[TLS] Re: Deployability of DTLS 1.3, HRR, and MLKEM512X25519
Frederik Wedel-Heinen <frederik.wedel-heinen@dencrypt.dk> Tue, 01 September 2026 07:14 UTC
Return-Path: <frederik.wedel-heinen@dencrypt.dk>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 026C7132DB8AF for <tls@mail2.ietf.org>; Tue, 1 Sep 2026 00:14:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788246897; bh=VA7pIGdDnaR0LkRvQF3lKsXH91qeSSL25iOu3nSYCrk=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=WYdgvcH1D6aeuTS83UAS/Oe6YYFtVf5uyUjuw7uPdboZxrNQQmqNvH6fg5qTJQUhb xjAWHeZYw3Uxq9iYrXuzQMN3wIpT6YSAe18wWHlZ/imuNSJpnDpdThySCSNfIosgju 1QlDBDUCEgHluoDtJE+4gYGaXX5UznRJheNeAQbI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=dencrypt.dk
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 92IqkS6AOqfc for <tls@mail2.ietf.org>; Tue, 1 Sep 2026 00:14:55 -0700 (PDT)
Received: from AS8PR04CU009.outbound.protection.outlook.com (mail-westeuropeazon11021134.outbound.protection.outlook.com [52.101.70.134]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CB720132DB8A0 for <tls@ietf.org>; Tue, 1 Sep 2026 00:14:54 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=I4Nn+tgZzdV9Ysy4M4GBQ/8kKgIGTJsXaICRqivh3WCFjCmizMVi+u0hOVzB0UKbsJc3fmcHSPRw7KkMpeW3+kIzPFoaEZoLDgAG1Ngbm8CsjWueaoEqX1sLLoOQZC1XlHTMUdBRFslw+ZTHeA2PdR3UwskgGAXEAdne5xta1yN7CFYEENJfZ4rTyuXmQfrEZEl6fXEw43X1wEop0uLCM2bdi3SvCqq3+8ul2gnULQ6LjGgzd0rTUqWkhzGFpVdRwLrRhaMaxHj9kFyqPMy50HyAQMo+WqoQDZyvvdGCASANWSI/shRuH7yIgt5QsNJKcN1URpSgxJBChLU/LCRimw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=VA7pIGdDnaR0LkRvQF3lKsXH91qeSSL25iOu3nSYCrk=; b=KPnLFJVMPJjW43RKr9IjXEb1AhBcdZn4j988bdaSGNffo0HFPuF7oTjBkKJUnoXrCTzgHXvp1zgWRQV1ccnU1hZTL41eaCyQ+cMV+v/9tQYl7NGfXDAmpooOY3ZwxvKizXX074vo3D/Hhl6ZxSs6nV/35J+leTpw1Q4Lk9ju+TB4SSLNnxvrllgufbOjCmcf8kNMsAAJ2PwVmcSKVby6tiZuYfz2UolPUyrGgWy6/oktkhrRweQRE45wD9NCJ9l8L7+vqlEAUj6GtnRpmgDCI2HAl/yplF4OKwJB13tpWEDQPGWApeBJUVta57EoRWeQi8tPdEBs44Dhp6gHVOPhEA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=dencrypt.dk; dmarc=pass action=none header.from=dencrypt.dk; dkim=pass header.d=dencrypt.dk; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dencrypt.dk; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=VA7pIGdDnaR0LkRvQF3lKsXH91qeSSL25iOu3nSYCrk=; b=stsSooBXntowWSMPoapEUIeY0Xbpth+1QFj5zAsuuepP9ooYjVgEdoJl9eaYJJMx4sKkCa+d2dsjVrcmI8Ew8hn68i1wwrXQES0ITOz7CUjbQ2J+R0ruFQ+oODNIYAfVi5uoldbe+EafSydMyGj/3qoLawTscLwdwVFpBnlPUZU=
Received: from BESP191MB2870.EURP191.PROD.OUTLOOK.COM (2603:10a6:b10:ea::6) by AM8P191MB1140.EURP191.PROD.OUTLOOK.COM (2603:10a6:20b:1e9::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.13; Tue, 1 Sep 2026 07:14:45 +0000
Received: from BESP191MB2870.EURP191.PROD.OUTLOOK.COM ([fe80::bd5a:dbe5:efec:5c78]) by BESP191MB2870.EURP191.PROD.OUTLOOK.COM ([fe80::bd5a:dbe5:efec:5c78%4]) with mapi id 15.21.0360.008; Tue, 1 Sep 2026 07:14:45 +0000
From: Frederik Wedel-Heinen <frederik.wedel-heinen@dencrypt.dk>
To: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, Ryan Hooper <ryhooper@cisco.com>
Thread-Topic: [TLS] Re: Deployability of DTLS 1.3, HRR, and MLKEM512X25519
Thread-Index: AQHdOSKstMnppxV90kmwzM0yzj7SP7a3/MMAgAFOzjCAAAVLYw==
Date: Tue, 01 Sep 2026 07:14:45 +0000
Message-ID: <4E9A53DF-D005-4A3A-8D37-39815339E107@dencrypt.dk>
References: <AS4PR07MB882587C4F9F2AE3F9447B25189A92@AS4PR07MB8825.eurprd07.prod.outlook.com> <11c93a79-05e5-4323-b7a4-8a521f4d2f4f@app.fastmail.com> <AS4PR07MB882529CB2DB3C3D31C56106289A82@AS4PR07MB8825.eurprd07.prod.outlook.com>
In-Reply-To: <AS4PR07MB882529CB2DB3C3D31C56106289A82@AS4PR07MB8825.eurprd07.prod.outlook.com>
Accept-Language: da-DK, en-US
Content-Language: da-DK
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=dencrypt.dk;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BESP191MB2870:EE_|AM8P191MB1140:EE_
x-ms-office365-filtering-correlation-id: 0078a777-8e98-4391-94b9-08df07f8b381
x-ms-exchange-atpmessageproperties: SA
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|4022899009|366016|376014|1800799024|23010399003|18002099003|22082099003|55112099003|8096899003|38070700021|4143699003|56012099006|6133799003|10067099003;
x-microsoft-antispam-message-info: vcamGW4CyxfZqgu7/xPVpOaruJh7m23plBmyqYMqM2d+f9yY6R0DEs3eduEFvjjaffD05EhMh3sACQ8eSyrMgbl+M1Fi6frCPDWEKLArYc8s0GnJuP+p02uSJ5NHPodyHqfIcYnkfZC40vWqj8eeBj2JosYcDLlFSLjOca8Jb3WvY61L5Xgmz9wg/DHt2wOEfbvJYj4ES/qNI4OmpK72h0qUKbRD1ejm18MAweKaQ/kNKk10HjIZIq8fsy24JO6fTVkK8Phzi61nJy8wlz/BjZGV4G7SArtF41SzN7B0epSCgslDkshp9AvLaVqBpu1CBzFiQqZ+rJV6wTfOFa3d+wtE4ehArkGOO4V6OHqz1M0UHfi86oeFxukUJtlU08EtTAsFhnZnMKHMYmenYfbYOXi9uyqKiVb/As0kVUHoJe2ipFuequRCJcpl7nfydSRIpawWgP7kldfLhkbPqnYfMU9gw02IFptBAUWaarK5anubC2FbZHWMljLDyF7a5ul/voQkDJCKX6QqYztZ8seVQLchvraeKacKCIUwIM2J6vlTA+OT4VZ5ytOPg66opyJuW+xhjg6uPieSeuFfS5k74v1j2LzLcs1k5S3hFQqx14eqIRD6lougsPDhASpKr3nUpnY/WhOtzySJrgz1sYAyZPg5wRTNJJzpO2vN1jFDWO8m6b4zkkuXeXjBB3nGx2/AlahMZRbPvydpXkNrP3y7esr1/URjcPRyhyLlOKnqWtQ=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:BESP191MB2870.EURP191.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(4022899009)(366016)(376014)(1800799024)(23010399003)(18002099003)(22082099003)(55112099003)(8096899003)(38070700021)(4143699003)(56012099006)(6133799003)(10067099003);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: SIYdmGufP1r7pubR8AnyGCsKfm9dX/WKFVhUBdvGaqFx95Pyv1CqVDF+ysIoNBbBkQBbSQOcnjfOJ5hplIytXwvET0iOslsLMfWpJ0JnFUHzXUGZDviUf3kXYF6QFNKIKglrEcWQYgfKfkFZ7JMVfxR5Ku9Lv/LsYxu7xKyKtzD7ou7iB7Z5a6lxlgpA2qD5Zy8bqLuKFXIl5FFjYuCBhXGaIzhrFimQz5CW97xF1slAgQ6l3ifld0pAycaCcIXU86ELsUA8s6OhJ6jM4nwbODz3rQxVc1koZZeKOnKG5eexVLsvj0iaiPIx7pttovZMGNN/CTu6bazV4QQr8CpsDztQ4ehbJ/d1msScUSfpRj4tscwt245/axrv7qj8Mt0sWNduWPRaeiZhgQg1Xt2EozolCH8FI2NpjJ3o42DXK43mgAJMvh3f03f7OCzW8F6uA1bRnjWSaH8pgwJDVXTSDUUtQCLAQmeVuO0/w7O88Dw4Dd8u6LmjucUySaKkjNV2Vm0zJLz24taaHFVgfRgSMrbybRZdnn8rID/7fW8+8Vfd/I+/CvhZW0Ubg4McoXy5zE+ocWJJ8T+TIynGixU4ayguo5XG0WNIhNXwTgP93E72UOKK0a3QXvAUp9kwMuVX0yil4iyqPhezh0INC9s+HUoAStqBqktLd+K/YM5Wt7cunbbtSWKwqXGUXKLyi5oE9OuNAb4wyrdU+ivbuRpr90Doq2Z9v50CEyH+e4IYzWwDeN+ddUQhTx3WeD1pPm/S3lP/cQ2TlKREkLHskB5h8Ujs82STjHqyZEaxB2PCkj3D5xaiSaNgBtBV9v4APVV8UU4m73Q1rZgWuaFWJFygmBNZs2NDw3JPFhoB3oXZdi5eYojyZo+lVbuTFT2UcpBaL097hHuq4eGB8OptSOfDf803k2E3JAkHVWUrg/RlSMhezJWpkHhOspdIWMfyIY0L/lnU/OWus6VOh7l+LrFkg9ZzK0f3tXS/1KeLASfkeFP4Gq5kBZdQSJVEs+dE8xnnn43m4tvhoY2EJGiUWLSwXJwX09Rv2Si1RzRvYQvezNHuafrtmp06wX2HwtHiOR6CLzdMGfRhHPyjVFQaSfc5XRCPEf5XTramBmmOTz7CpoRr3DQqYvcr8j2zS5JfAAmu8G6ToSUski+hPmWCdu202OA2d06rBjjGXwzF7/PKqJOsftpjhZz8RsA4u1S5K8uZ2woWZzhSQNwA3HR8SftQwTuOg661aM0zmvTEkh2tI0luBXrSS+ddHMizP2h4ekneHeWmDigFhEazGqx7DpK2x/K40ZPjZGs8wg6B0JWgBsKrBsFMFipnzbg+kCM/M0nyrjs0AA5UenqaFxx7xyURJS4OALmVprFcEPJQjwqyY4Z/ORXy+Eym4li19HpkFQBwicauu37FdpYSlNs0v1PVjb1b5nAvAflqwt1cp2brhgTJvU5dwAVjhakv9ZRa0kDNPRPop2r383/dnsd/5B9NtbNXzn7521TFMDuydrTRNoI8OiFlkMFaTdXY/zInCo7wNUcbyVO6z9ygfh1nkIWAet8T3sL5wOcelmjAT9gEsSkVb7/4CebZwTSIJsgfB+B1JMTLwPCqMMhdtQiEfJN/0xrHOCQ09N+6cr5QOny9tfZ7PUmXNM8VraUPv4uGnrhl5gh75j7k9KLvhQeUlctXa/vKx7suIzW9wiJExJ7OHrx3vG124ZXonGWyISjG1Th9ie9po6XXNd14xblGNbkS5XgUOhFwWaA1JD6N8rBc82Y=
Content-Type: multipart/alternative; boundary="_000_4E9A53DFD0054A3A8D3739815339E107dencryptdk_"
MIME-Version: 1.0
X-OriginatorOrg: dencrypt.dk
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BESP191MB2870.EURP191.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 0078a777-8e98-4391-94b9-08df07f8b381
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Sep 2026 07:14:45.4663 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 6d83943f-0558-46a1-ab6d-9b34ee064cd2
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 7TMxFzxPMuiD2QPDaWv6IcFqPMmLwj2r/GE3n1XJaqZJbQv6WklAF93NdAXIvJoo5G/5t6RuNEGWxNUQnc+HpX0tZ8yx5BFcShdZV8/6zNJBOoOXD2lt+vbO4uf2j/yz
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM8P191MB1140
Message-ID-Hash: LRYVGIEZGCMYELCPVH3EB4NNT5R3XWOD
X-Message-ID-Hash: LRYVGIEZGCMYELCPVH3EB4NNT5R3XWOD
X-MailFrom: frederik.wedel-heinen@dencrypt.dk
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Deployability of DTLS 1.3, HRR, and MLKEM512X25519
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/DLYBSyavVBD8Txo2n0UOl40hl7I>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
I don’t know if it is of interest but the DTLS 1.3 implementation in OpenSSL was recently merged to master and will be available in the 4.1 release expected in October. @Ryan Hooper, I remember I had some issues when integration testing with WolfSSL around fragmented client hellos. But I forgot the details, maybe you can chime in on this thread? Regards Frederik Den 1. sep. 2026 kl. 09.01 skrev John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>: Hi Martin, We did not test the DTLS 1.3 implementation in NSS. I will check with my colleagues whether they can include it in our testing. The DTLS 1.3 and TLS 1.3 HRR tests were independent of each other. We tested NSS’s TLS 1.3 implementation and did not find any bugs. Some of our findings were: * TLS 1.3 HRR: wolfSSL and mbedTLS do not echo the HRR cookie as mandated by RFC 9846. * DTLS 1.3: BoringSSL and wolfSSL do not interoperate in their default configurations, regardless of which library acts as the client or server. Testing the default configuration is important, as this is what users are most likely to deploy. Based on your comments, I assume BoringSSL and NSS interoperate. * DTLS 1.3 HRR: BoringSSL does not handle an empty ClientHello key share, which should trigger an HRR. * DTLS 1.3: wolfSSL drops fragmented ClientHello messages. Cheers, John Preuß Mattsson From: Martin Thomson <mt@lowentropy.net> Date: Monday, 31 August 2026 at 12:58 To: tls@ietf.org <tls@ietf.org> Subject: [TLS] Re: Deployability of DTLS 1.3, HRR, and MLKEM512X25519 Have you tested NSS? We've had that deployed for a pretty long time now in Firefox and - aside from some early problems - we haven't seen problems, including with HRR. We have no plans to implement ML-KEM-512, in either form. Our early estimates showed that it doesn't always fit in an MTU when other TLS ClientHello overheads are considered, so I'm not sure if it really saves much. And if HRR is as broken as you suggest, that leaves a serious risk of ecosystem fragmentation. On Mon, Aug 31, 2026, at 12:38, John Mattsson wrote: > Hi, > > We frequently conduct interoperability testing using our internal test > suite, CipherSnake. We recently expanded the test suite to cover DTLS > 1.3 and HelloRetryRequest (HRR). > > * DTLS 1.3 appears essentially undeployable in its current state. As > far as I know, BoringSSL and wolfSSL are currently the only libraries > claiming support for RFC 9147, and in our tests they do not > interoperate. I assume we will have to wait for RFC 9147bis and > subsequent implementation work before DTLS 1.3 can realistically be > deployed. > > * Relying on HRR for middlebox traversal of large ClientHellos is > questionable. When discussing the need for ML-KEM-512, several people > argued that it was unnecessary because HRR could be used instead. > However, after testing HRR interoperability across 11 TLS libraries, > our conclusion is that several libraries do not interoperate, making > reliance on HRR problematic. It is therefore good to see that > MLKEM512X25519 has recently been registered, although future library > support remains uncertain. In contrast, support for standalone > ML-KEM-512 appears to be good. > > Cheers, > John Preuß Mattsson > _______________________________________________ > TLS mailing list -- tls@ietf.org > To unsubscribe send an email to tls-leave@ietf.org _______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-leave@ietf.org _______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-leave@ietf.org
- [TLS] Deployability of DTLS 1.3, HRR, and MLKEM51… John Mattsson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Martin Thomson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Marco Oliverio
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Martin Thomson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… John Mattsson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Frederik Wedel-Heinen
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Ryan Hooper (ryhooper)
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… John Mattsson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Martin Thomson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… David Benjamin