[TLS] Re: [Last-Call] Last Call comment on draft-ietf-tls-mldsa-03: Security Considerations

Blue Dog <king347608@gmail.com> Sat, 23 May 2026 03:05 UTC

Return-Path: <king347608@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A0FA5F395694 for <tls@mail2.ietf.org>; Fri, 22 May 2026 20:05:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779505509; bh=cGUFISgyio87jWtd/z1PrneleFQsC6cJgmaOjtdU3HQ=; h=References:In-Reply-To:From:Date:Subject:To; b=xWDyd8cd1GA/uuWZWrj4snxPd1WLyaCpbKS9dNwPY6n+gcloJyJ0xjF2gEVI5fdps 7dP4ozOh10uLTlU8EQZARl0USZnxA7rMsRisz/1sTEdKteZJOnloGU25tfSIIztyWt hdKxlbJuiHQfIH8h3SS5NttME5ikNoWL3ozmJuHc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.848
X-Spam-Level:
X-Spam-Status: No, score=-1.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ok73U05M33Bk for <tls@mail2.ietf.org>; Fri, 22 May 2026 20:05:09 -0700 (PDT)
Received: from mail-qv1-xf31.google.com (mail-qv1-xf31.google.com [IPv6:2607:f8b0:4864:20::f31]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 23BA3F395685 for <tls@ietf.org>; Fri, 22 May 2026 20:05:09 -0700 (PDT)
Received: by mail-qv1-xf31.google.com with SMTP id 6a1803df08f44-8c7154725easo91706146d6.0 for <tls@ietf.org>; Fri, 22 May 2026 20:05:09 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1779505508; cv=none; d=google.com; s=arc-20240605; b=DTMb4Y1tpInImaH9rxh9sgmzU9DqhIZzFsX5yDnSNHpGXxEoCgL/Kni5jQ8c9EaWUZ RjHMRiLGGDGkvANwA7YaL0GVUcCJLMxzHrZXLqjWKi/ENhKR1L5iDVJGUm5xq2mJRAJs U25lIHelC/Andu5FHHqZj3rB8+hbhGxx5hoLBo2dpWu5u/yjn0YkdS6gaCp0goRvCxVe 7YyKIgjxxpZLW9GMmIxqI68ic8JznO9TZNAdDmeI9xny9W7YRjnp/w4z3uENKdY4d9ke rqiLKeNX4cDBypLh+/OloQX1wAMb2kF9CAazyyLGXoEJKKRFFrWzwA0KWtCS6g6HAsaN Udlw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=cGUFISgyio87jWtd/z1PrneleFQsC6cJgmaOjtdU3HQ=; fh=mqIsY7xK3y2IYoDmZT6RXee3Hz9Mgu7dZ5Y6ZiSJ+Js=; b=PTrCHkaot4+D+aUalnUGAZkx9UtKz0ASiEMqf8OAGO2n3ceRE3BM1353ymdQO0BLci hSLzAVQC6EhGa0SsUgKRb2X4ehTJKYvCXT2yCslqI0Gm5dTV7O9Dxi81+7SXN5kUSMDV 0KGm3xSa7QInjPfReqF150K2QkyrUWyZF1F/DeqDI5Dtel/4PoixV+XeOiwDjRsftJia YTWpwKfffAKua4F4doO4rpTPkUQ57bhJ9QgK+3vk6ttbCMDGIIlZgtjRmSUvBWXHDk59 CAP7O+8q3u4OLF655EmLaKqaoRrtzsDexerJvkjMHd89/2IPKVx5zug3UZYDuHGa09ww gLSQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779505508; x=1780110308; darn=ietf.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=cGUFISgyio87jWtd/z1PrneleFQsC6cJgmaOjtdU3HQ=; b=NMHd4//FzM2aIIxnavwESSyoJPCK6Q6IfGyVnP9o+fEfSl7qWU6LmFKJF6AJOgzIAu pb5kAc1Gs9Gdbx3qs5qYLWql1TAsuWS7M8OZOn82lysH7OYJOA9Q8R1ZHY1EmvBAfyT3 tulgCFeHhF4T0F+EZUd+SknLABvoZTzEuWKBYjp+gjCY4Q0mQuGZV4p7cIBXctNFlLrT cI4Fv1t14b4dhLuKYwxjI/pLNrVZksW5fzLx8Cln97KQFidJgnlFXq9afHaajdrXDT+F w9k2WMH1SNVY1qJP0wjG2yrJaca2KDzFnpigkTo0HtH8/MswwwlBOzPm2YmKlaMhIIC3 bZwQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779505508; x=1780110308; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=cGUFISgyio87jWtd/z1PrneleFQsC6cJgmaOjtdU3HQ=; b=nGESqeGqEU+SGGFlCL4wqVVRou7APu/BBhRZxTo8DECFFbik3CaWKRrcst+JODFZ5F na/ukh4DlHTNQGyqAyjW1lvMi1i+K3t1stpWH0Ns617eH5zSHGlueWaTV+dGD/yka5Ud BEEmgpPRVOoxnrlR9TLG2ZDTKWkhElmHG9ac2dkYDMoXtPgQndGcQI+6OW64RhfIwWfU TwVSrZs4uWgIAY6iA2Iwyy1wULRml+7GBrhewnXTvYlUSQdfDHFTOowYSuMXGVIpvJeM yflhvF+VG6vqMhsgyucykCrRmCqjealh7qC3ZHoPY8nCP8ETqsCsq9vMph4IcGiW1Hu5 TuMQ==
X-Forwarded-Encrypted: i=1; AFNElJ+eLlT31UIGH/lGcxKSYyKAgGNZQ2xPZfUFoq04Npvw/eusrP1yz6yNBK5glXrAXepKkLs=@ietf.org
X-Gm-Message-State: AOJu0Yz+9Kpsup9mnNZXmqTsk4OM3ReYpBVQSVy1Q0xgy6E0Be9BMY7o mnM029uEwHzRYZgREpg6A4gJqS18iHtoUoeNY7PAEhiy/Z6umRLZi3tVdTbfgIyLuZCCvPH+AOS ybodDCRm/V9t4E2fQiUVLd+iC0Z/0pRzdV7gu
X-Gm-Gg: Acq92OF8rtf2bbJBjA2d9IlQlHXmRwG5lOn5AUK8mn+/hRlkWSRMpT8qXPX/M5ooA9U Nfcso6THqwVgNK7vfBexbQUQwL34BYthkb2QQpaYBlOVwXsP1p/siaZh3Dv/DmrxKNRRDgoJBF6 fc92mB2R+qUxRWwsCVcqULWhUBw2Cvp5VvWDyB3xWbM9xoG2wS3BFvBH0bDbnUnwQfoUcqnxrpz VUc2vVu1IajI4mF5SQtt3OUsBbwqjU7IHV+KXUMvPAfbfaznhb6a4jCu3mKCWOkU5MFtIJcwD+6 i9ANrrg=
X-Received: by 2002:a05:6214:1250:b0:8ca:1e87:29b9 with SMTP id 6a1803df08f44-8cc7b5f09bfmr107769066d6.5.1779505508079; Fri, 22 May 2026 20:05:08 -0700 (PDT)
MIME-Version: 1.0
References: <CAK08nYY6Aqi2hHAxwmF6n52SRYDL9hnQPJJyhfJkCiOvyj2yUw@mail.gmail.com> <BY5PR17MB4020C2180358E9FC60ED16A0CD012@BY5PR17MB4020.namprd17.prod.outlook.com> <CAK08nYakYrztzXWv9AiggM1a_09oPHSF7UJPAvvAOdyOwoEzQg@mail.gmail.com> <ag63N9Af6dINUN8u@LK-Perkele-VII2.locald> <CAMjbhoVqE2v9TZ1egOGe0kNi-quM4v9TdrOU22E6gMa8BbM7Cw@mail.gmail.com> <AS4PR07MB88251771E95594BEB7987817890E2@AS4PR07MB8825.eurprd07.prod.outlook.com>
In-Reply-To: <AS4PR07MB88251771E95594BEB7987817890E2@AS4PR07MB8825.eurprd07.prod.outlook.com>
From: Blue Dog <king347608@gmail.com>
Date: Sat, 23 May 2026 11:04:55 +0800
X-Gm-Features: AVHnY4LxjK8NVZt2qyBlehfF99lV0WR69FOgI9wRjbm5YBlbHSRnZBhCJRd6WJo
Message-ID: <CAK08nYY8ZUXFCB97qWeANng+PhMagAtbvaKrm4DXQmq6F6dfmQ@mail.gmail.com>
To: last-call@ietf.org, tls@ietf.org
Content-Type: multipart/alternative; boundary="000000000000af5aa40652736902"
Message-ID-Hash: NYRJ3LCVJPCNDP7OGFJC4YHYUK6GUN6G
X-Message-ID-Hash: NYRJ3LCVJPCNDP7OGFJC4YHYUK6GUN6G
X-MailFrom: king347608@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [Last-Call] Last Call comment on draft-ietf-tls-mldsa-03: Security Considerations
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/ErG0DgxEfkLnMYlUzhiHwkL13Ac>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hello Ilari, Bas, John,

Thank you for the clarification, and thank you Bas for opening PR #36.

>From my side, I do not intend to push for a normative requirement on the
signing mode. The point I was trying to raise would be addressed by a short
explanatory note, if the WG thinks such a note is useful, making clear that
TLS does not signal the signing variant and that the TLS signature input
already contains fresh transcript material such as the client and server
random values.

That clarification is narrower and better than the text I originally
suggested. I have no further comment on this point and will follow the PR.

Best regards,

Songbo Bu

On Thu, 21 May 2026 09:23:51 +0000, John Mattsson
john.mattsson=40ericsson.com@dmarc.ietf.org wrote:

I think it is best not to add the suggested text. The signer can only rely
on its own TLS random value, and while the hedged randomness is often
produced and kept inside a certified hardware security module, the TLS
randomness is not.

Cheers,

John Preuß Mattson

From: Bas Westerbaan bas=40cloudflare.com@dmarc.ietf.org

Date: Thursday, 21 May 2026 at 11:09

To: Ilari Liusvaara ilariliusvaara@welho.com

Cc: last-call@ietf.org last-call@ietf.org; tls@ietf.org tls@ietf.org

Subject: [TLS] Re: [Last-Call] Last Call comment on
draft-ietf-tls-mldsa-03: Security Considerations

On Thu, May 21, 2026 at 9:43 AM Ilari Liusvaara ilariliusvaara@welho.com
wrote:

On Thu, May 21, 2026 at 03:20:32PM +0800, Blue Dog wrote:

The concrete change I still think is worth considering is the narrower

implementer-facing guidance on deterministic versus hedged ML-DSA signing.

That guidance seems TLS-relevant because the signer behavior is not visible

on the wire, and implementers may otherwise treat the choice as a library

default without noticing the operational/security trade-off for long-lived

authentication keys.

For TLS, deterministic versus hedged ML-DSA does not matter[1]. However,

given that at least three people have commented about this, I think that

maybe the specification should mention something about it.

This is a good suggestion. Thanks Ilari.

https://github.com/tlswg/tls-mldsa/pull/36

[1] The randomizer only appears together with the message hash, so it

only affects things if the same message is signed twice, which TLS

never does (as the input includes things like client and server

randoms).

-Ilari

TLS mailing list – tls@ietf.org

To unsubscribe send an email to tls-leave@ietf.org