[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26)

Stephen Farrell <stephen.farrell@cs.tcd.ie> Mon, 24 November 2025 23:00 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C33148FD0852; Mon, 24 Nov 2025 15:00:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p13ifQO2IS1g; Mon, 24 Nov 2025 15:00:30 -0800 (PST)
Received: from OSPPR02CU001.outbound.protection.outlook.com (mail-norwayeastazon11023096.outbound.protection.outlook.com [40.107.159.96]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 327FC8FD083D; Mon, 24 Nov 2025 15:00:30 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=nnxN5d7J6NE2OPr5z5iSY1n3BM9/+cY2nqvLddpDN74RyNAyQt5t8XuCAIpvpwfEL5hNwGbK4NKHe8DIQgl0D+r+lam2g0ddNNy+97iRbtUAqpy7gA+sI5iNRv5uFKCDB/Gc6BKSJQ+2pM6Bbp8eQ41g57z8YrwiqURXBMduCxDmtvsKqhaV2CG6qGuV8S4QQIlJQMFs32fB9+jtacMbtZfHbESmlCSG3GhqwmcVRW9ZAixS/9ESoUVoEkSziuqk3kwNggTI4VDWXEYoMeziI9vBSrWSb/J9sbXwq0WvJWFdUIvnL16n2Lzaewqk8gGXWjYw5XKBqqevdlALgL494w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=8pJB3/yZOEH+areu7WZd5d/m+cE7otAVTGI1osEVpww=; b=XP7Nwp+IIZfAJEExjgOitukYmqHWYJL12qZydrpwIqt/ZNcQ/Q6i98CWIfOW2E/agcGK4kwcb883NkAfHW9IiyUtllrKW8D7J+NminsKskom0djgArlLCCaUnmpEL/5SoSREdIPRJM2gdYOUHyyle2xL+4ONxd9tkYG4hlAYfqxnLUdIL7MZUFZpJidWvg+iMnxEwGNK4dCzOYQw2VtvPRZCTBiEQf1hfmwT2CyQhS/rBdGoD3GAbiI12JrUprWw8i3riR9s53SpiXfJr7ZHumrxBgdfGBdqxeDfqDM5/m5uRahZJvpXYK63tMN5lxvQRBxmDxV9GFiHhbGPbObEOg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8pJB3/yZOEH+areu7WZd5d/m+cE7otAVTGI1osEVpww=; b=lvmVg2aW0kLS3c2nnNW9fSp4EULO+EUlF3Tk8nGs+Nem7pm9BNr6qqzDjqo+Us+VntXjW2mTcBfC7qskRTpXG82CU5lT+0F1BMVNAkSPn66KhgmX72njpAIkE2BeJH3IYioYOBUgtn7mlH91PkDH7V4ePFaxC35XGfOgX/pH5vXpDL+xQhRSkBOr8OLeYN4EBiaEV1hKsJXyy5pCCHQRskNAJCXFbJtaenqDQIQB8ugwWwSPn8JcZ6DKEavgtZ/5z2CHMqEEWGP2on0wZiP7R0TAo1ZVFXejnQ0dj+WT4AhYNBFsxuobQA0JjlYU5sdyCaU2/UtWkjah3d6OponL4Q==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from PA3PR02MB11163.eurprd02.prod.outlook.com (2603:10a6:102:4b4::19) by DB9PR02MB7067.eurprd02.prod.outlook.com (2603:10a6:10:227::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9343.18; Mon, 24 Nov 2025 23:00:21 +0000
Received: from PA3PR02MB11163.eurprd02.prod.outlook.com ([fe80::d308:cb8d:9d3d:31b1]) by PA3PR02MB11163.eurprd02.prod.outlook.com ([fe80::d308:cb8d:9d3d:31b1%5]) with mapi id 15.20.9343.016; Mon, 24 Nov 2025 23:00:20 +0000
Message-ID: <066c8811-e20c-4eab-8be6-f4d0f94b89ee@cs.tcd.ie>
Date: Mon, 24 Nov 2025 23:00:18 +0000
User-Agent: Mozilla Thunderbird
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
To: Sean Turner <sean@sn3rd.com>, draft-ietf-tls-mlkem@ietf.org, tls-chairs@ietf.org, tls@ietf.org
References: <176236867319.904123.10146982018394612684@dt-datatracker-5df8666cb-7l4w5> <bc79d0a8-ff81-4b02-aca0-4221ad6a8fd0@cs.tcd.ie>
Content-Language: en-US
Autocrypt: addr=stephen.farrell@cs.tcd.ie; keydata= xjMEY9GzphYJKwYBBAHaRw8BAQdAo6JvjmSbxHdQWPZdvciQYsHhM1NxQBU398Mmimoy4p7N M1N0ZXBoZW4gRmFycmVsbCAoMjU1MTkpIDxzdGVwaGVuLmZhcnJlbGxAY3MudGNkLmllPsKQ BBMWCAA4FiEEMG54R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwMFCwkIBwIGFQoJCAsCBBYC AwECHgECF4AACgkQ5Njp+ZeoM93bogEA25ElRyX0wwg+kGEN1AoL60MoZfvQZ/VtmXY6IC5j +csBAIBpkL5ySuzJK2zLNZn9qQGht8IaUcA7cvDcLvS2uHUEzjgEY9GzphIKKwYBBAGXVQEF AQEHQILCPWOwW36e8D3pY8GmvvtItIT+A5uV80ist+WokVsQAwEIB8J4BBgWCAAgFiEEMG54 R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwwACgkQ5Njp+ZeoM92bcAEA8R+8cpqRUIS+SoAN iO05xE6O/wEx8/e88BqzAYki3SoBAOQdwiPX+MQrAxkWD8xxOsdMOAtxYKpkD1n8aPJUw6QJ
In-Reply-To: <bc79d0a8-ff81-4b02-aca0-4221ad6a8fd0@cs.tcd.ie>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------OxbwbugyPkD2JFRg01MEL08h"
X-ClientProxiedBy: DUZPR01CA0024.eurprd01.prod.exchangelabs.com (2603:10a6:10:46b::11) To PA3PR02MB11163.eurprd02.prod.outlook.com (2603:10a6:102:4b4::19)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: PA3PR02MB11163:EE_|DB9PR02MB7067:EE_
X-MS-Office365-Filtering-Correlation-Id: c7d583ff-af70-466d-6781-08de2bad3d83
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|10070799003|366016|1800799024|19092799006|4022899009;
X-Microsoft-Antispam-Message-Info: +amqmBe6+zod+4R0lmdkWIDMhIxdVY7K/qBQ0qZ03+nqC7QMtc5Rm5yBHj6eOQdR0nCwPFeVqeujCfaCgRQI2S60Wa9BFD/88/+v5eUhvcQ6RRFxG9qSh32xisLXlBn99kbSRyv3KQC6e5Qg1eO6lltSpzcdTP82mp59A5cCediLmQk/Ueaa0SCilwsbmiNoeOhnqiExjcUxEFlo+vRsZhkor2bAsTzncvxmKJIOqSqoK5bvtrKgsCYH0C23cwsU/Xu6dCvBvexC4Awu2laghlcmiZ/ZBcWuHbfi0t/SdAai58OJDe60fCO14K3QFQHUeVIGxEHwvUIHFBzG1HlbuxzPjLrN9CupKNfKToMH2qVfsD9dnqk6taGkLivU46vkjz+uyAbnAWI3EzAqCEP4PUpvusLJekz8O65l3AweoxVwZrt7veokPsNC/UFSJfmmqnX7h4AsXapnDQmJT5U3kJmyD7Ir0/B1m0CxA6gh4cKd72153+9LVojjrUYlT3fYlpiPURO3f7hqdkRrhOwIwf9v0ZwSMyyJGsAdaWnYM+yEe4sq0p+z6tqfOzHeP8dQMSesIVYH2VwbqcBT00d5UURX/UtlfqNJV8phWOkZ5grjTCrlavJjcQJ5L2ZRDapVgY/ttH3LWinKywA8NIG0bcfiSC9zDt6i0sPij/xkp8uwygIK+zwfQzENREYlJzPiT4FeTjPNb5kLrxqQ8AfQ/qfyKOXmaMFNGMFwyv+AW2hyRJK4eVXdQa0zH8J2Swy/Q/yHZblkO+m6Pn5DwqNM4j/PiE7GqOMc73ZZxtCizoWljBIQkOha99xRZpHi/AkMlC6bZeo2KFt4MSOyyc/h5lCpod+qJX6mdWdmcp4aAnCaR5iJuROrRW47nlaJFD2WvtAB2F+LxpjxyaIkt9nOb5xPMIovd83vPe1BDGzpx/0GPEYQNdQeSmgsE+TDlKHz8tmSVzpMff9dzkc6Jj4UTXE6FC/8V1Usn//9U+9xD9IUUMbfLEVw8IJg4kloN9cpRAYa9EwQStiDA0frAJyoMgwRPHSq+CxSJJX9uiD7OzzhfWhcTIff+1OR47qN/RJy1E4pphPeO+clGb2T9rN36kXyJTgaC6i+IIEr+csbd+v2hJLbxvcx8USiF9Grh72zqmbwcZJE9WY//RvX4E75/A82nmWDN/Dzv3Vm95k2c6sTtRcUoSK5T9j/lVpCxFf+QrQPh6g2DDrmm4YYy+fxiYOdYiYYhy7CovPZR+Zo7m3ZHuE8vdYx0A+NLQlllbuR1G3R4BOqocmPrukche/Wo1swFKjAtlGVfbXyLDyjn5D9Hn+uaNJbV7w+0TnlrnLtFlaj/5VRo0WOTpHwu7Tkqu9ruNKVcYz62STSLufa/vllUnXVrpYl6UdcRVN0vLbTyxy+mWaf0bmwLoQ5jab/HmGrMINk9JAWegBVx48Z7nczKegM+YKFHZMnblyXu7QCRvQineTsGEYU9QkGqMpYlA==
X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PA3PR02MB11163.eurprd02.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(10070799003)(366016)(1800799024)(19092799006)(4022899009);DIR:OUT;SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: 8bBSxd39O4Q0AL8wHQM+zCvJmEwUVW3FwPMBEfkd41WOkSiMlShgfEj8wJVc6iHYWTb1WY2HBFqLTBm6hf77pPOfmeOy5UJNbcaj7l5UjIfQAg0Dk+7ISRnql4z+cYqFMINI07aYPd62sSKv1Z43W/TOcClkyb58HhtCYWOt+x5nlRo358EdiLRPao0+TKET8cdqsphlC6FE0FcR5O8tJ0gP571jsk5HP/FDtAomWn4rDcQhCbZLiYPAfV2sQ7nnt9cGZgVfFBs4FP1gwymjAf8QYfLYTAACMHJ1S9oRFwsl0DigINCULHaAkzcA8U02jP33d+EGzSbJGtpmSSvz6SmsG4pArtO/KlrmSVaWqQfVmibbSKiGz50z3SO9V53fqsMiCk39IokbwaXo8B0woXx/ymFPlcXelyKl4J+gqK8Wys4QtASQ+zZfYVBXbk3oKDvC+f7MTOEuEMS475RxmIi7t+aQlMtPBVq/sAk1KdmlRtQ6NrFkwGRaO81eZeL9wi4SonzH2hevzXMQWKUGl3JP7Vckh+Xvy8YcDS4fEk6Q25/hLgFXjR6WplcNzJdIzsoxuWgXjpxqdDZURfovhCfFedzYnf4La+3nNxqFYikis78IJdCG9eAlrEgMnL7GYpryzEV9dL9HwS22hEgtLOr+IFo9Em1TBivEWzO0gAiozigpGkb1xXwIqt21sAYvNdPjkGrcxsZhhzYiag1tKLPDNHDNn77+xJV4qR3BmdrLPPQ3WyOtuiaPvcVgJGpNSBkHwEbL98tqoKF5sedMQfeKPmL+qSZZ+ZhU1UmPfSwYeASTjwXDrV1I/71GY/u5CqcMK7JQp3MzVM923F6rdv5Mmeel+E7H/o/zmMBXVrtjNtFcbe/jeNKwTtdCAH9MtdIdHYAHZQJsQMU2ravpSgcEy6fexyDtX217Q7YjvZ2a8K6lUfAzDAYuyKul3hL4majzZpofjsw6esq3fmVzPdLM4Gdng4O7dWDB5IThyP1DpDDLVqCrAc3Xe1CGMqkrVO48Rl+HPUxkMe5+CLS4wH7Y/R+Rrs8c/cS7IZqlx9kGZm0gw+Fx1EFB9M/T1rfaaG8NfZvAwHF1xfWRK4hcPCLvqcEeYUFCa2y7hVxZ3p576tpA3AeoyEINdAyNldRO2eOGweOFjrGA57guOQkTMQAS8NlCW4HC6c7BkRmBao/GFoQweHyS4FB3Xj2Rieg3KPuNhkJpllmiVNqm+7QFiLyr9qSdni0kZUCYcW4qB59spGoN3vlrVBRiFBdmVir/Q0l7dE8OplBOAYTydZVoiJRAx96/vsjucVldgcRnALaybKO1Zt6VLiA6ZYJdns+aXHWUu7h+tNP8Kpo3LFh26P1B0AoDYtI0scuauktLVI5GO3ZZPNZbMV9ELh8qWiTUpnTO4IohlsVDW98n6b5w5PwDtAWe6/Gh5usEQ7q+sPgR6LwrUg07lz3nW04p+mRiD2ux1OhoQePUwsD/jNmUlAwyF21r0xXGf7KO5utFYSr7GViNtbSmJeSqbnrzPgtpfR5c15MmBhBYwGjc5xe1bBvyVH5ziD3s/qFWwmhRf410sXM9oEbXoepHT4Hf6IqFtJFlaPLmFnLIR9AqMsJBZLgknKAyBs/YNBMSVmKl9U1rE5HhyrGw4BGJng9Y0qnF
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: c7d583ff-af70-466d-6781-08de2bad3d83
X-MS-Exchange-CrossTenant-AuthSource: PA3PR02MB11163.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 24 Nov 2025 23:00:20.8565 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: 9CUvVxsXrCop3ATvp1AcyCZJwDRi98l4pDPZsUgxHDt0tFXlQ/un025oz4GwIbPX
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR02MB7067
Message-ID-Hash: 557AD4Z7XP5DAXCR2HULD4Q33ASBIPCU
X-Message-ID-Hash: 557AD4Z7XP5DAXCR2HULD4Q33ASBIPCU
X-MailFrom: stephen.farrell@cs.tcd.ie
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/Fx139vcUbU-69L-ikF0tl4MT3_A>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hiya,

Just to clarify my position a little, based on what some others
have said: I'd prefer this not be published at all for a few years
at least.

I'd also prefer we develop a security area BCP that covers the
hybrid vs. pure KEMs topic and make that a normative reference
for all RFCs documenting pure PQ KEMs.

Much worse than either of the above would be to add specific text
to this document saying we prefer hybrids. But at the very least
that has to be done. If that's done soon and there's another WGLC
for this document, I'll still oppose publication on the basis of
the 1st two reasons above.

Cheers,
S.


On 05/11/2025 19:00, Stephen Farrell wrote:
> 
> I re-read the document. It has zero commentary on the issues about
> hybrids vs. pure PQ. It may be hard to reach rough consensus on what
> to say about that, but it is a topic where people have significantly
> different opinions, so I think we ought say something, for example,
> along the lines of, "At the time of writing a significant number of
> knowledgeable people consider it better to deploy hybrid KEMS, while
> some do dispute that. Opinions may change over time." I'd be happy
> but surprised if the WG had consensus to add such text, but we
> should. Absent that, I think producing an RFC based on this draft
> provides a misleading signal to the community.
> 
> Also - what happened to the adopt-but-park plan? Did that get lost
> in the fog of appeals?
> 
> Cheers,
> S.
> 
> On 05/11/2025 18:51, Sean Turner via Datatracker wrote:
>>
>> Subject: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26)
>>
>> This message starts a 3-week WG Last Call for this document.
>>
>> Abstract:
>>     This memo defines ML-KEM-512, ML-KEM-768, and ML-KEM-1024 as
>>     NamedGroups and and registers IANA values in the TLS Supported Groups
>>     registry for use in TLS 1.3 to achieve post-quantum (PQ) key
>>     establishment.
>>
>> File can be retrieved from:
>> https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/
>>
>> Please review and indicate your support or objection to proceed with the
>> publication of this document by replying to this email keeping 
>> tls@ietf.org
>> in copy. Objections should be motivated and suggestions to resolve 
>> them are
>> highly appreciated.
>>
>> Authors, and WG participants in general, are reminded again of the
>> Intellectual Property Rights (IPR) disclosure obligations described in 
>> BCP 79
>> [1]. Appropriate IPR disclosures required for full conformance with the
>> provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are 
>> aware of
>> any. Sanctions available for application to violators of IETF IPR 
>> Policy can
>> be found at [3].
>>
>> Thank you.
>>
>> [1] https://datatracker.ietf.org/doc/bcp78/
>> [2] https://datatracker.ietf.org/doc/bcp79/
>> [3] https://datatracker.ietf.org/doc/rfc6701/
>>
>>
>>
>> _______________________________________________
>> TLS mailing list -- tls@ietf.org
>> To unsubscribe send an email to tls-leave@ietf.org
> 
> 
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org