Re: [TLS] WGLC for draft-ietf-tls-hybrid-design

"Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com> Wed, 17 August 2022 19:06 UTC

Return-Path: <sfluhrer@cisco.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E664CC1524B8 for <tls@ietfa.amsl.com>; Wed, 17 Aug 2022 12:06:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.605
X-Spam-Level:
X-Spam-Status: No, score=-9.605 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=FwAk4JWh; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=ucohJAFC
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iGymsGbHTals for <tls@ietfa.amsl.com>; Wed, 17 Aug 2022 12:06:54 -0700 (PDT)
Received: from alln-iport-5.cisco.com (alln-iport-5.cisco.com [173.37.142.92]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B9B0FC1524B1 for <TLS@ietf.org>; Wed, 17 Aug 2022 12:06:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=5194; q=dns/txt; s=iport; t=1660763214; x=1661972814; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=XD4/q8IEsLKBIi3HxKUYWgU3q82bTkVaasNdD0Lqm0w=; b=FwAk4JWhueKXNuCLnIFHgpm4JFTCybwE8YajWFujkCS6+i9UqhBA97Jw fI5a4DJ9cu9sTZQGEO/yWzlvAH376PJw8yvWR2sngwjuq+WSMOfn+fmCn X5nZQnB0qlTv8ERIvr8WPUPcztKLfmD+/ac60HiUwWA40ujy5XAdlmSyL Y=;
X-IPAS-Result: A0AcAABOO/1imIoNJK1aHAEBAQEBAQcBARIBAQQEAQFAgTwGAQELAYFRUn8CWjpFhE6DTAOFL4UMXYIlA5tTgSyBJQNUCwEBAQ0BASwLCwQBAYFTgzQCFoRjAiU1CA4BAgQBAQEBAwIDAQEBAQEBAwEBBQEBAQIBBwQUAQEBAQEBAQEJFAcGDAUOECeFaA2GQgEBAQEDAQEQEREMAQESGgwLBAIBCBEEAQEBAgImAgICJQsVCAgCBAESCBqCWwGCbQMyAwEPm2kBgT8Cih96gTGBAYIIAQEGBASFERiCOAMGgREsAYMkhGCHQiccgUlEgRVDgmc+gmIBAYE4KhWDPzeCLpkoHDcDRR5CAwtSCAkXEhAQAgQRGgsGAxY9CQIEDgNACA0DEQQDDxgJEggQBAYDMQwlCwMFDwwBBgMGBQMBAxsDFAMFJAcDGQ8jDQ0EGAcdAwMFJQMCAhsHAgIDAgYVBgICGDY5CAQIBCsjDwUCBy8FBC8CHgQFBhEIAhYCBgQEBAQVAhAIAggnFwcTMxkBBVkQCSEWBg4aCgYFBhMDIEkmBUUPKDIBNTwrHxsKgRIqCSAVAwQEAwIGEwMDIgIQLjEDFQYpExItByt1CQIDImkFAwMEKCwDCSAEHAcJIiY9BQVfEigBBAMDEyI+mD2BK2E+KjsIECA7PRw3GpMIOIMiqzcKg1KgPhaobJcCIKIPhQECBAIEBQIOAQEGgWMDghBwFTuCZ1EZD44gDA0Jg1CFFIVKdTsCBgEKAQEDCYg6gkcBAQ
IronPort-PHdr: A9a23:epuZ+h+DbG8yc/9uWCXoyV9kXcBvk7n3PwtA7J0hhvoOd6m45J3tM QTZ4ukll17GW4jXqpcmw+rbuqztQyoMtJCGtn1RfJlFTRRQj8IQkkQpC9KEDkuuKvnsYmQ6E c1OWUUj8Wu8NB1eGd31YBvZpXjhhQM=
IronPort-Data: A9a23:F2XxDa1vVn8/J4PkVfbD5cxxkn2cJEfYwER7XKvMYLTBsI5bpzJTy 2oaUD3XMqrZZjH1fIsgaYWz8EIO7JDUx9Q1QAs53Hw8FHgiRegpqji6wuYcGwvIc6UvmWo+t 512huHodZxyFjmGzvuUGuCJQUNUjclkfZKhTr+fUsxNbVU8En152Us8w7RRbrNA2LBVPSvc4 bsenOWHULOV82Yc3rU8sv/rRLtH5ZweiRtA1rAMTakjUGz2yxH5OKkiyZSZdBMUdGX78tmSH I4vxJnhlo/QEoxE5tmNyt4XeWVSKlLe0JTnZnd+A8CfbhZ+SiMa7ogSbdMHOVhupA6LsZMyk vdWhMavVlJ8VkHMsLx1vxhwGiV6O+hN/6XKZCX5us2IxEqAeHzpqxlsJBhpZstDpKAuWicXr qxwxDMlNnhvg8qtzramSvNhnOwoLdLgO8UUvXQIITTxXKx7G8+THPibjTNe9DkegoNcB9KAX M9HTRRoYVPKfxkVPn5CXfrSm8/x1iWgLFW0smm9mY4My2ne0AI316LiWPLUftWQRMFUg12Gr 2vc9kzmDxUaM5qUzj/tz563rubLmSW+U4UIGfjlsPVrm1aUgGcUDXX6SGdXv9GFpGfncskPN HU7wSgA7uto1leaFMbiCkjQTGG/gjYQXN9ZEusf4Q6Ly7bJ7wvxOoTiZmMaADDBnJJrLQHGx mNljPuyXmU27+P9pWa1s+bK82zjYED5OEdYPUc5oR05D84PSW3ZpjvLSttleEJepoKoQWirq 9xmQdRXuln+pccP06P+9lfdjnfx4JPIVQUyoA7QWwpJDz+Vhqb4N+RECnCCsJ6sybp1qHHa5 RDofODFtogz4WmlznDlfQn0NOjBCwy5GDPdm0VzOJIq6i6g/XWuFagJvm8mehg1bJxUJmS3C KM2he+3zMIDVJdNRfInC79d9+x3pUQdPY2/D6uNPoYmjmZZLVXbpUmCmnJ8L0i0wBRzzsnTy L+QcN2nCj4BGL97wT+tL9rxIpd1rh3SMVj7HMihpzz+iOL2TCfMFd8tbQvfBshkvfjsiFiEr L53aZDQoz0BC7KWX8Ui2dNJRbz8BSJlVcmeRg0+XrPrHzeK70l7V6GOn+p7J9M190mX/8+Rl kyAtoZj4AKXrRX6xc+iMxiPtJuHsU5DkE8G
IronPort-HdrOrdr: A9a23:GMLuvqFkvvR3CqgnpLqFVZHXdLJyesId70hD6qkvc3Jom52j+P xGws526fatskdtZJhSo6H9BEDmewKQyXcV2/haAV7GZmjbUQSTXfhfBOfZsl/d8mjFh5RgPM RbAuRD4b/LfCBHZK/BiWHSebtBsbq6GeKT9JzjJhxWPGVXgtRbnmFE43GgYypLrWd9dP8EPa vZwvACiyureHwRYMj+LGICRfL/q9rCk4+jSQIaBjY8gTP+wg+A2frfKVy1zx0eWzRAzfMJ6m 7eiTH04a2lrrWS1gLc7WnO9J5b8eGRhOerRfb8y/T9GA+cyTpAV74RGYFqewpF5d1H3Wxa0O UkZS1Qe/ibpUmhOV1d6iGdpDUImAxelUMKj2Xox0cKZafCNWoH4w0rv/MBTvKR0TtQgPhslK 1MxG6XrJxREFfJmzn8/cHBU1VwmlOzumdKq59bs5Vza/poVFZql/1owGpFVJMbWC7q4oEuF+ djSMna+fZNaFufK3TUpHNmztCgVmk6Wk7ueDlIhuWFlzxN2HxpxUoRw8IS2n8G6ZImUpFBo+ DJKL5hmr1CRtIfKah9GOACS82qDXGle2OFDEuCZVD8UK0XMXPErJD6pL0z+eGxYZQNiIA/nZ zQOWkowVLau3iefPFm8Kc7gSwlGl/NLQgF4vsulaREhg==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.93,244,1654560000"; d="scan'208";a="925278759"
Received: from alln-core-5.cisco.com ([173.36.13.138]) by alln-iport-5.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 17 Aug 2022 19:06:51 +0000
Received: from mail.cisco.com (xfe-rcd-002.cisco.com [173.37.227.250]) by alln-core-5.cisco.com (8.15.2/8.15.2) with ESMTPS id 27HJ6pl0031453 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK); Wed, 17 Aug 2022 19:06:51 GMT
Received: from xfe-rtp-001.cisco.com (64.101.210.231) by xfe-rcd-002.cisco.com (173.37.227.250) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14; Wed, 17 Aug 2022 14:06:50 -0500
Received: from NAM04-DM6-obe.outbound.protection.outlook.com (64.101.32.56) by xfe-rtp-001.cisco.com (64.101.210.231) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14 via Frontend Transport; Wed, 17 Aug 2022 15:06:50 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=VEzdBcb2wlOjF4p8e1jnCmuIpA691VZvvvVaKqDFtC8zmT4nt97n4BU4DuYmbzvIrtS2Lp2cPlzBS99qiCY4aAqu3+WAfDNJa7BkIf7sEFgqL+B2h1M+j8Hwfgf08vVRC5JZeTHioVl9U3CbALzY8/+53sUANEQLKbUPQcH7jlgyQq3tjm2vmES8OJaw/uHMFG6oBLM5+nQhmkwhbIKTxb7PC0NToDCOkn6/3cyFUvxn5x9CCpV0MKJ91Sg8KRnPt0cIFznLU3DXiEo7Cw83LzXWdF57NnnPFjHtPgbIIctTGGOIkL1p4+GQG8ZJTtIa9V07JxUUlAn69gslvybRpQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=XD4/q8IEsLKBIi3HxKUYWgU3q82bTkVaasNdD0Lqm0w=; b=dfpdeJpNSqK/jb8S0FHKTzqG91BQCsWlrEj3yW0wQlM1BA8q82dqUGdiJ0E+0F+W+Wt5pi9I8fqZ/a5mxSy/BamuNTA6tCdEqlIVX1NdepUX46sn/cfbWfBjxpSZxUyc6JXht6YHRpasAnfRIseoGW8FUgvwtKKdN3CEnzHf14XNNUprOw/hABqAtQYw4A7Bltkj43pAQVz7e9t7ZKW2hKnl3inxNHHoNyLXieU5305ErwBQL+sHVtwWVM/GMM8Kz6Jrd0+4Ztk0fQDNUfT2fxwmmDCmhpJ+QUuTvTB1u6THoNIFmAKjMeETzXuzSQvfZ1HPgOovA0XQ0HQmWleD4Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=XD4/q8IEsLKBIi3HxKUYWgU3q82bTkVaasNdD0Lqm0w=; b=ucohJAFC8gJ3LB7pxMlU6hp13konTUBqeKtm5i0QeLGzh+vAkQRg5OA6GkyIC40NcQfp6RxOyU44bb5iXGA+cG+FsNQpLofL+imfTj7UbAL5ygJeHHMrmaOAguXLQZEfAkfRVcCXXRN/lco6+HYyjBJ77Zul19wDoj27fGbNRd4=
Received: from CH0PR11MB5444.namprd11.prod.outlook.com (2603:10b6:610:d3::13) by BY5PR11MB3973.namprd11.prod.outlook.com (2603:10b6:a03:185::29) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5525.19; Wed, 17 Aug 2022 19:06:49 +0000
Received: from CH0PR11MB5444.namprd11.prod.outlook.com ([fe80::ec97:3894:f9f9:ff0a]) by CH0PR11MB5444.namprd11.prod.outlook.com ([fe80::ec97:3894:f9f9:ff0a%3]) with mapi id 15.20.5504.028; Wed, 17 Aug 2022 19:06:48 +0000
From: "Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com>
To: Ilari Liusvaara <ilariliusvaara@welho.com>, "TLS@ietf.org" <TLS@ietf.org>
Thread-Topic: [TLS] WGLC for draft-ietf-tls-hybrid-design
Thread-Index: AQHYWkuBuMztUErONkCS/S1i+5V10q0HnNsAgACRXACAAHDOgICjlfyAgAFkh4CABony8A==
Date: Wed, 17 Aug 2022 19:06:48 +0000
Message-ID: <CH0PR11MB54447BA50DA9DA02F6DA2511C16A9@CH0PR11MB5444.namprd11.prod.outlook.com>
References: <27E9945C-6A0A-46DD-89F0-22BE59188216@heapingbits.net> <e43fc649-3fc6-333b-c44d-55de0627c710@cs.tcd.ie> <Ymz7yncQAnzmp/eL@LK-Perkele-VII2.locald> <38de10e6-ab3c-6ea1-44b7-57057c97e7aa@cs.tcd.ie> <CH0PR11MB5444D7D4F32F195FFB189C10C1679@CH0PR11MB5444.namprd11.prod.outlook.com> <Yve/S5OoKZMnUjNz@LK-Perkele-VII2.locald>
In-Reply-To: <Yve/S5OoKZMnUjNz@LK-Perkele-VII2.locald>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 0ca6555c-87d6-4e3a-5dd4-08da8083a2f7
x-ms-traffictypediagnostic: BY5PR11MB3973:EE_
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: oUDOEfB7cHfbbv//bxUhwTbp9Ce+0KdWI2hKGfK4/qb6zVgPJNVJAhIrBXDXdAvY+JCzVMiH+G60pkiMx/hcBTm6sUk8D7NON8NrunwB1vPBDxB/ekO9BCKDPTRhGViYAMDTnhSgkeoh0Ohu0KR+3uLJi1zYlzACJgLygNEKA293GQIYITxYtQgVVmrdqYptQv90hdVW7aKy5RFszGVmqXnAfA5Ort5WCLcNiinMDZvK7SpsU0XYIJmCjNi8QTXAahKUnWCHbZXduszRMgr/sGsimJ/D/ouTY8/ID6F+cnFZOBTFQ5s+zQPNcMRwkHWhAYLmmnte+38aeuGJgnAFHlMMnTOVe8KlDx0TTHyP9x0dz1TimqxT4Qytmawq2zht7j1Q4fQYthx4+1nN84W5PZ49mt4g2bppV8w+s+PhlGgeY5tW1kSR4/Aj5EAVJtad49VYqXbshYnKcRYe6OBOpJ8TeCyQrKafmhcRPJa7bHK0tTD1hs5gXoeMByjDj1WBrXNZz6BMbHN1VP6iLkk4DL0Yc0mUOFMh0igiiuzwqC5lVHMgqdbKyRkbtFdIBhf4bCHMeDY2CAIN1evRBJ3AD8F9l6UzCnK9hOShrCGJf6DaSimTQftGlNsbT1AtVtZ3stGZIBcthp31B7Z4EybHpvBlTZ982pWj2RpDgvfFZvxtBN0TdfHPN4FTPZH1JMu1mfyenA2b/Pm0Y5iQLkix3mlBxiKishJ0BDxUv2BDKCj9ZWtI27d0lAuV1QD4qtOXRyS4zOp/X6sxVYl0f1EEzRijZeorsMkI/OeRNPPm/MY=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CH0PR11MB5444.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(366004)(396003)(346002)(136003)(376002)(39860400002)(26005)(9686003)(38100700002)(2906002)(53546011)(7696005)(6506007)(55016003)(186003)(83380400001)(122000001)(33656002)(66446008)(64756008)(8676002)(66476007)(66556008)(71200400001)(76116006)(66946007)(478600001)(966005)(110136005)(41300700001)(316002)(5660300002)(38070700005)(86362001)(8936002)(52536014); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: /uVs/HtIqDrbxAHPg5M3YhCPZt5cUV4ttCR4Vt/2b9wCSXjwZCqObUkdSAvPeJVXK9VdO7uKE2d0IwAZ/VZfSVbZFQfvB0x+gmpR+By0qnX5wSN2EplAcFqTTqyrAQLcDQr9b7z+Jq27IlKiM3rXN/klnKqtNM73Q8t/zwzPQ/5R1faT2O41nRliIp3q9ZQBQiSE4zy4uDT1XGSmFWkBo+vQLYmADgUB1hC7tHRl6pR2qoyuE4Cc/62T+r54vVxzYfWSelskWLkmdfuIEtB/bR6wKl1uvIVtecpp0HhiYJFIKaTnzqIQ33BRrQYL0Hl/LEiHJqBVhfLHc6LdEPFbKTs8hW8LxTu174j7gtXdeFQBbKPknMU0WTVh65f9XKDgiS9t1JM8pqpQ0QEKokhzbGqg2CpY4pxSNRz30t6bSTjkUMOxo9Bmf40yUCdv0PhLyGJ4ADP90I7R58QMWN9bxy3JVLcYjPKx5V8gT2eKAIjXHdgFHDY4op5GR31VtvmxvMykDGOKpz7O0qetVSGA7FYKPTeLZGalK5D8f7C6UZSgb2UW/+QcpBu9deFtWSe5RPLPm3vk7ji9kYzQqxon+k0Qsbbpx7xsXPd2PjaZTeC2C2CCPdEsRU7fiMAA5K6LQFCNmTCbwpBkkZJ5H7D4EQxwAcw4FXtwSB52azJAo93pkQVsiLIo8u4dcRHIgtoNtYKCgaGM/m+rmX7kBPptKn+m4HonKXL1UYlaBpg/OEry3/Y6cBydVElTFk1ubXlJ/k4ATD9iHqrCyHZ6J4rLyxul9FGG8wZhIQ4SdMIOe4BhCkHT7baYqo1Fz5Y0mGnx1bLIKj9wxJPfeCjOfMTJEOwYrsamLLzoTcXzZaivkUThuY0T0AUXhbs8B/qPAKLbUIpUBSP44wO6xLxdW9OXZ0YtDneQWcdayoiZ+SUl/Xbb4Ftx4zIHdqFppx87dpI9tkpzJUa8EFGel5HTlg8JZWmYzv6bW02IVEpHOBeNgIVgd+Dty1X4tDvXB7mo5ke/Xwg9pUg92qUMBtLUzMSFl431kezMTnZSPyVawywZE3fo/8sqxiKVdciLzK6qlTkE5/q0pg52PfjoRZWAB0qY8rsgVLCoZIway/etl+FT5rOLA/ADpjXi70M5B4JCsNHRq3OcxzC1rZec0CJPuIYScLg4LnO+DY4SSrsfjCc71EThHZKqXlcBVw7NYdzzVYLwnkvVIQ6+YMtXLQSfN/96fkoVb2AqClcc9r0+aFoukr/Pg1ihYFqEsUNKQuUikxuVAt2cgkmRY18ltWtQ4z1PdGUve/SPJKLAb1m5BR1bVOnKSEsDaa3S2QbpayPsaWTOqU2zyP27yW4kDcctwtZU8zQKuFOkcfUsRfqiYzLm0tNsMPylqSTSXIaa7R2RulQtsYvQG+Ncj9pulNOVA73OZRCFHNQthgBF+KpAydCm9m3ZE3KDVeEbHoXKhzaarOKo+QPhvvCUAnBefNLCwbAbzOeYs+iSmJ7+tgY4ksSGY8vS7jgo7poHRYo39GPbqth3veYx6rtvXPxNw7XGePAx/YAyDviEQmqyQtQEuGfMODXzq2/dJCoCXLNzx11BsYmd
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CH0PR11MB5444.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 0ca6555c-87d6-4e3a-5dd4-08da8083a2f7
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Aug 2022 19:06:48.9381 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Qt6Evx7FxR3eb9J6DvrxVso0R2Qe7ItCSAB2Br1O3elvgFvAKULMU2N8lsomMQDwNIgjtg1+V40rdjoiGzzV7Q==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY5PR11MB3973
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.227.250, xfe-rcd-002.cisco.com
X-Outbound-Node: alln-core-5.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/6veRejYXZ2Y9O0jp9I40rJ11XKM>
Subject: Re: [TLS] WGLC for draft-ietf-tls-hybrid-design
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Aug 2022 19:06:59 -0000

So that we get an initial answer to this (so we can put it into the draft - of course, we can debate what's in the draft...)

Illari suggested:

X25519+Kyber768
P384+Kyber768

Well, I would suggest adding in

X25519+Kyber512

For those situations where we need to limit the message size (perhaps DTLS and QUIC).

Is the working group happy with that?

> -----Original Message-----
> From: TLS <tls-bounces@ietf.org> On Behalf Of Ilari Liusvaara
> Sent: Saturday, August 13, 2022 11:12 AM
> To: TLS@ietf.org
> Subject: Re: [TLS] WGLC for draft-ietf-tls-hybrid-design
> 
> On Fri, Aug 12, 2022 at 06:13:38PM +0000, Scott Fluhrer (sfluhrer) wrote:
> > Again, this is late, however Stephen did ask this to be discussed in the
> working group, so here we go:
> >
> > > -----Original Message-----
> > > From: TLS <tls-bounces@ietf.org> On Behalf Of Stephen Farrell
> > > Sent: Saturday, April 30, 2022 11:49 AM
> > > To: Ilari Liusvaara <ilariliusvaara@welho.com>; TLS@ietf.org
> > > Subject: Re: [TLS] WGLC for draft-ietf-tls-hybrid-design
> > >
> > >
> > > Hiya,
> > >
> > > On 30/04/2022 10:05, Ilari Liusvaara wrote:
> > > > On Sat, Apr 30, 2022 at 01:24:58AM +0100, Stephen Farrell wrote:
> > > >> - section 5: IMO all combined values here need to have
> > > >> recommended == "N" in IANA registries for a while and that needs
> > > >> to be in this draft before it even gets parked. Regardless of
> > > >> whether or not the WG agree with me on that, I think the current
> > > >> text is missing stuff in this section and don't recall the WG
> > > >> discussing that
> > > >
> > > > I think that having recommended = Y for any combined algorithm
> > > > requires NIST final spec PQ part and recommended = Y for the
> > > > classical part (which allows things like x25519 to be the classical part).
> > > >
> > > > That is, using latest spec for NISTPQC winner is not enough. This
> > > > impiles recommended = Y for combined algorithm is some years out
> > > > at the very least.
> > >
> > > I agree, and something like the above points ought be stated in the
> > > draft after discussion in the WG.
> >
> > Section 5 is 'IANA considerations', and would be where we would list
> > the various supported hybrids, which we don’t at the moment.
> >
> > Well, if we were to discuss some suggested hybrids (and we now know
> > the NIST selection), I would suggest these possibilities:
> >
> > - X25519 + Kyber512
> > - P256 + Kyber512
> > - X448 + Kyber768
> > - P384 + Kyber768
> 
> I would take:
> 
> X25519+Kyber768
> P384+Kyber768
> 
> The reason for taking Kyber768 is because the CRYSTALS team recommends
> it. The reason for taking P384 is because it is CNSA-approved, so folks that
> need CNSA can use that.
> 
> Of course, that is likely to bust packet size limits. I do not think that is an
> issue in TLS, but DTLS and QUIC might be another matter entierely (in theory
> DTLS and QUIC can handle it just fine, practice might be another matter
> entierely. And if such problems are there, it is good to know about those...
> This stuff is experimental).
> 
> 
> > Of course, it's possible that NIST will tweak the definition of Kyber;
> > that's just a possibility we'll need to live with (and wouldn't change
> > what hybrid combinations we would initially define)
> 
> I would think such changes would just mean the interim post-quantum kex is
> not compatible with the final one. Not that big of deal, there are tens of
> thoursands of free codepoints. If an implementation  needs both, it can
> probably share vast majority of the code.
> 
> 
> 
> -Ilari
> 
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls