[TLS] Re: Ketan Talaulikar's No Objection on draft-ietf-tls-mlkem-09: (with COMMENT)
Deirdre Connolly <durumcrustulum@gmail.com> Wed, 02 September 2026 19:21 UTC
Return-Path: <neried7@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 2486F1342395C for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 12:21:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788376869; bh=42I3jBEMLCI4LHegvg8NWi5s6/WGYKJl2djN6xjumwM=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=wDISP/anYEA+qKZulRAcHvYbifSBlbAS2LWbFau1rafexHSq01B45iT24BvQNoSwR XmNtGKNeqg4fJp62Ye3g+GBqH1tiRFOQ19xXeTNgrDLZYX/Y8Koe6WVZdIkorywA6G K3T2vGL7udT0MP3qDz9SzO5EHLi/A1G2qDjBsevM=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.848
X-Spam-Level:
X-Spam-Status: No, score=-1.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1grFERuljRNR for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 12:21:07 -0700 (PDT)
Received: from mail-lj1-x22d.google.com (mail-lj1-x22d.google.com [IPv6:2a00:1450:4864:20::22d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 39F3B1342393D for <tls@ietf.org>; Wed, 2 Sep 2026 12:21:07 -0700 (PDT)
Received: by mail-lj1-x22d.google.com with SMTP id 38308e7fff4ca-39c9a3acd40so11264461fa.3 for <tls@ietf.org>; Wed, 02 Sep 2026 12:21:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1788376866; cv=none; d=google.com; s=arc-20260327; b=Y3dc/S+X5S/cXY0M5vKYjTFDncbjXHIS21G70S8+Z931590Yts/rhwwPV/lP5rhU7P HngI+fEjlGSdLb4XwjnPrTe4bYXtVeN4yO1rOFFOJdyPCisC9/JDCgYkS/Hyg1kzN2uw Qz8JzQCRQ7AxyhbhKJk5xz+2IhZH1+nwqg3WUsF2mF+YIoaCCpsjXFY/Qtbn2S4jxn3V DTOHbR70QnBTE7N6yQ8ZrlzIRnBDxCS5psT8nkzzeflfXeTFWuHxB/rRdOetmyVAtV5N h9LPNvdmOo/xlItOJpk/TBszl12QxBy9cTJCettmbbUtJhTx1XpKcnmx5i1jI/QsjY+s rTZA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=Ayxt/WwpUxM3A2M9QHm1vWamJENRNh85mi+vPofMwkk=; fh=ulnogXdqNWCTuYG8vCbzn9wTsUdIW/3+JyDmz4zv2Uo=; b=WlHRDU1DXQ5OAB3m+TS9uMLI/WCauvqBsbR4DH2nX/jsR1VQF1Qd78U2LhvnFrQHw7 dItecsdZCLc8D81zny+xWfIiUQOMzxnWfzxriSV7o8nsDH5W8bVTejpN/yV6b2zi7ucS QGj40ONRR0XjeekajpOjsTyK7Gxc//oB0unnY14mSaCHseQ2+pViAQTVK1B+PMY1lzdZ CoVBD2s5Mdl2F0ELC77EZ6KS0SrXvEUtlsNiQYMNkDTaS0QxY+Xsn5EFmXoFFq9R+eYU PEbXS2cQyvDHQijpyieiwltKPLYsrDn44EZpi/QSKqE5g/QFiVGceFEGJ/+jzj9Wdtpc 4+0A==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788376866; x=1788981666; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Ayxt/WwpUxM3A2M9QHm1vWamJENRNh85mi+vPofMwkk=; b=TrNp0LW7CpYNnnO3EGaanVQrqglBlCua/SBbbwn120ULi3sfs68gDrfB9IfW1+UJgZ TkBz8bFjqx02un+Y4ZaQigFBcyZOchjnq1bMpxgacUtmxKczdILjX23rOsDxAawoyMC0 59es7dQEjMevzUsPbbxr1HX55lzWzVBy3YNiIy8FVOrNAqF43xJSljnCwcyBB7OCiaSW Q0lPxXwWzCj04zpdaBIg1WKflapJX7ibmD2WTv10dq7koFNk0KlIAr3q02QTY1v5pJJc 5F7y+q+qxB2Es4Zv+MhxvxV5X15IwKd1qCLwFkSoJM+vF+E32NnlODuiZ7mQzxQZ2B39 l5uA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788376866; x=1788981666; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=Ayxt/WwpUxM3A2M9QHm1vWamJENRNh85mi+vPofMwkk=; b=ScZjYozsljDLWLcRUsjlJFlDAK++kBnY2c8ibSzJ8pj1l/u58p/5Fv4/ayChbOl/UA Nk8NrhjgEoNFbSug02UWG5GNfE5xXFichY/u/cwVb/CUqrhgKJmgALjbq5FUk2NK30dL dvaBhLb9KVQriyxavVOaG1vVK4pbNOqMmGfp2nSV0J9Jb4S3cD1GV+MZVGAdkTDb9jQ3 zA3sz6H83NOa/xQ2HMtlEt1UaA6Ai07GiGO0mq7rs0pqsIJY+NVdet0gvmVq9gH4+Xxe dOB6OQzK2vLw5l+NsQW+YgSnaEZrFY7ckfuR4VMXLKemQdV0M5XA7tBwoUyCW1smnHv9 h+Lw==
X-Forwarded-Encrypted: i=1; AKwUvBy2Oeyx4rTgmxiXWdjDhkfsly82G93RUVNUjLQBWqCGeRq/eTOP5s/9Y0NExebeSAJKU24=@ietf.org
X-Gm-Message-State: AFuF++kvieSWpn0F1XzoYIfWQ7fZYBuQxdMuAlsmlWsbMAdzL/HP/778 Rxi0xETWo7n1jiHTWiMxX8/+/fUTfGUvt8r9gMsKzORMGQU4xt+g3PQx9QsrqUG/NbFdkWK/3Yj v53OgZb+xRdpr5x+8NUaAloHQeA9Fiag=
X-Gm-Gg: AYBFou3ekI58XpzD7P5v0McZsn/ycWHlcncG+NAb/DvCBIliBOCsLAqPJMn1WJPH9ok KC+lyvE76/fvjPdtYkqNpzMiOavc/xqBDSEJR00fq9RIabv1vhNFJElVbN8XdWGK/tbBjMxHJj6 lN4Ogc5EkHj3rJdArNUSQw1OXUBy3bhTxTsZNpUX2qmPhVhEBmtiL4pTrFai20gWI0bJxHLLl+F Ny4OiCb3UvkrfxMx2N7zx/Feg7nL18OBl17wCNPxyKIcT96MSsN4uP91yilhpNAdxOR5ajBZO5M nxjstIvTBPc5Rv/558WX3p4juV/3+O9oZDyHBiJi9RjAs97u9NsRt/uV5Jh4rC2xmnmAcd0ccLs Umb0=
X-Received: by 2002:a05:6512:3d89:b0:5b6:422:a61b with SMTP id 2adb3069b0e04-5b6087b9274mr2380266e87.27.1788376865689; Wed, 02 Sep 2026 12:21:05 -0700 (PDT)
MIME-Version: 1.0
References: <178824279669.342843.9093761933892609989@dt-datatracker-6669c7b496-4m6kd>
In-Reply-To: <178824279669.342843.9093761933892609989@dt-datatracker-6669c7b496-4m6kd>
From: Deirdre Connolly <durumcrustulum@gmail.com>
Date: Wed, 02 Sep 2026 15:20:28 -0400
X-Gm-Features: AcwNN1WayBwe1hZlVeqG6JJ9qpO6MBjKVwNRP7mqgPgaFoQ5s4ucVUaXKqNKAEU
Message-ID: <CAFR824wVpLcTHWnqK9dB2AZr=t8_gzTVYFcvw_iZKvEi2FYS9g@mail.gmail.com>
To: Ketan Talaulikar <ketant.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000cdd4fc065a84efab"
Message-ID-Hash: 5BTRN5YDUAGFOB5NRN6SSDWD24L5A2WC
X-Message-ID-Hash: 5BTRN5YDUAGFOB5NRN6SSDWD24L5A2WC
X-MailFrom: neried7@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: The IESG <iesg@ietf.org>, draft-ietf-tls-mlkem@ietf.org, tls-chairs@ietf.org, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Ketan Talaulikar's No Objection on draft-ietf-tls-mlkem-09: (with COMMENT)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/LOerdkZshMvVIGbwM1mZ7UpSPa4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Thank you for the review, I think all of these comments are now addressed in version 10: https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/10/ On Tue, Sep 1, 2026 at 2:06 AM Ketan Talaulikar via Datatracker < noreply@ietf.org> wrote: > Ketan Talaulikar has entered the following ballot position for > draft-ietf-tls-mlkem-09: No Objection > > When responding, please keep the subject line intact and reply to all > email addresses included in the To and CC lines. (Feel free to cut this > introductory paragraph, however.) > > > Please refer to > https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ > for more information about how to handle DISCUSS and COMMENT positions. > > > The document, along with other ballot positions, can be found here: > https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/ > > > > ---------------------------------------------------------------------- > COMMENT: > ---------------------------------------------------------------------- > > Thanks to the authors and the WG for their work on this document. > > Please find below some comments on this document inline in the idnits > output > of v09. Look out for the <EoRv09> tag at the end to ensure you are seeing > the > full review. > > 132 The KEMs are defined as NamedGroups, sent in the > supported_groups > 133 extension. Section 4.3.7 of [RFC9846] > > <nit> The second sentence is a fragment. Perhaps: > > The KEMs are defined as NamedGroups and sent in the supported_groups > extension > defined in Section 4.3.7 of [RFC9846]. > > 201 This document defines standalone ML-KEM key establishment for > TLS > 202 1.3. Use of KEMs for key agreement in TLS 1.3 has been > analyzed in > 203 multiple settings and security models [DOWLING] [KEMTLS] [HV22] > 204 [CHSW22] [CZCJWH25] [ZJZ24]; ML-KEM's IND-CCA security exceeds > the > 205 requirements for ephemeral key establishment [GHS25] [RFC9846]. > 206 Multiple formal analyses, including pen-and-paper computational > 207 proofs and machine-checked symbolic analysis using ProVerif > 208 [KOBEISSI26], demonstrate that replacing Diffie-Hellman with an > IND- > 209 CCA-secure KEM preserves the security properties of the TLS > > <nit> Please expand IND-CCA at first use. > > 210 handshake. Formal analysis has also shown that hybrid key > 211 establishment (e.g., [HYBRID], [ECDHE-MLKEM]) provides > compositional > 212 security: the exchange remains secure as long as at least one > of the > 213 component algorithms is unbroken [BJ24] [CPWB25]. > > <nit> Both cited Internet-Drafts have now been published. Please update > [HYBRID] to RFC 9954 and [ECDHE-MLKEM] to RFC 10024. > > 233 The disclosure of the output(s) of an insecure random number > 234 generator (RNG) when used in TLS and other protocols can be > used in > 235 an attack to compromise the state of the insecure RNG itself as > 236 described in [DUALEC-TLS]. The encapsulation randomness in > ML-KEM is > 237 an additional place where raw RNG output may be disclosed, > therefore > 238 it is important to follow the RNG guidance in [FIPS203] and > 239 [RFC9846]. Implementers can choose to implement mechanisms from > > <nit> The citation above uses [DUALEC-TLS], while the reference entry is > defined as [DUALECTLS]. Please use one reference key consistently. > > 244 This document requests/registers three new entries to the TLS > Named > 245 Group (or Supported Group) registry, according to the > procedures in > 246 Section 6 of [RFC9847]. > 248 > +======+=============+=======+=============+=========+=============+ > 249 |Value | Description |DTLS-OK| Recommended |Reference| Comment > | > 250 > +======+=============+=======+=============+=========+=============+ > 251 |0x0200| MLKEM512 |Y | N |This | FIPS > 203 | > 252 | | | | |document.| version > of | > 253 | | | | | | > ML-KEM-512 | > 254 > +------+-------------+-------+-------------+---------+-------------+ > 255 |0x0201| MLKEM768 |Y | N |This | FIPS > 203 | > 256 | | | | |document.| version > of | > 257 | | | | | | > ML-KEM-768 | > 258 > +------+-------------+-------+-------------+---------+-------------+ > 259 |0x0202| MLKEM1024 |Y | N |This | FIPS > 203 | > 260 | | | | |document.| version > of | > 261 | | | | | | > ML-KEM-1024 | > 262 > +------+-------------+-------+-------------+---------+-------------+ > > <major> These entries are already registered in the TLS Supported Groups > registry. This same issue has come up in the IANA review, which confirms > that > the entries already exist and that the remaining action is to update their > Reference fields. > > Please replace the request to register new entries with an instruction to > update the Reference fields of the existing entries, and use the registry's > exact name, TLS Supported Groups. The registry presents these values as > decimal 512, 513, and 514; please use that presentation or show decimal and > hexadecimal together. > > 398 Thanks to Douglas Stebila for consultation on the > draft-ietf-tls- > 399 hybrid-design design, and to Scott Fluhrer, Eric Rescorla, John > Preuß > 400 Mattsson, Martin Thomson, and Rebecca Guthrie for reviews. > > <nit> There is a duplicated use of design here. Perhaps: > > "design of RFC 9954" > > <EoRv09> > > > >
- [TLS] Ketan Talaulikar's No Objection on draft-ie… Ketan Talaulikar via Datatracker
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Deirdre Connolly
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Ketan Talaulikar