[TLS] Re: Ketan Talaulikar's No Objection on draft-ietf-tls-mlkem-09: (with COMMENT)

Deirdre Connolly <durumcrustulum@gmail.com> Wed, 02 September 2026 19:21 UTC

Return-Path: <neried7@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 2486F1342395C for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 12:21:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788376869; bh=42I3jBEMLCI4LHegvg8NWi5s6/WGYKJl2djN6xjumwM=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=wDISP/anYEA+qKZulRAcHvYbifSBlbAS2LWbFau1rafexHSq01B45iT24BvQNoSwR XmNtGKNeqg4fJp62Ye3g+GBqH1tiRFOQ19xXeTNgrDLZYX/Y8Koe6WVZdIkorywA6G K3T2vGL7udT0MP3qDz9SzO5EHLi/A1G2qDjBsevM=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.848
X-Spam-Level:
X-Spam-Status: No, score=-1.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1grFERuljRNR for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 12:21:07 -0700 (PDT)
Received: from mail-lj1-x22d.google.com (mail-lj1-x22d.google.com [IPv6:2a00:1450:4864:20::22d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 39F3B1342393D for <tls@ietf.org>; Wed, 2 Sep 2026 12:21:07 -0700 (PDT)
Received: by mail-lj1-x22d.google.com with SMTP id 38308e7fff4ca-39c9a3acd40so11264461fa.3 for <tls@ietf.org>; Wed, 02 Sep 2026 12:21:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1788376866; cv=none; d=google.com; s=arc-20260327; b=Y3dc/S+X5S/cXY0M5vKYjTFDncbjXHIS21G70S8+Z931590Yts/rhwwPV/lP5rhU7P HngI+fEjlGSdLb4XwjnPrTe4bYXtVeN4yO1rOFFOJdyPCisC9/JDCgYkS/Hyg1kzN2uw Qz8JzQCRQ7AxyhbhKJk5xz+2IhZH1+nwqg3WUsF2mF+YIoaCCpsjXFY/Qtbn2S4jxn3V DTOHbR70QnBTE7N6yQ8ZrlzIRnBDxCS5psT8nkzzeflfXeTFWuHxB/rRdOetmyVAtV5N h9LPNvdmOo/xlItOJpk/TBszl12QxBy9cTJCettmbbUtJhTx1XpKcnmx5i1jI/QsjY+s rTZA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=Ayxt/WwpUxM3A2M9QHm1vWamJENRNh85mi+vPofMwkk=; fh=ulnogXdqNWCTuYG8vCbzn9wTsUdIW/3+JyDmz4zv2Uo=; b=WlHRDU1DXQ5OAB3m+TS9uMLI/WCauvqBsbR4DH2nX/jsR1VQF1Qd78U2LhvnFrQHw7 dItecsdZCLc8D81zny+xWfIiUQOMzxnWfzxriSV7o8nsDH5W8bVTejpN/yV6b2zi7ucS QGj40ONRR0XjeekajpOjsTyK7Gxc//oB0unnY14mSaCHseQ2+pViAQTVK1B+PMY1lzdZ CoVBD2s5Mdl2F0ELC77EZ6KS0SrXvEUtlsNiQYMNkDTaS0QxY+Xsn5EFmXoFFq9R+eYU PEbXS2cQyvDHQijpyieiwltKPLYsrDn44EZpi/QSKqE5g/QFiVGceFEGJ/+jzj9Wdtpc 4+0A==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788376866; x=1788981666; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Ayxt/WwpUxM3A2M9QHm1vWamJENRNh85mi+vPofMwkk=; b=TrNp0LW7CpYNnnO3EGaanVQrqglBlCua/SBbbwn120ULi3sfs68gDrfB9IfW1+UJgZ TkBz8bFjqx02un+Y4ZaQigFBcyZOchjnq1bMpxgacUtmxKczdILjX23rOsDxAawoyMC0 59es7dQEjMevzUsPbbxr1HX55lzWzVBy3YNiIy8FVOrNAqF43xJSljnCwcyBB7OCiaSW Q0lPxXwWzCj04zpdaBIg1WKflapJX7ibmD2WTv10dq7koFNk0KlIAr3q02QTY1v5pJJc 5F7y+q+qxB2Es4Zv+MhxvxV5X15IwKd1qCLwFkSoJM+vF+E32NnlODuiZ7mQzxQZ2B39 l5uA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788376866; x=1788981666; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=Ayxt/WwpUxM3A2M9QHm1vWamJENRNh85mi+vPofMwkk=; b=ScZjYozsljDLWLcRUsjlJFlDAK++kBnY2c8ibSzJ8pj1l/u58p/5Fv4/ayChbOl/UA Nk8NrhjgEoNFbSug02UWG5GNfE5xXFichY/u/cwVb/CUqrhgKJmgALjbq5FUk2NK30dL dvaBhLb9KVQriyxavVOaG1vVK4pbNOqMmGfp2nSV0J9Jb4S3cD1GV+MZVGAdkTDb9jQ3 zA3sz6H83NOa/xQ2HMtlEt1UaA6Ai07GiGO0mq7rs0pqsIJY+NVdet0gvmVq9gH4+Xxe dOB6OQzK2vLw5l+NsQW+YgSnaEZrFY7ckfuR4VMXLKemQdV0M5XA7tBwoUyCW1smnHv9 h+Lw==
X-Forwarded-Encrypted: i=1; AKwUvBy2Oeyx4rTgmxiXWdjDhkfsly82G93RUVNUjLQBWqCGeRq/eTOP5s/9Y0NExebeSAJKU24=@ietf.org
X-Gm-Message-State: AFuF++kvieSWpn0F1XzoYIfWQ7fZYBuQxdMuAlsmlWsbMAdzL/HP/778 Rxi0xETWo7n1jiHTWiMxX8/+/fUTfGUvt8r9gMsKzORMGQU4xt+g3PQx9QsrqUG/NbFdkWK/3Yj v53OgZb+xRdpr5x+8NUaAloHQeA9Fiag=
X-Gm-Gg: AYBFou3ekI58XpzD7P5v0McZsn/ycWHlcncG+NAb/DvCBIliBOCsLAqPJMn1WJPH9ok KC+lyvE76/fvjPdtYkqNpzMiOavc/xqBDSEJR00fq9RIabv1vhNFJElVbN8XdWGK/tbBjMxHJj6 lN4Ogc5EkHj3rJdArNUSQw1OXUBy3bhTxTsZNpUX2qmPhVhEBmtiL4pTrFai20gWI0bJxHLLl+F Ny4OiCb3UvkrfxMx2N7zx/Feg7nL18OBl17wCNPxyKIcT96MSsN4uP91yilhpNAdxOR5ajBZO5M nxjstIvTBPc5Rv/558WX3p4juV/3+O9oZDyHBiJi9RjAs97u9NsRt/uV5Jh4rC2xmnmAcd0ccLs Umb0=
X-Received: by 2002:a05:6512:3d89:b0:5b6:422:a61b with SMTP id 2adb3069b0e04-5b6087b9274mr2380266e87.27.1788376865689; Wed, 02 Sep 2026 12:21:05 -0700 (PDT)
MIME-Version: 1.0
References: <178824279669.342843.9093761933892609989@dt-datatracker-6669c7b496-4m6kd>
In-Reply-To: <178824279669.342843.9093761933892609989@dt-datatracker-6669c7b496-4m6kd>
From: Deirdre Connolly <durumcrustulum@gmail.com>
Date: Wed, 02 Sep 2026 15:20:28 -0400
X-Gm-Features: AcwNN1WayBwe1hZlVeqG6JJ9qpO6MBjKVwNRP7mqgPgaFoQ5s4ucVUaXKqNKAEU
Message-ID: <CAFR824wVpLcTHWnqK9dB2AZr=t8_gzTVYFcvw_iZKvEi2FYS9g@mail.gmail.com>
To: Ketan Talaulikar <ketant.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000cdd4fc065a84efab"
Message-ID-Hash: 5BTRN5YDUAGFOB5NRN6SSDWD24L5A2WC
X-Message-ID-Hash: 5BTRN5YDUAGFOB5NRN6SSDWD24L5A2WC
X-MailFrom: neried7@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: The IESG <iesg@ietf.org>, draft-ietf-tls-mlkem@ietf.org, tls-chairs@ietf.org, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Ketan Talaulikar's No Objection on draft-ietf-tls-mlkem-09: (with COMMENT)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/LOerdkZshMvVIGbwM1mZ7UpSPa4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Thank you for the review, I think all of these comments are now addressed
in version 10: https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/10/

On Tue, Sep 1, 2026 at 2:06 AM Ketan Talaulikar via Datatracker <
noreply@ietf.org> wrote:

> Ketan Talaulikar has entered the following ballot position for
> draft-ietf-tls-mlkem-09: No Objection
>
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut this
> introductory paragraph, however.)
>
>
> Please refer to
> https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
> for more information about how to handle DISCUSS and COMMENT positions.
>
>
> The document, along with other ballot positions, can be found here:
> https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/
>
>
>
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
>
> Thanks to the authors and the WG for their work on this document.
>
> Please find below some comments on this document inline in the idnits
> output
> of v09. Look out for the <EoRv09> tag at the end to ensure you are seeing
> the
> full review.
>
> 132        The KEMs are defined as NamedGroups, sent in the
> supported_groups
> 133        extension.  Section 4.3.7 of [RFC9846]
>
> <nit> The second sentence is a fragment. Perhaps:
>
> The KEMs are defined as NamedGroups and sent in the supported_groups
> extension
> defined in Section 4.3.7 of [RFC9846].
>
> 201        This document defines standalone ML-KEM key establishment for
> TLS
> 202        1.3.  Use of KEMs for key agreement in TLS 1.3 has been
> analyzed in
> 203        multiple settings and security models [DOWLING] [KEMTLS] [HV22]
> 204        [CHSW22] [CZCJWH25] [ZJZ24]; ML-KEM's IND-CCA security exceeds
> the
> 205        requirements for ephemeral key establishment [GHS25] [RFC9846].
> 206        Multiple formal analyses, including pen-and-paper computational
> 207        proofs and machine-checked symbolic analysis using ProVerif
> 208        [KOBEISSI26], demonstrate that replacing Diffie-Hellman with an
> IND-
> 209        CCA-secure KEM preserves the security properties of the TLS
>
> <nit> Please expand IND-CCA at first use.
>
> 210        handshake.  Formal analysis has also shown that hybrid key
> 211        establishment (e.g., [HYBRID], [ECDHE-MLKEM]) provides
> compositional
> 212        security: the exchange remains secure as long as at least one
> of the
> 213        component algorithms is unbroken [BJ24] [CPWB25].
>
> <nit> Both cited Internet-Drafts have now been published. Please update
> [HYBRID] to RFC 9954 and [ECDHE-MLKEM] to RFC 10024.
>
> 233        The disclosure of the output(s) of an insecure random number
> 234        generator (RNG) when used in TLS and other protocols can be
> used in
> 235        an attack to compromise the state of the insecure RNG itself as
> 236        described in [DUALEC-TLS].  The encapsulation randomness in
> ML-KEM is
> 237        an additional place where raw RNG output may be disclosed,
> therefore
> 238        it is important to follow the RNG guidance in [FIPS203] and
> 239        [RFC9846].  Implementers can choose to implement mechanisms from
>
> <nit> The citation above uses [DUALEC-TLS], while the reference entry is
> defined as [DUALECTLS]. Please use one reference key consistently.
>
> 244        This document requests/registers three new entries to the TLS
> Named
> 245        Group (or Supported Group) registry, according to the
> procedures in
> 246        Section 6 of [RFC9847].
> 248
> +======+=============+=======+=============+=========+=============+
> 249        |Value | Description |DTLS-OK| Recommended |Reference| Comment
>    |
> 250
> +======+=============+=======+=============+=========+=============+
> 251        |0x0200| MLKEM512    |Y      | N           |This     | FIPS
> 203    |
> 252        |      |             |       |             |document.| version
> of  |
> 253        |      |             |       |             |         |
> ML-KEM-512  |
> 254
> +------+-------------+-------+-------------+---------+-------------+
> 255        |0x0201| MLKEM768    |Y      | N           |This     | FIPS
> 203    |
> 256        |      |             |       |             |document.| version
> of  |
> 257        |      |             |       |             |         |
> ML-KEM-768  |
> 258
> +------+-------------+-------+-------------+---------+-------------+
> 259        |0x0202| MLKEM1024   |Y      | N           |This     | FIPS
> 203    |
> 260        |      |             |       |             |document.| version
> of  |
> 261        |      |             |       |             |         |
> ML-KEM-1024 |
> 262
> +------+-------------+-------+-------------+---------+-------------+
>
> <major> These entries are already registered in the TLS Supported Groups
> registry. This same issue has come up in the IANA review, which confirms
> that
> the entries already exist and that the remaining action is to update their
> Reference fields.
>
> Please replace the request to register new entries with an instruction to
> update the Reference fields of the existing entries, and use the registry's
> exact name, TLS Supported Groups. The registry presents these values as
> decimal 512, 513, and 514; please use that presentation or show decimal and
> hexadecimal together.
>
> 398        Thanks to Douglas Stebila for consultation on the
> draft-ietf-tls-
> 399        hybrid-design design, and to Scott Fluhrer, Eric Rescorla, John
> Preuß
> 400        Mattsson, Martin Thomson, and Rebecca Guthrie for reviews.
>
> <nit> There is a duplicated use of design here. Perhaps:
>
> "design of RFC 9954"
>
> <EoRv09>
>
>
>
>