[TLS] Re: New Liaison Statement, "Liaison communication to IETF regarding draft-ietf-tls-mlkem"

"Salz, Rich" <rsalz@akamai.com> Wed, 08 April 2026 13:56 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id CA769D818F9D for <tls@mail2.ietf.org>; Wed, 8 Apr 2026 06:56:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775656608; bh=5V+9ewQspdO/gFfimGxMG1oR7tu0ZLdRngijJ5rv5J0=; h=From:To:Subject:Date:References:In-Reply-To; b=RlJGfiGoVisRKNRIADcKA1/5oh0or4x4u4x+mq5Q81oiInUWvWLiTWGtTLQVBKHv6 SuhvEiyVMmypdQfV3bg6elADPgvlwHcTifN/m9w/78wHsMB0RewK/+xLnniGTwBxjk jM80qilw114vfQwixPmBL1FunXdaQkep1OHrCEkA=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.798
X-Spam-Level:
X-Spam-Status: No, score=-2.798 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EYDdwWAms28z for <tls@mail2.ietf.org>; Wed, 8 Apr 2026 06:56:48 -0700 (PDT)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2E402D818F96 for <tls@ietf.org>; Wed, 8 Apr 2026 06:56:48 -0700 (PDT)
Received: from pps.filterd (m0122332.ppops.net [127.0.0.1]) by mx0a-00190b01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6387nJTx3337071 for <tls@ietf.org>; Wed, 8 Apr 2026 14:56:47 +0100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h= content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to; s=jan2016.eng; bh=8apyH9BxC4tmD+yCcL9HP2 AHNlp+XBHqKrsrHGI6I6U=; b=hdiOUgpuczZcGePF1rXvntYIKLI8hK3piGfdZp mz0yaRkrCiVboPdAihSHH0FX8KbqeEHm1lY/zWKxzle9/MybJd0xwMVGATalJl+D JlKOfogT2nwASdAvl61uWnbqoAodB5YooBWKz+DlU4olPMaJIMiXpD+1ljhy+dlO DBEQxKXZp3rarv0po1qXgmTLPlAFUrZTxaqGS5JkQt5c4cVUPC6aFY2BUtzUTzJF Uedg/0s8fEaaPb7adE4BsrqDjVZrGBR4K3GMdOo6tOQNKiM6AFpmFjTTIte8GtGp 3whMRu1FkH6vr86J6ULsXv25ymeijbZSnRyBznTbSak54NtA==
Received: from prod-mail-ppoint7 (a72-247-45-33.deploy.static.akamaitechnologies.com [72.247.45.33] (may be forged)) by mx0a-00190b01.pphosted.com (PPS) with ESMTPS id 4dda5ny13j-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <tls@ietf.org>; Wed, 08 Apr 2026 14:56:46 +0100 (BST)
Received: from pps.filterd (prod-mail-ppoint7.akamai.com [127.0.0.1]) by prod-mail-ppoint7.akamai.com (8.18.1.7/8.18.1.7) with ESMTP id 638Do8bJ012989 for <tls@ietf.org>; Wed, 8 Apr 2026 09:56:45 -0400
Received: from email.msg.corp.akamai.com ([172.27.50.221]) by prod-mail-ppoint7.akamai.com (PPS) with ESMTPS id 4dcmekp2vg-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <tls@ietf.org>; Wed, 08 Apr 2026 09:56:45 -0400 (EDT)
Received: from ustx2ex-exedge4.msg.corp.akamai.com (172.27.50.215) by ustx2ex-dag5mb4.msg.corp.akamai.com (172.27.50.221) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.29; Wed, 8 Apr 2026 06:56:45 -0700
Received: from ustx2ex-exedge4.msg.corp.akamai.com (172.27.50.215) by ustx2ex-exedge4.msg.corp.akamai.com (172.27.50.215) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.27; Wed, 8 Apr 2026 06:56:45 -0700
Received: from CY3PR08CU001.outbound.protection.outlook.com (72.247.45.132) by ustx2ex-exedge4.msg.corp.akamai.com (172.27.50.215) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.27 via Frontend Transport; Wed, 8 Apr 2026 06:56:45 -0700
Received: from CH2PR17MB4022.namprd17.prod.outlook.com (2603:10b6:610:8c::9) by CH2PR17MB4069.namprd17.prod.outlook.com (2603:10b6:610:5c::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9769.18; Wed, 8 Apr 2026 13:56:43 +0000
Received: from CH2PR17MB4022.namprd17.prod.outlook.com ([fe80::d1f1:14dc:970a:dd23]) by CH2PR17MB4022.namprd17.prod.outlook.com ([fe80::d1f1:14dc:970a:dd23%4]) with mapi id 15.20.9769.014; Wed, 8 Apr 2026 13:56:43 +0000
From: "Salz, Rich" <rsalz@akamai.com>
To: "tls@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] Re: New Liaison Statement, "Liaison communication to IETF regarding draft-ietf-tls-mlkem"
Thread-Index: AQHcwtbgrDIYlX2TuU6KJZxzpK/jQLXMLPQAgAAgBwCAAAbcgIAAAMAAgAAEbwCAAAbEgIAA4hCAgABgAoCAAA7RgIAABkyAgAAHfgCAAAJnAIAGVXeAgAAulICAAFCWgIAAoUQ4
Date: Wed, 08 Apr 2026 13:56:43 +0000
Message-ID: <CH2PR17MB4022FAA970DA4E497AA75AC6CD5BA@CH2PR17MB4022.namprd17.prod.outlook.com>
References: <CAF8qwaBcotZqOnY2qJ6d0fRoa=5v0sZTOSWqeqkou+bLJcy9LA@mail.gmail.com> <CABcZeBPr+WeivTWpSCVC4f95fRuSiOytvvBPB_6r+af9Didhgw@mail.gmail.com> <CEB84168-5998-432A-9D62-36E28B9CDFA5@vigilsec.com> <CABcZeBM-eoqh+kJ7H6SiwC9p4tKAt+YiQhzetJZJmPNpXc+5OA@mail.gmail.com> <CAF8qwaALDXR6d=jLD46wXmKHDjyj=OdJ1X3a1AgxF+ByQceeMg@mail.gmail.com> <CABcZeBO0ysBjtbiPuSboP4fAATuVHQxq1TA5TbQ+_Oy-NrET0g@mail.gmail.com> <7A4F9775-8929-469D-B454-B027A0BAFA69@vigilsec.com> <CABcZeBPk3fdfPw=S_f5v2E9Y1LUfQL8f6sKvTYG0R6qRHm6rgg@mail.gmail.com> <b1527204-149e-6979-a344-8d530613e979@nohats.ca> <24a09e13-ad76-4af2-9e2c-27f1c2282b02@cs.tcd.ie> <adXVIdmIOG8SonlM@chardros.imrryr.org>
In-Reply-To: <adXVIdmIOG8SonlM@chardros.imrryr.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CH2PR17MB4022:EE_|CH2PR17MB4069:EE_
x-ms-office365-filtering-correlation-id: 253f79c0-22df-4705-98c1-08de9576aa78
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|10070799003|1800799024|366016|13003099007|8096899003|56012099003|22082099003|18002099003|38070700021;
x-microsoft-antispam-message-info: 5o6Fkan8wQsL0L8uB5ZrsmwkE8CW0xzC132ceKStsL6Iaays62YECwYVieSL2sLzI/q3bj+/TIYlJYx9VR/Hl77xtmxRsAanIg4nl/y27CIEaw2Lo8VMxzEVX0bPBYK/gRjGXXuT6nqCVNVI+8yyZUU7kVQuQx1P7upgAlwpomfnkmO/iksP8CrawlVQDds5BGJfUPJNaeryKFpPM7io2TChW5NoGQU9PwEqQuPBra+jWfmhI90X4w8fz7jRh4JVsoQIIyB0ST5NZ8nWtGHzInhCP98NHlzF0LHTTtDrJ6KVIMbrH5Jsdyh6e/Qi398UysgF6CJXi1fBHKYLlFT941nH3alPiSYMjsq72VCMFxhr2kPvao9SBNbSZEUaafUv9gQR74mYe4qseuBePtokVvPNKj4mzM5G66TNfj/Ds8PTL15Qbq7JSrqq/iGh5xUHbo+DkoDdf7ELnF4dBa314jO8b7LZ0SkB76f7lCf4GumgqV4NvFmwyG9lVIhwgzwWb7AwUBIZAWc4Mi7gW98PtxOjUb7ksC0XNzlUSnFK08URWLyUM+1kqxPnGx23QoS1gdua+mTLluvHbrpFNFblv3DReuedKYTSd9NB5FCaRoReE9n2REp3w4Yjg/vLdU7wQmTeyA8+1n+c0N8ugPMo9FZxJ52AkS1SdRUI0zwGHUITWUGHFdoWQ3QdY9m6UNml6UP06IVaoDXi/n6Og4zdPqibberR1iJXk0GRhCcgvDl3myWN1yH15RxrSEGuI5Qu1+orXMHbytWTlrSyEVMxEZVxlpRN1wnrA0fHkAENcdI=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:CH2PR17MB4022.namprd17.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(10070799003)(1800799024)(366016)(13003099007)(8096899003)(56012099003)(22082099003)(18002099003)(38070700021);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 2
x-ms-exchange-antispam-messagedata-0: nb1sdxxH6a1hAhv6AGT+Ps9G4lNGLuac0Pg82SgRJPxGEwi+1K6dWn5/OuJZ3hjDwvJgj9Wv0Ep6ABenr9UDNYGgaPwpxuAT0lyeE1quaSWEGgcurKsfj+P6v/8GDARrj59IpZCCRnKVnESZ41PSssPK14z5fS1KQC75igc9dme9vP2n9FvRx9qsUxbLCC9PMWFewqYphkDIOFF4ghMPnE4SaqNdLvU59zDYJnUMcKyfdYjuoXIqz1r6/p+OnP//kM4Rj69W8OxdWnWfROcCycRdJnAeHhD4daVAdzEZVCROKW2gcW3NertyVNJha7re6/NE2H1wUoVLh8rmEMmIFqdGPklJj6VugkTiBoFZIQrH27TbFAAKZXKRqyKeKA04dTgE8Y70HoUa9DkkIAqFj4jhXC0/wbURUEu5GdDYCwgZVPAQKtJbCaPCqcWzoybhe5whprRtDDBQZqWtVPvCT8sXX6WfFM7NqsJwAsTOaDnP9Bi/z+VR8ASzJcG64es9BzvvaFZnXHeXmB3lH2Alg6RdYuAHfYUDGcWkMv4ri1yM0VEDqbbzxhfCnDNt7070+CTyu6eDmB/PZS2Murm6g+5AVY2kY6ghyRUwwK0ziD2JaZrWO8DEpQuqqIJl/Z23mxZ1uLdw2YLs75/lwgcTRbXR17PvPrE59ljDsDIPs65CwkATCzUcjW7vMtzY6tRqpUHxhyCEdgeIhoF/BrGXqf+eRa16FOibzcnbfUA6K9uGQ3PBKj7efoD/zkjM1VFR7zyaNiXhgqGtHN+E9hu0rvn+kZJ+yR5rF590HLEGSN0p3x6v48+uInlIZ4/VYJ9JrTn/xnBByREDboGgb+/hpuD1mKYjEs6opWRrpJfx4GMpc6dhtGuVFNpFpOGpUggKmtRU/LJHghgo/QuF+X4bhc7tnrbhqA4aIl2h7cwHAOOWaXC3J88zRQRvr/Fji9PKNvmgWmZGWp2KogwVCBasnrQvqJxnbevviah1gmpzVq84X1KTZL0iCr7L1sWvWn1hDamVL6YbRvpxJBdLPtpGOQhfTpKgwW9cKrwgmz2DtJrEA7u+9v9/MTDqQ4Gwd53wbBN+ViKnwM+xSNXG1rXWTH+O52t779m02a1w9WIA1D/xivD0jh+E2xxUPTvqlvrZDF01weJFpHu5tLXXhfQWpGLconnti+L5HvbyH0KoUWb4ng5YwqSXYH+54v7lPHsGBZRlpvnWCIp+69CGrQ5TYNYtmqI2oG0C9uoCgVasNCaEzTSIlzF+Bx9XG6llzGyGtmuTn1NN8x2LpEGx/rlliaI15oEEKMqagrLIdhg4HpGkelk8cZT518bZeY3JvQ17QRhtDF5rPXsvaUIgM7bJ55o8kxNcCThACBjw5c0dk84msQHAvASaIYol1MB/K1UMunsGdfZdg+NEmrI3V/B5eCLeKWTStG/RdJlIHt5RQKTu74Z4j83VyHpwHX25rcTCZxeI+zpMTSlRgvn3qWqqtPSlH09YIiXb1Z0doED9adp7quZl+p3JHW/97ZGAFu5Ik8IJgr2UJ8HNjlbjrRRjkRDJBmV60TLc3QFrHv8lVr8nq+60G0m13vFVOYf1L25nhG6ksymZuJpPt9MvSbBc3yF6B4hpua/NtP4zPrBDwptFxvU+THRcplZAudpMw4JEALux434KdG8etoWSkwq4Fvm3nJrvLjgO2JcI3MhOc70kTtBSlsYHtWiBXD8tm+3+GngzefTdT5u9mmElP53+smiJZQFnnPZxoIkhOxgZIr3dcsDpeLCWfZo1eqO/Dtc7V1GRMdrr
x-ms-exchange-antispam-messagedata-1: aQcbzG6k/1BVzg==
arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=mRDWYgVddYHNVBOFjxYGk3h/7UhPqVBM+xsdhVrQ+2GstZgf4HWgW+f3LfmSq99bQ+Q3D4WwVA1Nbu4X+wlKLYFZK0L61o7LVzEE8h/NV0ZBFlNrOiYI/OqWSjGTK8DdBKWKzs7r9keydAj7aTJw0386hhPTIYSiYgDknSAvqAv/J6d+BmQueJjEL0lhRqeabqffMPfsipjPKq9XGsQzNg8/JwfF+FJ3TuzPwarQbhcO5j44Wc2KPs4RYXn9T16Pl6usYPhEShtffXq548REYn6gszRPG+tCEH8/wVHjF9lPlgaOC5TVKUxsgH72f8b+29rUl+/1nJrawpllr5SCCg==
arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=SlbrHxuAx5n6MbGQlALm6p28RyWo4Bg0jL7rovwiIyQ=; b=SuR8cjh9yF4Gx86rt2G/G2gMXh3M8ICmC9iW6WrPJaIgSUHw/fSPa3bDghVFRCmGxTmue5jhvHCVwFCpF2AXYeV8sxFybQjUw369g4aXG4IObrDeKYvvLhXaagbNt5ZO+fjKd38YayPNzb1Ej4LUJ6W4777ob3+JaSk2tXMzkJC5Cf0Y6ZThjDwaW9LV3p7e83Ur+1rIevaWii5LzF2ZtyC44JX5Jmog1PjTuk8GSMqmUjo28J6ZYLeb4FWkCLCg6YFlGLb/1HRTq10HuqV4P+zU55K6qzBiNw4ho6WU71IGHfQK99KsZeE5OcsLl8Zy+gYkEx/fOxqzDoTdvi6tzg==
arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=akamai.com; dmarc=pass action=none header.from=akamai.com; dkim=pass header.d=akamai.com; arc=none
x-exchange-routingpolicychecked: bLtgp527BXF+q5LpQU9sdKIAamz2z1cRrVLw0WgV0SyXBQkTDhAb8lUCs3FC/R47xtlA7hkjIYEISBF6vrCmfkCEhUVkiy0pdEq3LUY8KXP7mWe75J8/jSUpFl2RBO7nxi+v+EmY0yiVANbbfADLIPlzRJkUhqM5j6ItvYnxcUpB3rZ0WrOFMQN6suW1RoT4/um+acdMYvCYpkDjmz1UvECbD3/zByPC87tlwhBQoIA+pRmoCjgYlb8UZ5tCxwZyijz9yfVdRYiUgVapRva0JfAhQ03F2z+LrAxlA0Z/UMs5vv8sfgShh8yhipIvfbPL2x/3C4jEuYJ7/oNhk3/Wow==
x-ms-exchange-crosstenant-authas: Internal
x-ms-exchange-crosstenant-authsource: CH2PR17MB4022.namprd17.prod.outlook.com
x-ms-exchange-crosstenant-network-message-id: 253f79c0-22df-4705-98c1-08de9576aa78
x-ms-exchange-crosstenant-originalarrivaltime: 08 Apr 2026 13:56:43.1767 (UTC)
x-ms-exchange-crosstenant-fromentityheader: Hosted
x-ms-exchange-crosstenant-id: 514876bd-5965-4b40-b0c8-e336cf72c743
x-ms-exchange-crosstenant-mailboxtype: HOSTED
x-ms-exchange-crosstenant-userprincipalname: UjP9iy1jS9i3WdDPE7hFs1AS+Y8ksyrPSDnRzoQYJwcXsTJ8Oe2T8ykVIXPfcJu1m1Qs8ZZpsWN9dB/ZOsi3bw==
x-ms-exchange-transport-crosstenantheadersstamped: CH2PR17MB4069
Content-Type: multipart/alternative; boundary="_000_CH2PR17MB4022FAA970DA4E497AA75AC6CD5BACH2PR17MB4022namp_"
MIME-Version: 1.0
X-OriginatorOrg: akamai.com
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-04-08_04,2026-04-08_01,2025-10-01_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 phishscore=0 adultscore=0 lowpriorityscore=0 spamscore=0 mlxscore=0 malwarescore=0 suspectscore=0 bulkscore=0 mlxlogscore=999 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2604010000 definitions=main-2604080128
X-Authority-Analysis: v=2.4 cv=Eu7iaycA c=1 sm=1 tr=0 ts=69d65e9e cx=c_pps a=3lD5tZmBJQAvN++OlPJl4w==:117 a=3lD5tZmBJQAvN++OlPJl4w==:17 a=lCpzRmAYbLLaTzLvsPZ7Mbvzbb8=:19 a=xqWC_Br6kY4A:10 a=A5OVakUREuEA:10 a=VkNPw1HP01LnGYTKEx00:22 a=Ifg-1AOnLHOf1gn6spyb:22 a=4OENtXgxWbduB0e82o7S:22 a=NEAV23lmAAAA:8 a=AWVtMy7wbiVylRYIE-kA:9 a=pILNOxqGKmIA:10 a=KjLGq6MQ5BNGn7d1Dx0A:9 a=_9PdVDhnlJA30Aee:21 a=_W_S_7VecoQA:10
X-Proofpoint-GUID: 1qNKXe_RfjMcjoX80VT6ZCS5nHn_uZdG
X-Proofpoint-ORIG-GUID: 1qNKXe_RfjMcjoX80VT6ZCS5nHn_uZdG
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNDA4MDEyOCBTYWx0ZWRfX72Wv5gAGZEGu SjRCSwPNsLdZ32lfiPJLwVkeIBVyAL32144qsbXeLPFPJhOvx6tPAxn4D6IkbLTXWbvPa2L12PA Dc7Y5pnGZHTcOowTnfJnB4h1OSJF2V9snVeJKDzakSoSJbj1iYrBSh7Ktp81pr8Z9p2u8nPTM1I J9EQOvhT5jDIjtNLOeKeOkdZDubxsIqbWyngHw4wJCDQ0dNUwzuetDPNJVE4Vf59vsUzAtixTit uWlFJax1oxJAux5nvMZpZRN1GeNh1HSPlH/67lnwZkG1Av7dER/G/rVt0B0qEEx1Yv3iO6CcJFN JaKLj4m/JS00oZ4/R65IJyaaK2VwpqsNNJls186WkOJbeYQ+w8swzOGDH6JmQ+7gCvAwfvdKIYY fpbWJKzbYz2lXiRQLDdBld7HYHSKV94lBb8kvyjioOT/WbuadlwJDDTt3ieIvFx0JMloPsaqSzS CKb9VNfN9PTlqfDRftA==
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-04-08_04,2026-04-08_01,2025-10-01_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 lowpriorityscore=0 suspectscore=0 adultscore=0 phishscore=0 priorityscore=1501 spamscore=0 clxscore=1015 impostorscore=0 bulkscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2604010000 definitions=main-2604080128
Message-ID-Hash: FLXUQYKEOTTWT3AEXJ6E47J2NWQTO5GE
X-Message-ID-Hash: FLXUQYKEOTTWT3AEXJ6E47J2NWQTO5GE
X-MailFrom: rsalz@akamai.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: New Liaison Statement, "Liaison communication to IETF regarding draft-ietf-tls-mlkem"
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/88N2lv5XsH_IWc-_gidP7M3HTmk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

  *
I haven't seen any objections to publishing with caveats, only
  *
lack of clarity as to whether that'd be sufficient to lay this
  *
to rest.

Here is the intended security considerations planned for the next version of the draft.  It can be found at https://github.com/tlswg/draft-ietf-tls-mlkem/pull/14. There have been somewhat lengthy discussions (well, not compared to the threads here:).  Depending on the timing of things, “working on” might get changed to “just published” and include an RFC number. :)

# Security Considerations {#security-considerations}

{{NIST-SP-800-227}} includes guidelines and requirements for implementations
on using KEMs securely. Implementers are encouraged to use implementations
resistant to side-channel attacks, especially those that can be applied by
remote attackers.

TLS 1.3's key schedule commits to the ML-KEM encapsulation key and the
ciphertext as the `key_exchange` field of the `key_share` extension is
populated with those values, which are included as part of the handshake
messages. This provides resilience against re-encapsulation attacks against
KEMs used for key establishment {{CDM23}}.

This document defines standalone ML-KEM key establishment for TLS 1.3.
A PQ/T hybrid combines
a post-quantum algorithm such as ML-KEM.
with a traditional algorithm such as
Elliptic Curve Diffie-Hellman (ECDH)
The IETF is working on an RFC that defines several such key
establishment mechanisms, ML-KEM with a combining ECDH in {{ECDHE-MLKEM}}.

Both documents have IANA registry entries with an `N` in the recommended
column. Quoting from the registry {{TLSREG}}, "\[this] does not necessarily mean that
it is flawed; rather, it indicates that the item ... has limited
applicability, or is intended only for specific use cases."
Those developing or deploying TLS 1.3 with either encapsulation method
will have to determine the security and operational considerations
when choosing which mechanism to support.