[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26)
John Mattsson <john.mattsson@ericsson.com> Fri, 28 November 2025 16:44 UTC
Return-Path: <john.mattsson@ericsson.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 479E2922BDAD for <tls@mail2.ietf.org>; Fri, 28 Nov 2025 08:44:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ericsson.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k6ncw6btEnwx for <tls@mail2.ietf.org>; Fri, 28 Nov 2025 08:44:04 -0800 (PST)
Received: from DB3PR0202CU003.outbound.protection.outlook.com (mail-northeuropeazon11010003.outbound.protection.outlook.com [52.101.84.3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EFB55922BDA6 for <tls@ietf.org>; Fri, 28 Nov 2025 08:44:03 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=lE1LkZPS/+qEUudhT4+RV9+gIZaZ0BomPtylYY0/teQm8GY4nPqJbMNwFPdFNC3yUCNXGHItjLSlxZJv0bAEFL7V8AwLFE1DCThGBkfEWUYSLR1RJBQOUrcBuDA3Uu90DJ1ihY+j0lPwvpPLUnd64UE62Kuu2Ma1APXCJIvErJexDuW6iWOBFofdvSDqg46JY0n3iD0efDhMTR/sKoZDjzC+5uaO1OHoCIj05cMkJEHVpFkOB9hIHIIAhNM9Pb7tbVXPqHAIcY0vxmvbiE1kQC938pJKthsxK3kYYCBQSfN6r57E4qHjtIbmNF7knB1N1iJRF07OGlVqwLK4H3JE5w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=RGGW9ikND3KKhvylWpNv64Z0vHCaR57lYbU1fdprH2U=; b=pYnwohI4yVPti73JUoPzn00hZOOmE73uRIkL9o+pzf3w8eFLjTOGT6jukgL0UqNgbb90vUFCpuU8xKqVicAR1gOoko6l07IxSctjG57lz1oSBWlk7Se9V2egxkZlI5XbQ3dCb+z2QObNSsrkW9r5HezAcbRTysQfW7Nywv3/btGp7F0Hpsy3U536mTPXt8o6o9GYRgE+XBxsKtGqNEMiTQssuRRw7PTb+zmn41EHxbZjjRyu5pq0tMgU7/bNPgSyriEcfV2ohd2mlPEUkM5kS0wxJVEVK6JLhCX7bfZgLl5zv9LmXlkdDutQQ0Y9Qet6MuIDJ+I9Gp4y0IKSr/ZrfQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RGGW9ikND3KKhvylWpNv64Z0vHCaR57lYbU1fdprH2U=; b=L2Qjfm1x3kIby+m9mP0C3RHSP1CvyncYmIb2iStef0LncMyd4ttZITClqAwBkfdl5I7hQZV3fZSIfpGY0QtW2LP4fGzOaAf6tjEKAv32HD+Xs4pigqiCEgKjOnDwfpy/M41LAWykGAsQlDJPHEq7c5Uf8Ct5YCwh3fovkcC/x5JurODCvivHRmE0rO/Wm3ksdoFjoZIO7cKqgyd9I0B+LKJ2GMTfzw7Q8w9CNYjg5LF2ab2/C3aVikgc6nXTS576adkaBpEWjhR1vb3w0wpxWRv8Eu9X2fTrHG9nvSBLBAJ08vJc53j3P3Ju6LRRCdBsoyvYCcCIjUvhot1taVkxqQ==
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com (2603:10a6:150:114::10) by PA4PR07MB7456.eurprd07.prod.outlook.com (2603:10a6:102:cf::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9366.15; Fri, 28 Nov 2025 16:43:55 +0000
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::bcf3:3f45:888e:a4b8]) by GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::bcf3:3f45:888e:a4b8%3]) with mapi id 15.20.9366.012; Fri, 28 Nov 2025 16:43:55 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Deirdre Connolly <durumcrustulum@gmail.com>
Thread-Topic: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26)
Thread-Index: AQHcYDCeQBPyhE37cE2C33OwvtXsX7UILXOAgAAeH2I=
Date: Fri, 28 Nov 2025 16:43:54 +0000
Message-ID: <GVXPR07MB96789138C31A816AA0E5CA4089DCA@GVXPR07MB9678.eurprd07.prod.outlook.com>
References: <GVXPR07MB9678B44C77FACE5495ABD97789DCA@GVXPR07MB9678.eurprd07.prod.outlook.com> <CAFR824xWR2xQmTF20JKyFc-wDoOSYHCc-MLizqV5MABTGBwcxQ@mail.gmail.com>
In-Reply-To: <CAFR824xWR2xQmTF20JKyFc-wDoOSYHCc-MLizqV5MABTGBwcxQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GVXPR07MB9678:EE_|PA4PR07MB7456:EE_
x-ms-office365-filtering-correlation-id: 3abcf727-4633-4905-e50d-08de2e9d51cb
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|4022899009|1800799024|376014|366016|38070700021|13003099007|8096899003|7053199007;
x-microsoft-antispam-message-info: xNKWChJiXheMFvFo4fXH80RB86PRAilLxNlQzxXAWy1y4Bq/k//p8KqyeSTMLXQgo8KpKAScEGheluNTFKVqxYAAQfrnGWp2dKepw2iCLAsMuP+dEEExzne4kp+n9keGozS6GHww6u9owprh4eh9AWtTGlwLi7riORtgzODiICT5EcUyDMIWHlbUWQqZNmGbsAxh6VfgFDhqjlE432g+3WCyLOQfkPTJgr7/Oorlr9KPweR7dtfRyjQ1OcveF7Rj9jEYKhIhvUZVUfU6c4eKP1XP78zUdcsoWbsfvwh3IItQVfqrROR5IO5nYTUSTDfstdeGr+BW2SftmcCXKoQ/VeRj/hEh+k1de+2Oc4SRitcdwWKODCK3BR20ylJYisAo/Xmj2YAZE56b5RxO8GI1KaYdRYt+XMuIQH/mDwGTUBGpnIe/DIzcTKIGj5966Mt0w3t7FEe7Mllumb1K1dUnvfWeQEAiza/Ee3MdW03BAxjwgoTI+zA3FCbJejkofIXJ8vx9X033u+XYJ/kuj9hVAl090ll+ybN52gztjMPqx9Am9fr9E/s6lpL6nesgUL/KbqAC/mUdAZy+zInIqcB0LpMOYbW4WhLV6Py2uVj9d4f13Fa9CPcYKQkKAdu0NbJ+HScf+xz/gsKZrDaXZAsz/lnDBhqPM08zj9618aboC9uRTQQYfJLpd7PNa6+Db+qiN0awzFUaGrg5KPDrmnTuFHP+xH0p5Ru3BkS1t/L7cTypqpBsfV3nhHqu8+d/Ibmxqwd7484KNqwqyZb0gf5/yHbE0N+sr6mylum8p1edAMSNC/YM1ZkZJfTGbU4X6BR6ZIqNWNOH4nHkUc2IvfQDOa4MNRlIEpBqAjIeOAKSi5slQVy7oJ12OCF59RviN+Dz+CnqfT+DPMrKagK2vMHBPSWsu3x3XHDK/Kb7Zpzaa/iReOblqj4Zf/Whv3lAXGPW8VMMa5RksUtxt5IX843YKd8jh72jG27tPWzbNr0ek0/irkDCmDRdlpxq68tofph37bh6gpH9BTDsS8s2dWWnUp8YsRWew+XvcR4cFyMaL11IMbxQ/wl+FXVqAY4dt8tvI+Vqmd04pdskhSz63G89e2NnrECLyssUuJI2teEWiwtr4vhCCLGfdWBAYX/qnd8Uo8KhXk4tdvqNt1TuOc9T4Q0mNP3zzLbqwIRFl9+HvmMm3XGPj656LYmQ3+qK2vrurICm6WU8R8iuRwNUse/R328tkPemAug1SqEnybA9mlfEYNFuhuxJuaNT91Ox2L3qd9sky9SMtUtENNv53f8zpbzjE9rO7gUyiq2ugY7ZJBl2rYyWvuzJvJlUN9XpzFeGcqVJ2kwcWbQgkFhtgmmBfuzX8NqIDUfEgtJNCeljkoy1vRW38bWIqiK+uvKOYAiE1Ym10OQG744ORSgyvR9oibItIufdeNRYAs5UPyD0SJfKURXmLC52Odijq7IqskjG
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:GVXPR07MB9678.eurprd07.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(4022899009)(1800799024)(376014)(366016)(38070700021)(13003099007)(8096899003)(7053199007);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: qkqz2ikJjlyr+XxltLtw5mo1v7WWMldbjIVnmguWnehMwBIwwB2fDOsBkYfyAhkK//Wx6c/g7cNdjiM9PAuDHqTdq/DqVbH37GmHtoQ3YPHlatBLqbIDirhc8Jf4ZGRMHdhI+2l2T0Ga1zax/1c6LhMRtYTuPSSJrfGdwmmNJJudqvhBfof42V48KYucjtgfdaGOvAN7kLlvVDr46HAsxI0HMC7PWB9pqQOIXbLpOX9z9nWftq69ejVMChF7aKV5497BeoYBnrMgu2g+ThfKdE9UmERw9jx5Bl7YQN+ZNTKeTIRNhlyNfHIF5Rt/0ba4tCe3Mx5phKt8v3gBBm58E3yRlLwuWt5z7yCm9xPF5TOA9Q8snFS9G2hVI2WN3h9y2JO7MMcIZhZt8sI7IUTmKnx+td5Z+g1ZLRCM1X8NUQ28CJA7MUV3PQfeiKRXNHWpEOBRxFn6PGJHYZyeNuTAES6pOYvPUiLnby2mDhrTWHupIT5dPUlgA02VEfRka3lAejQf/elK/UQONJy8s6g/J/rbD6NyVIrY4b7iA2eydTznjjDYo27EuJx7GzvpwpOiIkNozLwxwK8i3TN1Xe0VktFS/JzYcu3tKhmE2CNRzO283q8fMbgUtUwyQYZG9x0E6Ie1GLFQUdiiLfw0HNL5m5TezNkLeomakffpQdgPOQuvvLiBJ3gFrp6asYgenUwpmquUvcH/0YpHNA93h4KQIB9JJHpcPI/k7deA+I8k7l7jvfLrHnVmd4K/4aBglswIkiMNpmu7gEDC0bA+PAE3VdWaZAvTId6NjPlAS92xt+lNoIGL7c43oLt3zWxY/LnLS+MoAfc41u8ox3eGqPk88kx/5aCV/+DSyS2ORg9zRdPeNo8HG8pKCeRoNYiYZwTaSHCowaNzIpsJDNS8hZsodw/QaiPFOTb3Clo0BMGC4DSk6obEQP4Wsa3kRYSWYQMlw/859U0i+P8pyFdoLDYelCRwDJW0SE6y5aG3CGkKmWQQg0oqwZScwPdit0pwArvSKyDl9/wc0knDuzKDkCFOvK38NNdPxdYSDz7DKFK6C92YDWOy/f2P9E6MlIYC3GhJXt29qD/SvAFV0KtSVPhOD/YUiv7uGg11u1SCCylxr3eh29o/aFiUJkEIHTzxJkSXn3Q1Lao0wkSNs0o+LXuKnJrXCYxvC+u2Do6+bBM8E+cG4MIk7tfG2p74wdZhnsqALoFEQGMJkLKmGoPnF/6hw08fLHfzPEIbcTWtQSH27coZKBquP/AR7A0paHDbFrT1jI+oWh8w/EuoySQSA4eIyDlGKkHlooYlL7+jgnpkqYHIZYWrsBcIb5vbXkqCi0COLcP/gupgBc/Gay241uk4jC7RFq8UN8Cz3wsae/mQoQdJ6N77lI65hQuXpB+PVyD4Ssacf/geyskTk8O4PktFOPhLfWECrcnHy9V2UcvNRZ+3DrrFMuWxk9FqVDH7kwE5jmrw6tuOB4ixJpWhkHrNweugV9oLlj76sqrWm98qQ0YJxUy/ZgVkOYUa2T5dP/KSZcIU+Zczx5kaCDndw0bflsdBXTy94p1T9Sg12zNStOKSqBkqnAjlE2bSLn1VSAjyZwLUGFpcZscObx6rPmVYqRxoS9XDVJoJgrsQM7vMwGo=
Content-Type: multipart/alternative; boundary="_000_GVXPR07MB96789138C31A816AA0E5CA4089DCAGVXPR07MB9678eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GVXPR07MB9678.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 3abcf727-4633-4905-e50d-08de2e9d51cb
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Nov 2025 16:43:55.0072 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: gCR0mXrtDMZuK+Ok32p3aaBYndnPEINDnwUqnuZVWF7/zK+DLh0mA97Ktm6rqTixYCUpZ9FiuKDHlg8eTffLYayzFnF9/QP8Mwu32zYhh/I=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA4PR07MB7456
Message-ID-Hash: POCCNQIPISTFFPGNT5UP2XRFWWHZO552
X-Message-ID-Hash: POCCNQIPISTFFPGNT5UP2XRFWWHZO552
X-MailFrom: john.mattsson@ericsson.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "TLS@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/2YqMFCLq1E7TrrnOtG8VX7PWdgE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
I missed that Meta used ML-KEM-512 as an optimization. My interest was for middlebox traversal when connections using X25519MLKEM768 are dropped. In those cases, the fallback options are X25519 or ML-KEM-512. Today it could be argued that the risk of implementation bugs in ML-KEM is higher than the quantum threat to X25519, but that balance will shift in a few years. My interest in TLS is internal telecom networks, not the public Internet or enterprise environments. I hope I am wrong, but my expectation is that some middleboxes blocking X25519MLKEM768 will still be around in 2030–2035, when I would prefer to phase out standalone ECC. John From: Deirdre Connolly <durumcrustulum@gmail.com> Date: Friday, 28 November 2025 at 15:57 To: John Mattsson <john.mattsson@ericsson.com> Cc: Stephen Farrell <stephen.farrell@cs.tcd.ie>, TLS@ietf.org <tls@ietf.org> Subject: Re: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26) > Yes, Meta has a good article on the topic > https://engineering.fb.com/2024/05/22/security/post-quantum-readiness-tls-pqr-meta/ This is a good article— I want to highlight that Meta deployed Kyber/ML-KEM-512 only on their internal connections, and don't seem to have any plans to roll that out to their external connections. While -512 nicely fits existing infra, and I agree it should be available especially for IoT settings and internal deployments like Meta's, in general public internet settings it seems to be a a little riskier as a right-on-the-line parameter set for NIST Level 1 security than say -768, which has more headroom security-wise. On Fri, Nov 28, 2025, 2:17 AM John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org<mailto:40ericsson.com@dmarc.ietf.org>> wrote: Hi Stephen, >Do you know if anyone's written up a description of that? Yes, Meta has a good article on the topic https://engineering.fb.com/2024/05/22/security/post-quantum-readiness-tls-pqr-meta/<https://engineering.fb.com/2024/05/22/security/post-quantum-readiness-tls-pqr-meta/?utm_source=chatgpt.com> There has also been quite a lot written about middleboxes, load-balancers, and other software that assume the ClientHello always fits in a single packet. See e.g., https://blog.cloudflare.com/pq-2025/ https://www.ietf.org/archive/id/draft-reddy-uta-pqc-app-07.html Just looking at the key share sizes, it is quite easy to see that you can use ML-KEM-512 (800 bytes) and would have been able to fit X25519MLKEM512 (832 bytes) and still fit ClientHello in a single packet. It is also quite easy to see that it for many PMTUs it is problematic to fit ML-KEM-768 (1184 bytes) and X25519MLKEM768 (1216 bytes) in a single packet. https://datatracker.ietf.org/doc/draft-ietf-iotops-security-protocol-comparison/ https://tls13.xargs.org/#client-hello https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.203.pdf While it did argue for X25519MLKEM512 (and X448MLKEM1024) I did not understand at the time that I would have wanted X25519MLKEM512 for middlebox traversal. Then I would have argued harder for X25519MLKEM512. The current situation is that OpenSSL 3.5 LTS has shipped with X25519MLKEM768, ML-KEM-512, ML-KEM-768, and ML-KEM-1024 and even if TLS WG standardise X25519MLKEM512 now, it will take several more years until it would be added to a OpenSSL LTS, which a lot of infrastructure is based on. That would make it hard to meet 2030 deadlines for PQC migration but would meet 2035 deadlines. I can live with ML-KEM-512 for middle box traversal, but if TLS WG does not publish ML-KEM-512, I would suggest that X25519MLKEM512 is added to draft-ietf-tls-ecdhe-mlkem. (Regarding misbehaving servers, if they don’t handle fragmented ClientHello they likely don’t support ML-KEM anyway and you need to retry with standalone X25519. Middleboxes and load-balancers is the big problem) Cheers, John On 2025-11-27, 20:43, "Stephen Farrell" <stephen.farrell@cs.tcd.ie<mailto:stephen.farrell@cs.tcd.ie>> wrote: Hi John, On 27/11/2025 16:02, John Mattsson wrote: > - ML-KEM-512 is the only adopted quantum-resistant algorithm that > can be used to bypass legacy middle boxes. Do you know if anyone's written up a description of that? Thanks, S. _______________________________________________ TLS mailing list -- tls@ietf.org<mailto:tls@ietf.org> To unsubscribe send an email to tls-leave@ietf.org<mailto:tls-leave@ietf.org>
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Quynh Dang
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Bas Westerbaan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Kampanakis, Panos
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Loganaden Velvindron
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… David Adrian
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Rebecca Guthrie
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Flo D
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Kazuho Oku
- [TLS] Fwd: Re: WG Last Call: draft-ietf-tls-mlkem… Keegan Dasilva Barbosa
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Bob Beck
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Bellebaum, Thomas
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Bellebaum, Thomas
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Russ Housley
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Watson Ladd
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Jan Schaumann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Wang Guilin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Kurt Roeckx
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Kampanakis, Panos
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Bellebaum, Thomas
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Benjamin Kaduk
- [TLS] WG Last Call: draft-ietf-tls-mlkem-05 (Ends… Sean Turner via Datatracker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Watson Ladd
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… richard
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Stephen Farrell
- [TLS] Deployability claims D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Bas Westerbaan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Bas Westerbaan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (… Joseph Salowey