[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

steve@tobtu.com Sun, 28 June 2026 22:42 UTC

Return-Path: <steve@tobtu.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id CA3921096DF49; Sun, 28 Jun 2026 15:42:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782686568; bh=Z0ZlPB8BHLHR8+0JNzstu+F7wTyN0jvk22QQNJLE49c=; h=Date:From:To:In-Reply-To:References:Subject; b=NbuUK142GBAwanfBN2d2JPeDVRz507h1+S79RBG7kfDlZ0N4UaUZEjSJUlquRplZB oAFiqKi+KlR9djM1xUwh8PpRax/VtfKz7CxQldEW7Gc1OyKvDvGehn4xK65NwGmHqy d63Lq5GKW0G7rzMAjPy/OE8NhPOfPz7lD5wbN5sE=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=tobtu.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WTfV8ZhAgWWG; Sun, 28 Jun 2026 15:42:48 -0700 (PDT)
Received: from mout.perfora.net (mout.perfora.net [74.208.4.196]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 11FE41096DE32; Sun, 28 Jun 2026 15:42:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tobtu.com; s=s1-ionos; t=1782686556; x=1783291356; i=steve@tobtu.com; bh=s8PZ7XbFFcW6zPreGeC0eDcNwXd/+E1tEFDJplMVXQE=; h=X-UI-Sender-Class:Date:From:To:Message-ID:In-Reply-To:References: Subject:MIME-Version:Content-Type:Content-Transfer-Encoding:cc: content-transfer-encoding:content-type:date:from:message-id: mime-version:reply-to:subject:to; b=GBPAC2pO0gBQZUvxT5qOnjPPN2Be/ozA78HratkshqIDMjuHCMsNidRi5Lx7XlXi Zgcl9rKUR3UmgTOyePs7dNeZpjkd4GliwFMbzMrcuQDMIZ2FUjg5W/D+0TldO2so6 YeQJb2FcNZDLBXvXopA1RlC2F1JaT0YsjzSRx197S3xCMjPliatzu1Ey1B2eSAGrJ nrzaDpk5kJ7ty28BTxTdh9goLGyLt9ZbPShfvVW/r/hs6jyJvSA+UzO4lgCYnW3lX lEJOIvpEc9IFuRxVwEuBGYgQlxbaeKfip6UchTdKUqtMKEghGu3i/Al6QtrHslop0 ahH/5Mipt24ZvG1hVA==
X-UI-Sender-Class: 55c96926-9e95-11ee-ae09-1f7a4046a0f6
Received: from client.hidden.invalid by mrelay.perfora.net (mreueus003 [172.19.143.1]) with ESMTPSA (Nemesis) id 0LiF41-1xQU751AAd-00kxmV; Mon, 29 Jun 2026 00:42:36 +0200
Date: Sun, 28 Jun 2026 17:42:36 -0500
From: steve@tobtu.com
To: Joseph Salowey <joe@salowey.net>, Joseph Salowey via Datatracker <noreply@ietf.org>, draft-ietf-tls-mlkem@ietf.org, tls-chairs@ietf.org, tls@ietf.org
Message-ID: <2074928449.469157.1782686556115@email.ionos.com>
In-Reply-To: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg>
References: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Priority: 3
Importance: Normal
X-Mailer: Open-Xchange Mailer v8.46.142
X-Originating-Client: open-xchange-appsuite
X-Provags-ID: V03:K1:bbPMU3sE9FBA04hYX+xlnqKyFKcow560hQaamQou+S530XYQDi9 jdH1nW//XO5g2XVww8aPhCH052OEyEJ5fJKKKf9CwrE+t7c49kC7BTaIbTrq1uKjM6ElG/N PMC1DtIfNINImIEYx/KphXRMUoJAR/20qLghGsfGGCVbHKzF0NNSY1Q3w01WtWniVZe1SzA Pu1NAOuso6Pc8BfxANyvQ==
UI-OutboundReport: notjunk:1;M01:P0:rV79a5mPIZU=;vMbbMQQqxFP9c493qICQT87SqmJ Gcm+vpS9vRWFyJM6BCewamfvdZiyAtWs2XjdJeoqqWuYGl64ZxJW/vkLxg5uNZ64SqaDUMRav V8u7UT4oDG8NMnSNyOGBGRzrwtu/VvoWXxxKfrBS6wJ/EUgiKApLPd53NDLhuWxz+ipnLRDby X5wL6lkt6Ks3QlT6pVzD6SnSjlpcoy4bvHObtk/Rke9QFxDKr0g8BHaQDicsmD+3ZdK58xUUi OvGQOVsb1IIfsflhnPa83DgjJjZ593V/3GVCHBwMgmorw0mmw0xLd8YWJ1fSYT0Y7HR/o5J8K AkF+nSc/AwZ2Hh6mEeIgJP4UY1ILjyordbaLZC1tto0cBSLTmRRqUoJKk7WxA8PYrOtns60DM 6Ix0J219spc5TQw0UigocEJeleFMp7XGdfZjFcnltZXWmtURfE6zFeSrxYB6f/xCPAPCxkBvl 6VRXmyQwBinl3QjfdZIHHAL1zGYsLKI2cf2rVtkvoOWaR2J+HXP6DD6vzrS380brB9C3aVBlF AVIz2UxI577xhXG5JfJHY4uAUT6XNhq4Uk+smlDndBb2iFD/izONZrdZbUbILQk5UkK+nl67L zCvGxE3R3Pa326XWQtDEUKmKjMcJBe9+Dgs1wsl/5BRIgubYvUfxfw8SR2ZHaVryJwz6aXFB5 8gE3qi8e62q0p2MtnCBW/w94OR8yyDeGuzHlS2oH3y7RDb27Gm5QSWx32EmNOV+WKLILFsifL Gmfsxu/Yx1sz2ebcmTWCBo9ciBLQhbm0Wiz9vQy8cSjHCJMYWWn0hx8f9g+T5hhcMmHwf6uPp y35Zw/5kjsKCr1iAIEz0S+oP1Vg0nArprS4B0PeFcs1c0jGV70PXpCX8diI+s32Qz1Cvhr9Hi eWXby7oOOLTCdfn9uSpauYGxr3IyBr0xv7pouou87Exozj2WdmsIicexv5YbA8+W4yzAVmLA0 cwQXgIsI+XNCSeBXPCzI6Z4pnqe6wZtwy1FaoL7wS4IL6qoJDa0BOgX/oQD6pLeELBTFAtR0r Q6jOygWr5b/A7FdWMLR27I8caH6Gxw/Oywk5ZQH2GrN9sp3gGJD8RnqLEaVNbPQB3bateyG0G J+xYF9Q8UrY1I2hc1e8BRDb2xfkROb6zF2Gc3TfnGhnjjcF10Pu7phKspT/W9ta0IWn67nELY f2CSFQ29uuOd2cR+Z9Fu1LrqWNuRI8l7D5FEaZulBN0clfEkiaztoYb6xWz612BjYt7IVhoBr wX/HUiyKML1o/1D5AQQbPZrJkg75QRJCTymKxJiLpYI0GzAw/Q3W3ang4NAka3QOalvbOKbiQ QYawgMgFZlrS62wZlOb6FtzZFup4MDJvWGvIqWTB5Uj+i2+vtGl88X/6YIHZOpW7hXYFD9tOm BCmLZWoEgA1EkOXasgC3IQ0CaHNRWFE25z7eoxcK93+bEmp4IMyvmgUPcG5JsGtHp/oE7snQx m67KfitgcBBd3nXx+iutnOBS09T3pf95kv0yZAc48vIfmTUjLCrLVAH9xOOwt7KHXNbYnJ9Z6 YgA2rZuKqYDieDa1yS9tQkoX0C4xC9verOS+yDospJo250gW+MnE0QzYTqW+yw6HqjR+UPjvX KIhnX0srJVU7nKheFHBhZ5Yq/1QaKeFhySNOfvXp/QrYLurEd2KYqLhAaK6oR+PMVTyor5kug GLfaXBQxAJ1xulZmVam0n9rDlMkSTVkk3obMP3AuQa7eMlN+6HzfHBl/sJeZM7CINj5hJUiCP J4Bfe0wJCJ3s782RpiEoMKvwqbVEXwegAZA4n0X7h1HKf7HWbmuCjqlPEgOGgCDDtTj6ddu0W n53Fhy/M+O5RJ5pjNaS6cGK1s7EP0gpHIQyBdVbXXGCo2ZTVNLLjN2fKW0oRcGL9dcil
Message-ID-Hash: A77QWBM7TNS7FJCFFV5GXSQIGEGJPNYA
X-Message-ID-Hash: A77QWBM7TNS7FJCFFV5GXSQIGEGJPNYA
X-MailFrom: steve@tobtu.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/NrCQPGN1LcZW_NGDUCtdd_sixM8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I support publishing this document. If these two typos are fixed:

The double "and" in the abstract:
"This memo defines ML-KEM-512, ML-KEM-768, and ML-KEM-1024 as NamedGroups and and registers..."

The extra comma in the security considerations:
"(e.g., [HYBRID], [ECDHE-MLKEM])" -> "(e.g. [HYBRID], [ECDHE-MLKEM])"


> On 06/24/2026 10:00 AM CDT Joseph Salowey via Datatracker <noreply@ietf.org> wrote:
> 
>  
> This message initiates a new Working Group Last Call for draft-ietf-tls-mlkem[1], which defines standalone ML-KEM key establishment for TLS 1.3. The main question before the working group is: "Should the working group publish a document specifying stand alone ML-KEM?". If there is rough consensus then we will push to refine and publish the document; otherwise, we will stop discussing the draft and not progress it. Please respond to this call indicating whether you support publishing a document specifying a stand alone ML-KEM. Please refrain from further discussion on this topic as most arguments have been discussed multiple times.
> 
> Why are we holding this consensus call now?
> 
> Significant developments have occurred both within this document and in the broader TLS ecosystem to address the concerns raised in the last WGLC. Therefore, the third consensus call is warranted. We ask the working group to consider document publication in light of these recent changes:
> 
> - Promotion of Hybrids in draft-ietf-tls-ecdhe-mlkem: Following a separate consensus call, the WG agreed to promote the X25519MLKEM768 hybrid group to Recommended: Y in the IANA registry. Consequently, the IANA registry will reflect a clear community preference for a hybrid because Recommended: Y clearly indicates this while the standalone ML-KEM groups defined in this draft remain Recommended: N. The updated security considerations in [1] reference the IANA registry to emphasize this preference.
> 
> - Key Share Reuse Prohibited in draft-ietf-tls-rfc8446bis: The WG recently reached consensus to explicitly prohibit key share reuse across connections in TLS 1.3. The new text changes the guidance from SHOULD NOT to a strict MUST NOT. This resolves the concerns regarding static key reuse and its associated privacy and forward-secrecy risks for ML-KEM.
> 
> - Nadim updated the ProVerif model of TLS 1.3 to evaluate KEM and hybrid KEM groups in TLS 1.3. This supports other results which show that KEMs are secure when used in TLS 1.3 and that hybrid groups are secure even if one of the components is compromised.
> 
> - Liaisons: We received liaison statements from multiple SDOs including  O-RAN[2], IEEE 802.11[4] and from 3GPP[3]  expressing support for the publication of draft-ietf-tls-mlkem as an RFC as they rely on the IETF to provide a stable normative reference.
> 
> Please note that a third-party IPR disclosure exists [5] against this document regarding patents related to the underlying ML-KEM algorithm. This IPR declaration has not changed since the last WGLC. As a reminder, per BCP 79, the IETF takes no stance on the validity of patent claims, and the working group may decide to proceed with a technology despite IPR disclosures if it decides that such use is warranted.
> 
> Conduct Reminder: Given the heated nature of previous discussions on this topic, participants are strongly reminded to adhere to the IETF Code of Conduct (BCP 54) and the TLS WG's Mail List Procedures. Keep feedback professional, technical, and focused on the document's text.
> 
> This working group last call will end on 2026-07-08.
> 
> Joe and Sean
> 
> [1] https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/
> [2] https://datatracker.ietf.org/liaison/2198/
> [3] https://datatracker.ietf.org/liaison/2151/
> [4] https://datatracker.ietf.org/liaison/2148/
> [5] https://datatracker.ietf.org/ipr/search/?submit=draft&id=draft-ietf-tls-mlkem
> 
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org