[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
Daniel Apon <dapon.crypto@gmail.com> Sat, 27 June 2026 13:18 UTC
Return-Path: <dapon.crypto@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E4224108BFE58 for <tls@mail2.ietf.org>; Sat, 27 Jun 2026 06:18:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782566331; bh=MlhL87BYvXxX2zHe2fQJuHJ7V3rNuzHp55pME7ekuvA=; h=References:In-Reply-To:From:Date:Subject:To; b=wlXBQljNAqFaK79Yj0rN2fFwUY+lcBPw9lYXKv4lwQRBuAakGP/I5pFOTIhgFhYQq tl2/EPS9hlikJku8hfXuFRa1ZdV4e730uwjk/nE08Vly/1upCZllmQsNNUAYyrKWIu TVhkln3DyTRoCJRMvf4js4BIt2KGboWmIvEI6nRM=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V8RqKXvmIF3I for <tls@mail2.ietf.org>; Sat, 27 Jun 2026 06:18:48 -0700 (PDT)
Received: from mail-lf1-x134.google.com (mail-lf1-x134.google.com [IPv6:2a00:1450:4864:20::134]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id E675E108BFE4A for <tls@ietf.org>; Sat, 27 Jun 2026 06:18:47 -0700 (PDT)
Received: by mail-lf1-x134.google.com with SMTP id 2adb3069b0e04-5aeae771c49so277021e87.3 for <tls@ietf.org>; Sat, 27 Jun 2026 06:18:47 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1782566321; cv=none; d=google.com; s=arc-20260327; b=DMAC8IgUsGdVPvdcY/URWK2MEBOFGRnHLYOxMT0NImYj6Z8whoUxBM2XAaqznH3qYi yTyVOwhHTx/FP7aN6kIPWfpclxyeiJf2Vt2Nq+i7fIOxTpMbIzl0XXE95SyUNYd657P3 zHgnbaPB0vaxpHj2W0hV+Lno0XRboevZoase0IbuNi7nNeOR0Pa0aXqMjitsGAdqxzoz c/LlCyU9WNDDWwnPM5fxrVT8oBoTkc5gfZNVWeZOP52ZrgKsNcBM/O71F81/QvS4sZas MI0V6C0wayOOaxW0hS9+dROoR5hpzJ81wbBRs5BqnryZOFQMkNR4Pz47lH/Tr2lpGqnH +R4A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=PTPcDpLRRRgbjfsluPwWexx/4CmhkjENr4veSlBO71M=; fh=gXNBJQDqiIc9+Hd6B8/z5vGBQGW9D7YsRu5dX+7PjWY=; b=ncYJa7w196MEY+x1BQQmIonXee+t8KtKiM3eGk5pYt5uEKbc5iqjSCEPhdedf3rZqK 1LE/TlVA57iKXlEFi1YWDWYPCA3Ol/thJo1bGjglTJ0d2uvBziRq4DiHIjLAbiN0yK0U Zn33umIUWz3hKTCOeHq1bB14htSyFzOiPkeFtvynufXzc97W9fMmbjoj6nneJ+8uTFsH H2o98EgcRbTT5xO2brWmf2KwYigRhNKvpqTCn9M1WSWc0gpDqyX+fsxXQVRWk1So6obb vlKXpsypP9bm+oM+wvqnGGkZ3QZY7wNDweNT+gQfSCXzN3dkHIcylF5NJw9pYdBwVUHO opOA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782566321; x=1783171121; darn=ietf.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=PTPcDpLRRRgbjfsluPwWexx/4CmhkjENr4veSlBO71M=; b=ZKRN3h96xKGfs8JfpZy0GoG5qZUbYeqBaU5QpgXGxhsmzzIiIWYA1qgANxj/rxsZ0l bkyz+ayPjpIc5MGE74eTehIh4BuKolH2b1inWmh1QMUqfyY1iH/Rm7dEHukYY0omJ6I8 HoHIL4a9yQVmZkCwD3LZ4vC1MN3hrZZpAkPDVNKob8hdHZMrepkYFh75Ak1mjaA91y0D KE7Ut2SDoVYtiPjnAq9LBZla+TsBTNhBXzc9XqOcVnB6Cb7eyKNfYKsRFug5HhNlzfb8 4Q1lp3El1lCgkqiUEPJAW4vXY5rTHMBfPTq/39CHbKS6ARC37daesiUjxyScgV5yZXMf az5A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782566321; x=1783171121; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=PTPcDpLRRRgbjfsluPwWexx/4CmhkjENr4veSlBO71M=; b=rtEuYEIU+t1thzVC9svHHMACWile6IrxjnFc0gFhUqmIlc5UhXmd6D8067jKWsq0qt O+kX4jEtlK2b7l038eFJQTlJ/zEsMVD5ljnKrrm17DFS7bjPpLCeAtlarhmcSKEUfQ3n DZAA+cvrF8qeHSNCBWrIngCFnmKZQ5KLJ9TtN1+MPhupBc4fm0rsDwk8l/zz1amcpojR UyTglfzaWz8cQjN6ymrziYYfJ6pjmsK0cY/S/MvNeEo5oNoV5m0PPurAmaBljlDMh3ll iY5x/0D1n3mdBpKZK17b5Jn8fvxfPD4yo5hYqblHZyWLQhc0c8miJTrPnarXflOSiHOE gLHw==
X-Gm-Message-State: AOJu0YxLU1PaCvoFg9zqu8RBnfogbAZEw8KknvIUsyoCPPYnbHLNN4e6 5NjfEO6KlxNuAH2FZhhxZas6+fWsZ0tlumoMI9Yi00mbLs0Yr1kb1ttuVbJerTMD004Twqf1dld mnhbtqQo/qF3qXCELeKW6erG3uaYmTrHBogIu
X-Gm-Gg: AfdE7cng5e1L9cmEdrBmlJuVo5lNaPdrPSt/MCbozewDulgMUHbzD1PC58Vn7AFP8Vg jhlrNEmxQMq+NqX2AU/JnvVMguTCsSsGhVle/q+N2QB2J0zbF0jAHQ+gv/aMGfLtijITTdXhCB3 TlOG01ZWAeQjduFHnmVBhwlgjG5eGY+T/WS8B2EOenozB/RQHGDHQdcGKw5BZAg1mhT8JIxz+F2 bcs3NI42dasTcHUOJNG4oGlYG2g5fiAYQKMlUdJvbc5Rmyq0cJPTgK91XhhHThu43Yw8JgY4iO1 Sf7rYq+bLQTdcd+arG15Rs/CaCeo9BHjt5PBQJn54T1CfCtiTb4WxK4u04Mvt+1rPShX73MoMEV JB7nuvWEnMLPzWJzqDtlk5f5e9zYDphaNe6Z0Pwp+xkXLdcgD/0jx7HWHvxzIzKTh++RMOhRrDx btAkTnLyt3mVRHfuQKVrHx4pBTD5u3
X-Received: by 2002:a05:6512:8399:b0:5aa:5eb9:a3d1 with SMTP id 2adb3069b0e04-5aea1f48305mr1891344e87.21.1782566320482; Sat, 27 Jun 2026 06:18:40 -0700 (PDT)
MIME-Version: 1.0
References: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg> <20260627103910.4070917.qmail@cr.yp.to>
In-Reply-To: <20260627103910.4070917.qmail@cr.yp.to>
From: Daniel Apon <dapon.crypto@gmail.com>
Date: Sat, 27 Jun 2026 09:18:27 -0400
X-Gm-Features: AVVi8CclDCZ9nfkOYBnmPgP_jcOCBc89W828V84raHpG2JXw5kC8phVDgyjOG5Q
Message-ID: <CAPxHsSJNDw6eYrb6Fafo69trY_R9h22ah6rAw+wWRn5tjt7s3A@mail.gmail.com>
To: tls@ietf.org, sean@sn3rd.com, joe@salowey.net, durumcrustulum@gmail.com
Content-Type: multipart/alternative; boundary="000000000000522f0906553c1001"
Message-ID-Hash: AGOITIUQNX2OMEW4B5GDQAONIEQXQB46
X-Message-ID-Hash: AGOITIUQNX2OMEW4B5GDQAONIEQXQB46
X-MailFrom: dapon.crypto@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/7hXwfepmuHGRzrCaP8RMSdfXZac>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
I support publication. Daniel Apon Anduril/AIS On Sat, Jun 27, 2026 at 6:42 AM D. J. Bernstein <djb@cr.yp.to> wrote: > This message is in response to the draft-ietf-tls-mlkem last call, but > it's also a complaint to the TLS WG chairs regarding their 28 Apr 2026 > 16:24:37 -0400 declaration of consensus to publish draft-ietf-tls-mldsa. > This is on different grounds from my previous, still active, complaint > about that declaration. I'll explain the complaint status below, but > I'll start by explaining the main content shared by my response to the > last call and by my new complaint; this large overlap is the reason that > I'm filing this as a single message instead of two messages. > > > 1. Security damage of solo PQ > > Deployment of draft-ietf-tls-mlkem and/or draft-ietf-tls-mldsa means two > things: > > (1) Throw away the protection provided by the status quo. I'll focus > on ECC as the typical status quo for concreteness, but the exact > choice has only minor effects below. > > (2) As something that's _claimed_ to provide more protection, roll > out ML-KEM and/or ML-DSA. > > But let's look at whether this claim is actually true. > > I have a new paper this month that presents fast exploit scripts for > some ML-DSA bugs; uses standard techniques to predict ML-DSA bug rates > starting from ML-DSA code sizes and https://arxiv.org/abs/2107.04940; > uses known ML-DSA bugs such as https://eprint.iacr.org/2026/1032 and > ML-DSA CVEs as sanity checks; and quantifies the security damage of > rolling out solo ML-DSA. The following graph summarizes the damage: > > https://cr.yp.to/papers/mldsa-20260601.pdf#breakable-keys > > The TLS part of the damage will be millions of breakable ML-DSA keys in > 2027, millions of breakable ML-DSA keys in 2028, etc. Even years after > the first secret quantum attacks begin (I was already on record in 2023 > with a median estimate of 2029 for that), there will be many more ML-DSA > keys broken because of software vulnerabilities than ECC signature keys > broken because of quantum attacks _plus_ software vulnerabilities. > > It's not hard to carry out a similar analysis for ML-KEM. The code is > noticeably smaller for ML-KEM than for ML-DSA and not quite as new on > average, so the vulnerability rates per ML-KEM implementation will be > lower, but this is outweighed by the fact that there will be many more > total ML-KEM keys in TLS than total ML-DSA keys, making quantum attacks > an even smaller part of the overall attack picture. > > To summarize, using draft-ietf-tls-mlkem and/or draft-ietf-tls-mldsa > will be an unmitigated security disaster. Let me emphasize that this is > simply accounting for the predictable impact of bugs, never mind timing > attacks (see, e.g., https://cr.yp.to/papers.html#kyberslash) never mind > the risk of breaks of the _specs_ of ML-KEM and ML-DSA. > > > 2. Mitigation: ECC+PQ > > The well-known, widely deployed, common-sense mitigation for failures of > PQ security is to preserve the existing ECC layer as part of ECC+PQ: for > example, continue signing with ECC as part of ECC+PQ double signatures, > and similarly for encryption. (Typically ECC+PQ is called a "hybrid", > although that name often confuses people.) There are many detailed > ECC+PQ examples, including specs that do the job for TLS, namely > draft-ietf-tls-ecdhe-mlkem and draft-reddy-tls-composite-mldsa. > > ECC+PQ has negligible cost beyond solo PQ. The complexity and risks of > software engineering and testing are almost entirely inside the ECC code > (which was there already) and the much newer PQ code (for code sizes > see, e.g., https://cr.yp.to/papers/pqcomplexity-20240419.pdf regarding > ML-KEM and https://cr.yp.to/papers/mldsa-20260601.pdf regarding ML-DSA), > not the combiner code. Sure, combiner code can have bugs too, but adding > that code is mitigation against bugs in much more complicated code for > ML-KEM and ML-DSA, so it would make absolutely no sense to wave at the > combiner complexity as a reason to avoid this mitigation. > > To be clear, having less code _tends_ to be good. But this has many > exceptions. Arguing for less code isn't a valid argument to throw away > test code, or to downgrade to the null cipher, or to use solo PQ rather > than ECC+PQ. ECC+PQ is safer than solo PQ. > > Quantification of bug rates and exploitation costs in the case of ML-DSA > is new to my paper this month, but qualitatively the advantage of ECC+PQ > is something I pointed out much earlier. For example, > > https://cr.yp.to/talks.html#2016.02.24 > > recommends ECC+PQ, even (explicitly) for the case of the PQ part being > hash-based signatures. As for software issues, > > > https://web.archive.org/web/20220308032457/https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/LVpCs_vjMlE/m/M2uQPfaEAQAJ > > from 2018 describes NISTPQC as "the largest regression _ever_ in the > quality of cryptographic software" and says this "will not be easy to > fix"; see also > > > https://cr.yp.to/talks/2018.12.28/slides-dan+tanja-20181228-pqcrypto-16x9.pdf#page.74 > > for a summary of the software situation. Putting this together, > > > https://web.archive.org/web/20260603074058/https://mailarchive.ietf.org/arch/msg/spasm/pcISUlnedpExwwLuISP18oR1zxc/ > > from 2024 emphasizes how the risks of "bugs in post-quantum software" > warrant "a blanket rule of always upgrading from ECC to PQ+ECC, _not_ > discarding the ECC layer, even when the PQ layer is SPHINCS+"; and the > same 2024 posting explains the difference between state-of-the-art bug > elimination and what happens in the real world. > > > 3. The actual rationale for solo PQ > > In the TLS WG, specs for solo PQ were introduced without any pretense of > an engineering rationale. Instead there were claims that NSA demands > solo PQ and will refuse to authorize government purchases of ECC+PQ > ("that's what they're willing to buy. Hence, Cisco will implement it"; > "CNSA 2.0 compliance"; etc.). > > What I found puzzling about the content of those claims is that they > were, and as far as I know still are, inconsistent with _official_ > statements from NSA. For example, an official NSA document > > > https://web.archive.org/web/20220524232250/https://www.nsa.gov/Portals/75/documents/resources/everyone/csfc/threat-prevention.pdf > > describes an NSA program asking for two cryptographic layers "to > mitigate the ability of an adversary to exploit a single cryptographic > implementation". NSA's official post-quantum statements such as > > > https://web.archive.org/web/20250827175413/https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF > > say that "hybrid solutions may be allowed or required due to protocol > standards, product availability, or interoperability requirements". > > On the other hand, an NSA employee wrote that NSA is "looking for > products that support /standalone/ ML-DSA-87 and /standalone/ > ML-KEM-1024. If there is one vendor that produces one product that > complies, then that is the product that goes on the compliance list and > is approved for use. Our interactions with vendors suggests that this > won't be a problem in most cases." > > A defense contractor seeing such statements will of course conclude that > if it doesn't push for solo PQ then it will lose federal contracts > ("that's what they're willing to buy. Hence, Cisco will implement it"). > So NSA gets to pull the strings here even without taking any official > responsibility for doing so. > > > 4. Subsequent discussion of the specs > > Within the TLS WG, more and more objections to solo PQ started piling > up---most importantly to the security damage, but also to procedural > problems such as the lack of an engineering rationale for solo PQ. These > specs were in clear violation of what > > > https://web.archive.org/web/20250528213926/https://www.ietf.org/blog/ietf-llc-statement-competition-law-issues/ > > labels as a "fundamental" rule: "IETF participants use their best > engineering judgment to find the best solution for the whole Internet, > not just the best solution for any particular network, technology, > vendor, or user." > > Unsurprisingly, the actual story of NSA paying for solo PQ was then > gradually downplayed in favor of other arguments for solo PQ. I've been > maintaining a chart of the arguments and counterarguments, with links to > the original statements: > > https://blog.cr.yp.to/20260221-structure.html > > This is most recently updated 25 June 2026. (For anyone who sees an > argument not covered there, please let me know.) > > It's remarkable that the case for the specs includes statements that > contradict each other. For example, compare the following: > > * One vote for allowing solo PQ claimed, as part of denying the > security damage, that solo PQ will be used solely by NSA so any > security problems will be "not impacting anyone else". > > * Similarly, another vote for allowing solo PQ claimed that ECC+PQ > "will surely continue to be far more common in practice". > > * Similarly, the chairs wrote that there's a "clear community > preference" for ECC+PQ. > > * But another vote for allowing solo PQ claimed that "pure-mlkem is > the obviously correct solution if you want high-performance > solutions". > > * Another vote for allowing solo PQ emphasized that "we have > implemented this in Chrome". > > * Another vote for allowing solo PQ claimed that deploying ECC+PQ > would require a "second large-scale engineering effort to migrate > to pure ML-KEM sometime later" and "would consume literal years of > my life". > > Who's the supposed user base for these specs? The answers are absurdly > inconsistent. Someone asking about the purported _advantage_ of solo PQ > over ECC+PQ is treated to wild exaggerations of the cost difference and > to a whac-a-mole game of supposed applications (such as "high-frequency > trading"). Someone asking about the _security damage_ is instead told > that this is just for NSA. C'mon, this doesn't pass the laugh test. > > The case for the specs also includes arguments that, because of some > "recommended" entry in the IANA registry, solo PQ won't be used. Huh? > How many purchasing managers ever look at the IANA registry? > > The reality is that an RFC will be viewed by typical readers as IETF > endorsement, and will lead to many deployments that wouldn't otherwise > exist. See, e.g., > > > https://web.archive.org/web/20260625095524/https://mailarchive.ietf.org/arch/msg/tls/LCtGfIAfsOkuuh5NP7l0wAWUk4A/ > > saying "I think it's clear that many regard the publication of an RFC by > the TLS WG as a form of endorsement, even when Recommended=N ... I don't > think this position is entirely unreasonable given that the documents > state on the face of them that they 'represent[s] the consensus of the > IETF community.' " Or see > > > https://web.archive.org/web/20260521112257/https://mailarchive.ietf.org/arch/msg/last-call/mNqIHumBiO2kJMfh7-MBWlVS3xg/ > > saying that what "largely" matters is whether there's an RFC, not how > the RFC is labeled. > > Perhaps most importantly, the case for the specs includes arguments > denying that ECC+PQ is safer than solo PQ: > > * There's conflation of spec security with software security (how do > we explain all the bugs and timing attacks, then?), accompanied by > a claim that the ML-KEM and ML-DSA specs were "fully vetted" > during the NIST competition (so eprint papers 2025/1910, > 2025/2189, and 2026/279 are all wrong?). > > * There's a claim that ML-KEM and ML-DSA will have "exceedingly few > bugs"---but no response to clarification questions asking (1) how > many bugs, (2) where this number is coming from, and (3) how this > is supposed to be an argument for the specs when the same posting > admits that "a single broken key per month can be catastrophic". > > * There are some astounding claims that attacks don't matter. For > example, in the case of ML-DSA, we're supposed to believe that > "the blast radius for signatures has a strict end with revocation > of the key". This ignores not just the expense and difficulty of > cleaning up after attacks that are discovered, but also the damage > done by attacks _before_ the attacks are discovered. For example, > NSA said that its QUANTUMINSERT forgery attacks were "highly > successful" starting in 2005; those attacks weren't publicly > detected until the Snowden documents revealed them in 2013. > > * There's a claim that ECC is useless. This ignores (1) all of the > available evidence regarding the cost of quantum computation (see > generally https://cr.yp.to/papers/mldsa-20260601.pdf#ecc) (2) > the value of limiting the number of attackers, and (3) the value > of delaying attacks. > > * There's a claim that specific ECC+PQ mechanisms proposed for TLS > allow malleability attacks that PQ by itself wouldn't allow. This > claim has been repeatedly debunked, even with a debunking demo in > https://github.com/crypto-security-tools/on-composites-signatures, > and yet the claim continues to be repeated on this mailing list. > > RFC 2418 says that disagreements "must be resolved by a process of open > review and discussion". This rule is obviously a big problem for these > specs: the case for the specs is flimsy and cannot survive a resolution > process. Unfortunately, aside from a few minor issues such as the FATT > issue, this resolution process simply hasn't happened for these specs. > > What the chairs _should_ be doing is insisting on the specs stating a > coherent, stable rationale that survives scrutiny and reaches consensus. > Instead the chairs are allowing spec proponents to ignore objections; > allowing new arguments for the specs to suddenly appear at the moment of > a limited-time last call; and now trying to terminate the process of > dispute resolution ("Please refrain from further discussion on this > topic"). Sorry, no, RFC 2418 says "must be resolved" and gives chairs no > authority to override this. > > > 5. Response to the last call regarding solo ML-KEM > > Regarding the draft-ietf-tls-mlkem last call: I am opposed to any > endorsement of this spec. In particular, I am opposed to the proposal on > the table to issue the spec as an RFC. > > > 6. Status of earlier process complaint regarding solo ML-DSA > > RFC 2026, Section 6.5.1, authorizes complaints from someone who > "disagrees with a Working Group recommendation". The RFC distinguishes > two types of complaints handled by this process. > > The first type is "a difficulty with Working Group process" where > someone's "views have not been adequately considered by the Working > Group". > > In particular, for draft-ietf-tls-mldsa, there were _14 people_ filing > objections before the end of WG last call, with no answer to the most > important objections. The chairs claimed consensus; there were process > complaints regarding that; the chairs insisted that there was consensus. > I escalated to the ADs. This is _not_ part of what I'm now filing a > complaint about; I'm just reviewing it to clearly distinguish it from > what I _am_ now filing a complaint about. > > > 7. New jeopardy complaint regarding solo ML-DSA under RFC 2026 > > The second type of complaint considered in RFC 2026, Section 6.5.1, is > "an assertion of technical error" where "the Working Group has made an > incorrect technical choice which places the quality and/or integrity of > the Working Group's product(s) in significant jeopardy". > > I am now invoking this provision. Solo PQ, whether solo ML-KEM or solo > ML-DSA, is an incorrect technical choice that places the quality and > integrity of the TLS WG's output in a situation of not just significant > jeopardy but clear security damage. Some of this damage will inevitably > become visible in CVEs and in forensic investigations of how computers > end up being infected by ransomware. Some of the victims will find out > that their security was damaged by various people and companies taking > money from NSA for this, and will file lawsuits. Surely this level of > jeopardy qualifies as "significant". > > In a standards organization following its own rules and its own promises > of consensus, the lack of WG consensus on solo ML-DSA would make this > jeopardy complaint moot---it wasn't a choice by the WG in the first > place. In IETF, the chairs are falsely claiming consensus, i.e., > claiming that the WG chose to approve solo ML-DSA, so the jeopardy > complaint isn't moot. > > > 8. New charter complaint regarding solo ML-DSA under RFC 2418 > > Beyond RFC 2026, there are further rules in RFC 2418. IETF says in > > > https://web.archive.org/web/20250528213926/https://www.ietf.org/blog/ietf-llc-statement-competition-law-issues/ > > that IETF procedural rules "include robust appeal options"---so there > must be a provision to appeal violations of the RFC 2418 rules. Indeed, > RFC 2418 has Section 3.4, "Contention and appeals"; in particular, this > says that one can follow the RFC 2026 process to request "a review of > WG, Chair, Area Director or IESG actions". > > I sent email to the list dated 22 Nov 2025 15:30:03 -0000 going > carefully through the WG tasks listed in the charter and comparing those > to solo PQ. In particular, solo PQ is directly contrary to the "improve > security" goal in the charter, a goal that one would imagine has very > high weight for a WG on "Transport Layer Security"; and solo PQ doesn't > serve any of the other goals in the charter. > > There has been no response to this. The purported rationale for solo PQ > isn't founded upon what the charter says the WG tasks are; it simply > ignores the charter and makes up its own desiderata. > > This violates RFC 2418, Section 2.2, which says that a WG's "charter is > a contract between a working group and the IETF to perform a set of > tasks". The word "contract" indicates that this is enforceable against > the WG: it's _not_ something that the WG can simply decide to ignore. > > So I'm now invoking RFC 2418, Section 3.4, to request a review of this > charter violation. This is separate from the process complaint that > there wasn't consensus, and it's separate from the jeopardy complaint. > > ---D. J. Bernstein > > > ===== NOTICES ===== > > IETF BCP 78, "Rights Contributors Provide to the IETF Trust", Section 5 > (normative), "Rights in Contributions", provides a modification right > "unless explicitly disallowed in the notices contained in a Contribution > (in the form specified by the Legend Instructions)". > > The official language from IETF's "Legend Instructions" for the > situation that "the Contributor does not wish to allow modifications nor > to allow publication as an RFC" is as follows: "This document may not be > modified, and derivative works of it may not be created, and it may not > be published except as an Internet-Draft." > < > https://trustee.ietf.org/wp-content/uploads/Corrected-TLP-5.0-legal-provsions.pdf > > > > The same language is used in, e.g., RFC 5831. The same language hereby > applies to this document. This is not disclaiming or limiting the > applicability of IETF policies; it is strictly following IETF policies. > > IESG claims that the "explicitly disallowed" provision in BCP 78 is > limited to the examples in Section 3 in BCP 78. That is incorrect. BCP > 78 states that Section 5, "Rights in Contributions", is normative, while > Section 3, "Exposition of Why These Procedures Are the Way They Are", is > informative. The opt-out provision in the normative text is clear, and > cannot be limited by an informative section. BCP 78 does not give IESG > any authority to issue changes or purported clarifications of the rules. > > Rationale for exercising the BCP 78 opt-out provision: I'm fine with > redistribution of copies of this document. The issue is instead with > modification, such as (1) IESG's May 2025 posting of an IESG-mangled > version of an appeal that I had filed and (2) IETF management selling > IETF mailing-list text to AI companies. This goes far beyond what > copyright law allows as fair use (such as giving quotes for purposes of > commentary). When I complained about the mangled document, the IETF > Executive Director responded not by apologizing but instead by asserting > that IETF management had the power to do whatever it wanted. > > _______________________________________________ > TLS mailing list -- tls@ietf.org > To unsubscribe send an email to tls-leave@ietf.org >
- [TLS] WG Last Call: draft-ietf-tls-mlkem-08 (Ends… Joseph Salowey via Datatracker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Russ Housley
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kampanakis, Panos
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ann Krieger
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Songbo Bu
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nathanael Ritz
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thom Wiggers
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Schäfer, Pascal
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Deirdre Connolly
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Ryan Appel
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Wang Guilin
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Michael Jones
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter C
- [TLS] Re: [EXTERNAL] WG Last Call: draft-ietf-tls… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] WG Last Call: draft-ietf-tls… Andrei Popov
- [TLS] Re: [EXTERNAL] WG Last Call: draft-ietf-tls… David Adrian
- [TLS] Re: [EXTERNAL] WG Last Call: draft-ietf-tls… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Thomson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bas Westerbaan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Thomson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Thomson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bas Westerbaan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter C
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Thomson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaroslav Rosomakho
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christopher Patton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Van Geest
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… nhgajco@uwe.nsa.gov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Apon
- [TLS] Complaints/Appeals Response (was: Re: WG La… Sean Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sean Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sean Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jan Schaumann
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… santosh.chokhani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sean Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Joe Birr-Pixton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Lincoln Stoll
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jack Grigg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… steve
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jeff Hodges
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yuto Nakano
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Marc Penninga
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Antony Vennard
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bas Westerbaan
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Yaakov Stein
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Bas Westerbaan
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Yaakov Stein
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Bas Westerbaan
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Antony Vennard
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Richard T. Carback III
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Richard T. Carback III
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Henrick Hellström
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… David Stainton
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Henrick Hellström
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Kris Kwiatkowski
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Flo D
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bertrand Jacquin
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Rob Sayre
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Soatok Dreamseeker
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Rob Sayre
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Rob Sayre
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Patrick Duc
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Tanja Lange
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Soatok Dreamseeker
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Peter Gutmann
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Salz, Rich
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Peter Gutmann
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter C
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Valery Smyslov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Michael P1
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaroslav Rosomakho
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Hammell, Jonathan F - [he/il]
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tim Bray
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Cooper
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wilman Lee, Vodafone
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wilman Lee, Vodafone
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wilman Lee, Vodafone
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… tirumal reddy
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eren Eroğlu
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Carlos Aguilar Melchor
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Livingood, Jason
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tony Patti
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Livingood, Jason
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tony Patti
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Livingood, Jason
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bas Westerbaan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter C
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bellebaum, Thomas
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bellebaum, Thomas
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Neuhaus
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thom Wiggers
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jan Zerebecki
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Algorithm agility (Re: Re: WG Last Call: dr… Nico Williams
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Soatok Dreamseeker
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Nico Williams
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Soatok Dreamseeker
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Nico Williams
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Soatok Dreamseeker
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Nico Williams
- [TLS] Algorithm agility, was Re: Re: WG Last Call… Paul Wouters
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Soatok Dreamseeker
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Peter Gutmann
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Salz, Rich
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Peter Gutmann
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jan Zerebecki
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Erwin Hoffmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Richard Barnes
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thom Wiggers
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Jacob Appelbaum
- [TLS] Re: [EXTERNAL] Re: Re: [EXTERNAL] Re: WG La… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] Re: Re: [EXTERNAL] Re: WG La… Jacob Appelbaum
- [TLS] Re: [EXTERNAL] Re: Re: [EXTERNAL] Re: WG La… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] Re: Re: [EXTERNAL] Re: WG La… Jacob Appelbaum
- [TLS] Generation of 'm' in ML-KEM (was Re: Re: [E… David Cooper
- [TLS] Re: Generation of 'm' in ML-KEM (was Re: Re… Jacob Appelbaum
- [TLS] Re: Generation of 'm' in ML-KEM (was Re: Re… Wang Guilin
- [TLS] Re: Generation of 'm' in ML-KEM (was Re: Re… Jacob Appelbaum
- [TLS] Re: Generation of 'm' in ML-KEM (was Re: Re… Erwin Hoffmann
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Verbücheln
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sven Schäge
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Erwin Hoffmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Campling
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… William Whyte
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Lucas Prabel
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ilari Liusvaara
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Orr Dunkelman
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Benjamin Kaduk
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Quynh Dang
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Joseph Salowey
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wang Guilin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… BRUNGARD, DEBORAH A
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mjjenki@cyber.nsa.gov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Yee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sam
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Pretty Hot And Tasty Bits
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: [EXT] RE: Re: WG Last Call: draft-ietf-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ian Palmer
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Grothoff
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Leonid Shamis
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mStar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Shane Killian
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Lauren Amsterdamer
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Willow Liquorice
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Dmitry Belyavsky
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Frieder Hannenheim
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Shane Killian
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Guy
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Abhinav Gottumukkala
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Kuehne
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… michael
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Adam Firestone
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ludovic Perret
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Roland Shoemaker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Justin Schnurbusch
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Justin Schnurbusch
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mike Ounsworth
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Watson Ladd
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Marc Stibane
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Dalrymple
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrey
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nicola Lazzari
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Alexandr Burdiyan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Florian König
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Neuhaus
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tim Bray
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Neuhaus
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Verbücheln
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Roald Van Glabbeek
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Charles Cazabon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Travis Burtrum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Koos
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wessel Jacobi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Hunter
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… stellakiritoy
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… STProjects Security
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Aaron Gable
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Fe Lix
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Fe Lix
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Travis Burtrum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Sigsbee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mathieu Bilodeau
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Brian Resnik
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tony Patti
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Tams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… marios.thoma
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bartlee Anderson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… marios.thoma
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mhalikosen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Joseph Diragi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nicola Tuveri
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Alexander Burke
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tommy Pauly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Dan Harkins
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Levine
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Carl Wallace
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Michael StJohns
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Q Misell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Hoffman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Charles Cazabon
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Daniel Apon
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Matt G1
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Andrei Popov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Brian Resnik
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Brian Resnik
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thomas Hardjono
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Preston Maness
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thomas Hardjono
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sofia Celi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sofia Celi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sandip Dholakia
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Brent Zundel
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… ghostkill73
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Hook
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sven Reissmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Motley
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jim Fenton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Vladimir Támara Patiño
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Tehrani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mr. G
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… DA PIEVE Fabiana
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Tehrani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Tehrani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Tehrani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Andrei Popov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jan Schaumann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Verbücheln
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David McGrew (mcgrew)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Naveen Nathan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… scosol@scosol.org
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Campling
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andreas Bartelt
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… DA PIEVE Fabiana
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Roger Grimes
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Chris Miller
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Dan Collins
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… William.Layton@cyber.nsa.gov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… William.Layton@cyber.nsa.gov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deb Cooley
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Employment or other personal history Salz, Rich
- [TLS] Re: Employment or other personal history Daniel Apon
- [TLS] Re: Employment or other personal history Sean Turner
- [TLS] Re: Employment or other personal history David Stainton
- [TLS] Re: Employment or other personal history Andrew Campling
- [TLS] Re: Employment or other personal history Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stange, Miyana
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Gessel
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Generation of 'm' in ML-KEM (was Re: Re: WG… David Cooper
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Gessel
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kai Page
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sam
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bruno Henc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sam Smith
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Josh Cepek
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… BARNETT Anthony
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… PEIRANI-MERCELOT Beatrice
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… BARNETT Anthony
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… James
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Harry Halpin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Roger Grimes
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stern, Morgan B
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman