[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Yaroslav Rosomakho <yrosomakho@zscaler.com> Thu, 25 June 2026 09:16 UTC

Return-Path: <yrosomakho@zscaler.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 71C351071F5B7 for <tls@mail2.ietf.org>; Thu, 25 Jun 2026 02:16:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782378975; bh=Xyk2MIA3OYEqLeHKrgooJFlZjk67FQq2rgzDWJaSaDk=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=jBUgEizuhVDPOkVNPQlbNfbtDeP0BgFZJXeHonkRfE17fzYcYwiMSn5DeyWFHcCaT 9Oc/F5h/KWugZ9XUl5bCr2cn6k9PAdsW8NCfn84HFYr9s4TQk/xfPtD9ZjXP3+TcvG k9LY8kCLeysKxvbMJg2OfKmQxQhS5Eyqiam//jwg=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=zscaler.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NRSHLdVziFFa for <tls@mail2.ietf.org>; Thu, 25 Jun 2026 02:16:12 -0700 (PDT)
Received: from mail-oo1-xc35.google.com (mail-oo1-xc35.google.com [IPv6:2607:f8b0:4864:20::c35]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 3A56B1071F508 for <tls@ietf.org>; Thu, 25 Jun 2026 02:15:31 -0700 (PDT)
Received: by mail-oo1-xc35.google.com with SMTP id 006d021491bc7-6a0a38a013eso669166eaf.0 for <tls@ietf.org>; Thu, 25 Jun 2026 02:15:31 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1782378923; cv=none; d=google.com; s=arc-20260327; b=Aba1nFxci58ZUnKel1n8x90m8TbPhavL5zQ0Ib8Te0s1tzFAr1RkX277T4JDWOwpId RUZH+k81VRiVyOWfUy0f1lM5bLfb6gdvYcPeZOJEOeCBRvKEbFuJZGfE+SZj1B09Wlwy +/gEAJpfZKTfXhnmUHJnSyGIoOY3zBKI3C+XNgkWg4zBeV5Y5eii2Er1+f+VCW4cbKU2 lWZn9b69y6fk03NTnYFPsybUoEIB3ksu1ZD5T9WOjg0inTiqFLbzpuDKIYSiMd7pE2GX lBDS364rDoml7OLvSx1IsLJLIpwaDk73XLu+h94ksQF0w3M0K8wHq3TC93tX3F0cXbYq uvYw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=JwGjfQGdMHFA7foaooLgoeRVMJg9qJBhnNLv2eNdrWo=; fh=fCp5LYkNvoZ+7l/2nK4lIrv5lv9Tu5dhp7tOjCq2Y1Y=; b=RrxQM/TmGgwwws8YvLxCC6PeOYgCnAKwifXdwdH+6CY45OKlWuHhWrlacCxo/I801u mr+fRpF6iEoJogCRzJB5/wLILqYU2vueFjRUq2s5RGChY5y1mO3YUUEZRgWaA43HcF7d StoHyS2TkWJy43lyXYORdD0QUXGUn1Uo2W0JMkMaEx712uMgyDfi67KASBbhH024wzHw JfP9XvbDQNdvEE7KS5XwxOLaekIF3hiE2wKG08yxLUYEkooqBSLnNSOUGXCZkwsaRF9E Uiy+Ec4NntQ5FYMEBTgvbCfJYDrll9O2IJzwKIgda33BSyyHiSCbY7WwEv9S9s0q5CuU ThLQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zscaler.com; s=google; t=1782378923; x=1782983723; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=JwGjfQGdMHFA7foaooLgoeRVMJg9qJBhnNLv2eNdrWo=; b=kusnpLhGTV0FFwozwHSiFimqXcFc36JL3i5OPzBDfF1PAB621WRY2wjUFDYbrGed2N Un5PzWT+5iK7iDLWKMPkgmMvq5epRewG0BMaHJMP3qmQu1T61Nxs5DhgCui4jwNGL63Y Fu2/augEJpXHOdTcuCXd9aAQgeXcs3aEhCeFQ=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782378923; x=1782983723; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=JwGjfQGdMHFA7foaooLgoeRVMJg9qJBhnNLv2eNdrWo=; b=mpCRmT5jQNZq/wE30H1sjXXUFf3WQ6HHOhhyRtleYvyGBwxSLxDF8pCBQHyCDppUPZ 56vZGmXZTcXmL21/Fo2DI+V8vk/2G01vDxPi8tYc+8Wp+6zHQ6BxFdycimGRgKgD9qwH Cg3eas07qZI7sOs2/YjN5EcVzPvoab9suwkE00UZpa7bAsjaiP2PxVigF+FjKYguAb9b OiCXfeU+snviuCiTEMxCqB1fBJWjZXL95HIjLK493YiD1a/8gfzgyYnIK6KT0+TM3OZZ m4T5nW15/GtF+yqjHVn0JeG7BMn7aFdVb75JdhsRJvDaHYnhHr5xFc4KBxwm3SqcgwV6 OUvA==
X-Forwarded-Encrypted: i=1; AFNElJ+/VtNQL6sX9AaKNVEgV+a635WK+oCikOCDOo83+4242vuxy+5WtXwWQd/xSAw+SDrV4S8=@ietf.org
X-Gm-Message-State: AOJu0Yzs3BFLOclMegAllTb8kD7nHDCwKKN/EG6VRhSlJbAF5gwenmgR NUXyqwfLFSUPX4pp5RNh63/W9lJPHkcKzEohgUvHE2PI5wZDPmIJj5C1rZzuH045oJ3cm+uHr4+ wBqijRUIvUiaHp7mDtzobB37Y9fP3p97Tt91Ms2zcvw0mM/77UGCPh4xX3AvZIaZsgqOvGJNtJc QGIuj83Z7FrK4=
X-Gm-Gg: AfdE7ckcRqlNntPl3gtTAotbXvVInEAX9gi8HafP8Ql7M8fgrEoQWrMee+6Ic7cdeyS e8fqvfAGZulXsT3DtvwXlNZUDzezPqjwcVTrJk8/WVxbS34Ad2hkVEuA38zqsVr9GaQir23tYKZ LqEkeX1rzjm6ZSg66iimj/54GonVPtAz/D00My7oW7ycnRh+5Kcwpe581Ivj6D62XMZ7n5Eh/ax Ejet4ute90W1FRCXZouqBsagcz7H49b+aZ/9PMRbBSV81Bf0cs1OR0wr+kOb/AJpmea3Cp6nWKn Kf109TYqImgksLFVaiTnPlvg78ROZuM90wgiJvqGJvqiWMxTkGHiNQ==
X-Received: by 2002:a05:6820:1688:b0:69d:eec5:20b1 with SMTP id 006d021491bc7-6a13426bac1mr1169189eaf.9.1782378923455; Thu, 25 Jun 2026 02:15:23 -0700 (PDT)
MIME-Version: 1.0
References: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg>
In-Reply-To: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg>
From: Yaroslav Rosomakho <yrosomakho@zscaler.com>
Date: Thu, 25 Jun 2026 10:15:11 +0100
X-Gm-Features: AVVi8Cc9XENIROular3QNanMEQ7wxLfGsdeVwFSK8Tf-LD7HSpRO9gpurU1BsVU
Message-ID: <CAMtubr17n=5DyB9PaD2dakxa=5xGUnJe7WUNfrcx5CrgHFLMqA@mail.gmail.com>
To: Joseph Salowey <joe@salowey.net>
Content-Type: multipart/alternative; boundary="00000000000097668d0655106e00"
Message-ID-Hash: KND4STO5QZGADCZXOOQEFAA7DYVBS236
X-Message-ID-Hash: KND4STO5QZGADCZXOOQEFAA7DYVBS236
X-MailFrom: yrosomakho@zscaler.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-tls-mlkem@ietf.org, TLS Chairs <tls-chairs@ietf.org>, "<tls@ietf.org>" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/MVIhOhFC51rBIXOH9Ut-e2Ts-5s>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Yes, please publish this document.

-yaroslav

On Wed, Jun 24, 2026 at 4:01 PM Joseph Salowey via Datatracker <
noreply@ietf.org> wrote:

> This message initiates a new Working Group Last Call for
> draft-ietf-tls-mlkem[1], which defines standalone ML-KEM key establishment
> for TLS 1.3. The main question before the working group is: "Should the
> working group publish a document specifying stand alone ML-KEM?". If there
> is rough consensus then we will push to refine and publish the document;
> otherwise, we will stop discussing the draft and not progress it. Please
> respond to this call indicating whether you support publishing a document
> specifying a stand alone ML-KEM. Please refrain from further discussion on
> this topic as most arguments have been discussed multiple times.
>
> Why are we holding this consensus call now?
>
> Significant developments have occurred both within this document and in
> the broader TLS ecosystem to address the concerns raised in the last WGLC.
> Therefore, the third consensus call is warranted. We ask the working group
> to consider document publication in light of these recent changes:
>
> - Promotion of Hybrids in draft-ietf-tls-ecdhe-mlkem: Following a separate
> consensus call, the WG agreed to promote the X25519MLKEM768 hybrid group to
> Recommended: Y in the IANA registry. Consequently, the IANA registry will
> reflect a clear community preference for a hybrid because Recommended: Y
> clearly indicates this while the standalone ML-KEM groups defined in this
> draft remain Recommended: N. The updated security considerations in [1]
> reference the IANA registry to emphasize this preference.
>
> - Key Share Reuse Prohibited in draft-ietf-tls-rfc8446bis: The WG recently
> reached consensus to explicitly prohibit key share reuse across connections
> in TLS 1.3. The new text changes the guidance from SHOULD NOT to a strict
> MUST NOT. This resolves the concerns regarding static key reuse and its
> associated privacy and forward-secrecy risks for ML-KEM.
>
> - Nadim updated the ProVerif model of TLS 1.3 to evaluate KEM and hybrid
> KEM groups in TLS 1.3. This supports other results which show that KEMs are
> secure when used in TLS 1.3 and that hybrid groups are secure even if one
> of the components is compromised.
>
> - Liaisons: We received liaison statements from multiple SDOs including
> O-RAN[2], IEEE 802.11[4] and from 3GPP[3]  expressing support for the
> publication of draft-ietf-tls-mlkem as an RFC as they rely on the IETF to
> provide a stable normative reference.
>
> Please note that a third-party IPR disclosure exists [5] against this
> document regarding patents related to the underlying ML-KEM algorithm. This
> IPR declaration has not changed since the last WGLC. As a reminder, per BCP
> 79, the IETF takes no stance on the validity of patent claims, and the
> working group may decide to proceed with a technology despite IPR
> disclosures if it decides that such use is warranted.
>
> Conduct Reminder: Given the heated nature of previous discussions on this
> topic, participants are strongly reminded to adhere to the IETF Code of
> Conduct (BCP 54) and the TLS WG's Mail List Procedures. Keep feedback
> professional, technical, and focused on the document's text.
>
> This working group last call will end on 2026-07-08.
>
> Joe and Sean
>
> [1] https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/
> [2] https://datatracker.ietf.org/liaison/2198/
> [3] https://datatracker.ietf.org/liaison/2151/
> [4] https://datatracker.ietf.org/liaison/2148/
> [5]
> https://datatracker.ietf.org/ipr/search/?submit=draft&id=draft-ietf-tls-mlkem
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>

-- 


This communication (including any attachments) is intended for the sole 
use of the intended recipient and may contain confidential, non-public, 
and/or privileged material. Use, distribution, or reproduction of this 
communication by unintended recipients is not authorized. If you received 
this communication in error, please immediately notify the sender and then 
delete all copies of this communication from your system.