[TLS] Re: [EXT] Re: WG Adoption Call for ML-KEM Post-Quantum Key Agreement for TLS 1.3

"Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu> Wed, 16 April 2025 14:18 UTC

Return-Path: <prvs=8201e787f1=uri@ll.mit.edu>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 81AC11D04DF3 for <tls@mail2.ietf.org>; Wed, 16 Apr 2025 07:18:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.597
X-Spam-Level:
X-Spam-Status: No, score=-2.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l8c4fau-ptkp for <tls@mail2.ietf.org>; Wed, 16 Apr 2025 07:18:30 -0700 (PDT)
Received: from MX3.LL.MIT.EDU (mx3.ll.mit.edu [129.55.12.52]) by mail2.ietf.org (Postfix) with ESMTP id DE9791D04DE9 for <tls@ietf.org>; Wed, 16 Apr 2025 07:18:30 -0700 (PDT)
Received: from LLEX2019-02.mitll.ad.local (llex2019-02.llan.ll.mit.edu [172.25.4.98]) by MX3.LL.MIT.EDU (8.18.1.2/8.18.1.2) with ESMTPS id 53GEGKU4204821 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=FAIL) for <tls@ietf.org>; Wed, 16 Apr 2025 10:16:20 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector5401; d=microsoft.com; cv=none; b=birfjapS8keWW39r/HUPBhn10ZeAL1XyzaPMuvc74x1sgAxekrwRNbMw4YeK8JG+9InqjlfL43FyZ6jXuJfr7b8Db/4eeC+9mSeFLvF7HpXepPorg0DGAAeean5KWFp8yNAVdihjEgl6QVjriQyLRYTlNACiFYwbfs4MARBncr6BFFeYxlj/zl3zn0mTfnvAQjixVbI1x+OOxGHebME2pDIiaisYkJpVkfXAqvF6oYJcs5dWSz+1x4ZvrfVn+aHqr6iTHJmxZsTdeQTwI5DPUjoTnb53H0XsshC35y9b2ijfVKlRSl1P4+MAn+Y3n/E+HQxAuyfldD/KIexWXZTASA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector5401; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=aMeCtL9+iyYRD4r9qqTQNHsZvuKx3Krw8QFW6Z/2Iic=; b=pOkC9BMwbPkGA/4W+43pMZ3mdIuCqyz9UAT/Exk7fFsOLeKhwP1Ds79slK/rBfGZbphxCqKLfpRTVK4zv4SFeriIq7mWhtYyqCnjRLsLzBLNFj4jRawzgMKjlUc7/tSwytgdHDhg2WdTrLcEJuhJ5j/KkuE+TQaqJJeA14Ye5OhohkSwYJi6Avn3g9WLR5DdnyXowPlzVr0yOvISIlIz+uQk2/aHBbE50PJMlUIw6IPXFMEywGPXcBixHojpEN2SSGnKMd46U/QLl/+uBCDaEgHNCwQh3Egu3nHY1r1AjZ9QZNwD6/KKwtUIpJAmrhastaj26nTRonPaID8MFsWF7A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ll.mit.edu; dmarc=pass action=none header.from=ll.mit.edu; dkim=pass header.d=ll.mit.edu; arc=none
From: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>
To: "tls@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] Re: [EXT] Re: WG Adoption Call for ML-KEM Post-Quantum Key Agreement for TLS 1.3
Thread-Index: AQHbrlRXZFbw6EIWj0OaUwE6vU5RhLOmVHEk
Date: Wed, 16 Apr 2025 14:18:27 +0000
Message-ID: <BN0P110MB1419B053A8945B2A074DD5EC90BDA@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM>
References: <BN0P110MB14198B6485FA1CD4F6128B8290B2A@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM> <20250415221645.237106.qmail@cr.yp.to>
In-Reply-To: <20250415221645.237106.qmail@cr.yp.to>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-ms-reactions: allow
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BN0P110MB1419:EE_|BN2P110MB1558:EE_
x-ms-office365-filtering-correlation-id: b7d32000-c297-4bbc-8cc4-08dd7cf18e8d
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;ARA:13230040|366016|1800799024|8096899003|4053099003|38070700018;
x-microsoft-antispam-message-info: aOgqmBqLXnbl1ygmO7mUZN2l5I3xoBKIRFsXDyJJ223yx06AfJLqOgy2K6TKPx9iY23pYv1kV9khLttxs2POQbhcqBTuXpqPvWqRvaUwg3eNxJ3EIFOUPZwgS7ZV+G4h86A2nY4WCo6nhf7Bb+69PgwX4TR7DlfFX4IoraP2s879HlDPKlsGVtvfZLQZ1GCbpljH6RbXlKda2PjaqbJJsqbWDDV8nZ8w1To2PHX4S4fH3eYK7Xxd4T+Ysy2ZHGn41mm3HVIMJ/XbQdipVqkkacfZx3Vk/QIePowMyCUM8AfwJTZP+xt3zm1/vKdy3Wn4rUBndDC+zLjMrk7mVocj3rgzfA+SliIxu34CUFkv9Jk+TLzMKF09+0mfLCT/CChrAwiWVRf/fYMo3mT8YMu28xKzFY6Azkyv3qrJivAv7iHi3vM69M0g2dD1kMTCbNn4QtBZlY99EKjmwFt3zyEQH/MgaEIzVxoF54PSVribL1rhy8HCr3ae5dtRY1FVnOfaTKxEgI9L1KfOM0GJi3f1v7GdeqR9G8Xe3nMZZpcIQcvIJ9Ko0g4F3xW9saeSERToVWLZsrzpuAEAWcnyKZCHlHxh73v30+LSWVw/2XN66UqcGIk/ZdTLBVp8T6E4nyW8nHo5/wS9cRyOhy3QH1XHHOyFb+rf/CrMNt99/BNBw2Dk06wo5nUy7DccdyOjGl28CxsXSNMaH9nSUC7MlB+VryQcA+W2K7yoYyjRsJJYaHUW6IHVqYtfBv35DMWdQMSZEZXe3XJuRGwmpmas9ofb6XPnsj9DDxP1ac/90ucPfOj9EwebkzPhADUYfFQXtLe4uGhhSxYSQ60eyLxzeW6D6BJDZSHh6r8VzXGJSZ0WnYC6yK/d5K2dZ4+jX7ywwv1kx4HRzbBcYRs0s1/7w/U8O2Depm+oUxMhKqz8T5rW0xcw819Db4t/ksmBKe8OxhKZVze2qJ+59wVTOYIcb1JIp2GnVcv8I8Q9Pe/zqyac6jL+nnHNAE8iGTsl/WMELqz2BF1K9P0mxGMDACJ8HPWp1MgWRhClL2T29/A8zWohmg8t8dbj4CflunnZ+03bhVMa6OMbMGdhLt5s5/3POMeZTEYcSX6xHzS4ekNJEQhPxnfjIlDd9Xj87VSYHxrQgUXVSryNuQ5N1cX79099izxPPpucqaMvI6dqRsq7rlZekj1IetoHRFPVBQSHBirg0BT948XsMxDjHVvIIqmmao12P/DUhu542OEP0gMFWs8R8xCqn6/NiQulfSFX9fiVZ9VRBAzrfx5LfKXVfuu2eKKptI/jQ6B2UJBaIo5UKnW9MTV77rOgZbBm3GcW59QMRhMuSiTo9HebMYhKWTThkAFvWFT1ayXI1cMDhQhW12b860KY7ypLrzFub2NpRkXceZ1YU/SAEKU3BIT3MMJ9gBpJaS/TVVojytXD0uPWB1t4T5o=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(8096899003)(4053099003)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 17Zo6Wvgk/sAYXN1jNI+eA3SqGKCqOG4tLK4OFS/RsVh+9RtACqgP06+xbZPh2NCjXYJJDgeTIbgcI7g4I5g87nHnGnfVxkUMTZjRQQPV5lIkUMlXW8kKFrsuu2+GisddPGvdtqGZmNCQsHiruHRR+kLomxYs0aGyRb952lPZYsLnwwL6DNLiWrKvT/wrznud/QgD4sVygm1IENranM5dHCBSSx5dNI53wY5aTrOAAhUWU/pQFNKH59GflCYBf3rMQONTRTvxNaB6wo88cVpSTjtPwRBgM62jF0zCIIobU7WRh6ic1OzQhGmB4dtGCw2dyMa3zFN5Bgsd306jGRfqn+thPq+rsj3RQs5L91CvySElKIWU6LwXlieIHPbhZ0U3Qm5ubgOpQDW0Iqq9ghkQaDmu51kvU32/gF/qc3M4MeqkeY8MU7trWDCnJzDFEPisvA0dEfewhf5HxGH96k88HvyBd2ttmqpyhrfhXxFr2zRChUWgcA8juNW0fLXEI0xEWl8e45cMaYp1KnYCQgGWueun6SexYQwTklv6TjYL/JCDbEeqJLHiN7R17MgAZL935vLBzouGnhKmEcwbaHacPk0sTeod2AgVoIxdASIF2a3AwypUe6JUKQ2Tn5mOp7cTmgjTSfuXhfYBINR2yvAFJjmzDQfpMyD5mb23nqq2SgYOwMklwu8X1j0ATpUsGQRR8iZ9s2F0dDjjCZDA9OKi1AI26IX4jfefP62sOxS1iEZqXwnTyybp3SQ77+PGi5qOd6p7suN2e+GDylL+YHLwTwe9D+n+fCB/PFzizQ0+mat45psRs5eNJHSzFgE6RvetQv0vO4X2lj524rwKdYl7DsXecMaiy40w3G25rUFxaZXFZnfpGEtvCPKEQPJoMkH/XA74+Y8NetFMK83Ktfk0Sa9g9L2LgXqwZH/qbjY0Gr/1bxF/l+01b90fzK87lY72h6hM7thEXtstl+2+giruGd9Lgag1KYHHAxoFfzgeE8J+GuWUvKRSXga2TOW6G8qb9PqRrla3OZkEB4FRK/9xqhsLoxTEniXhKSf0jRcHBtBaO+0JAi3r460n6HZZBvIUasgzzd9hSaonIJWMbtCswkpF9Po5Jq1zNXlZU+yPems2tcCsfyv/iP0puRKJoqbbJ5opbDD7JiZB6MDdBZcJvPbNKcW6efNLGCD35jD88RSfrglztlfDD8BzaYxoa3dTwqC+AJy0DFCEuW/7JMSIdpb7DVojpYDB7ol78pwH+fDl+EYNf+f9ALbO1/XP7NY5pD3PIFcknvlkn//BFCSupfXRQMCVk9huoh+7J5c74wDNAnbU3WbUQI5cRKRUdKlfNLp4PzpJ+6PRTuisEGQL7Tdy2qkuVMwQCu0l/1ctlIzeOKKUqOTEaQkfrnCGY1RAmrv8W+FXK5ASN2Stjn2drBC6FL2ti30SgL8iQZM7+Zra7Lg8AfJy2h9iCMzSGXEeFXIAcIDmY+37UrlUiRRPIG8xQ+xYmqGH7A+tf4go2dHACQMWJ/m5aATTp8hSXE6
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="sha256"; boundary="_07FA7A48-46FD-C742-BBA8-C1B3CFC2653C_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: b7d32000-c297-4bbc-8cc4-08dd7cf18e8d
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 Apr 2025 14:18:27.6591 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 83d1efe3-698e-4819-911b-0a8fbe79d01c
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN2P110MB1558
X-Proofpoint-ORIG-GUID: QkwYHQNixwXXydNHm7YmdKjIqNSCrmeI
X-Proofpoint-GUID: QkwYHQNixwXXydNHm7YmdKjIqNSCrmeI
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1095,Hydra:6.0.680,FMLib:17.12.68.34 definitions=2025-04-16_04,2025-04-15_01,2024-11-22_01
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 mlxlogscore=871 mlxscore=0 adultscore=0 suspectscore=0 spamscore=0 phishscore=0 malwarescore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2502280000 definitions=main-2504160116
Message-ID-Hash: CTX5OYGVL74OTUZ25ND7DIZRFNFRFK7Y
X-Message-ID-Hash: CTX5OYGVL74OTUZ25ND7DIZRFNFRFK7Y
X-MailFrom: prvs=8201e787f1=uri@ll.mit.edu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [EXT] Re: WG Adoption Call for ML-KEM Post-Quantum Key Agreement for TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/8Q8XYrxotRp06E22ZnF8EYhfs2w>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

>> “Consensus” is not about reaching no dissenters.
>
> Consensus doesn't require unanimity, but it does require fairly
> considering and trying to resolve each objection---which is exactly what
> the list records show didn't happen here. 
I, for one, considered (I daresay) fairly your objections, and both myself and the experts whose opinion I respect disagreed. 
The record shows that our arguments failed to convince you, and you can see for yourself that your arguments failed to convince us. Thus, there is and can be no “resolution” aka “compromise” (and what compromise do you suggest when one side says “I need to do X and not Y” and the other side says “no”?). 
> Also, _if_ resolution fails and an objection is overridden by general
> agreement, the reasons for overriding it have to be documented. 
The reason is that the majority disagrees with the objections. 
>> It’s about the “prevailing” opinion of majority
>
> No, voting is _not_ how IETF is supposed to work. IETF doesn't even have
> a membership mechanism, so if voting were allowed then there wouldn't
> even be the most basic protection against votes being bought.


It is not about “voting” – but you must notice the similarities (and differences) between “voting” and “consensus”. 
“Voting” is where one vote can change the outcome. 
“Consensus” is where something like “super-majority” is needed. From what I observed – that’s what we have here. And yes, there are a few loud dissenters (thankfully, consensus is not determined by “loudness”).