Content-Type: multipart/alternative; boundary="000000000000f612dd062619bbec"
Message-ID-Hash: Y6IJCUMILX5L7AQWUCRXJ4YTVLCZEHHW
X-Message-ID-Hash: Y6IJCUMILX5L7AQWUCRXJ4YTVLCZEHHW
X-MailFrom: bas@cloudflare.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: New Version Notification for draft-tls-reddy-slhdsa-00.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/1baGwrkRaJGl2XyU3ZxhnvOer98>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Mon, Nov 4, 2024 at 6:31 PM D. J. Bernstein <djb@cr.yp.to> wrote: > Speaking for myself, not on behalf of the SPHINCS+ team (or other teams > potentially relevant here). > > Peter C writes: > > Under realistic network conditions, TLS handshakes with full SLH-DSA > > certificate chains seem to be about 5-10 times slower than traditional > > certificate chains and, in some cases, can take on the order of > > seconds. > > For, e.g., sphincsf128shake256simple, a quad-core 3GHz Intel Skylake > from 2015 handles 85 signatures per second and 1300 verifications per > second. (Source: dividing 12 billion cycles/second by the cycle counts > given in https://bench.cr.yp.to/results-sign/amd64-samba.html.) > > Sure, one can come up with scenarios where this isn't fast enough or > where 17KB for a signature is a problem. But there are also environments > where these costs are negligible compared to the transmission and > processing of user data. > Agreed. That SLH-DSA is clearly not suited for all use cases for TLS, doesn't mean we should withhold it for those where it's acceptable.
- [TLS] Re: [EXT] Re: New Version Notification for … Blumenthal, Uri - 0553 - MITLL
- [TLS] Fwd: New Version Notification for draft-tls… tirumal reddy
- [TLS] Re: Fwd: New Version Notification for draft… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-tls-… John Mattsson
- [TLS] Re: New Version Notification for draft-tls-… tirumal reddy
- [TLS] Re: New Version Notification for draft-tls-… tirumal reddy
- [TLS] Re: New Version Notification for draft-tls-… tirumal reddy
- [TLS] Re: New Version Notification for draft-tls-… Peter C
- [TLS] Re: New Version Notification for draft-tls-… Alicja Kario
- [TLS] Re: New Version Notification for draft-tls-… Peter C
- [TLS] Re: New Version Notification for draft-tls-… Peter C
- [TLS] Re: New Version Notification for draft-tls-… Kampanakis, Panos
- [TLS] Re: New Version Notification for draft-tls-… D. J. Bernstein
- [TLS] Re: New Version Notification for draft-tls-… Bas Westerbaan
- [TLS] Re: Fwd: New Version Notification for draft… tirumal reddy
- [TLS] Re: New Version Notification for draft-tls-… Russ Housley
- [TLS] Re: New Version Notification for draft-tls-… Alicja Kario
- [TLS] Re: New Version Notification for draft-tls-… Peter C