[TLS] WG Adoption Call for ML-KEM Post-Quantum Key Agreement for TLS 1.3

Sean Turner <sean@sn3rd.com> Tue, 01 April 2025 12:58 UTC

Return-Path: <sean@sn3rd.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3B37115C592F for <tls@mail2.ietf.org>; Tue, 1 Apr 2025 05:58:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id opo3A-rt5RrI for <tls@mail2.ietf.org>; Tue, 1 Apr 2025 05:58:23 -0700 (PDT)
Received: from mail-qk1-x736.google.com (mail-qk1-x736.google.com [IPv6:2607:f8b0:4864:20::736]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id AB7E315C5921 for <tls@ietf.org>; Tue, 1 Apr 2025 05:58:23 -0700 (PDT)
Received: by mail-qk1-x736.google.com with SMTP id af79cd13be357-7c54a9d3fcaso499472085a.2 for <tls@ietf.org>; Tue, 01 Apr 2025 05:58:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; t=1743512303; x=1744117103; darn=ietf.org; h=to:date:message-id:subject:mime-version:content-transfer-encoding :from:from:to:cc:subject:date:message-id:reply-to; bh=LSpJ73V+Mva4DiqDvQRrle6EmpvBPlcXTs/EclsRx6M=; b=DItAWunr4GK5K317c5lKzez8/AkI3oJy7SqVR5QmjmdbuyR9M+0mhgu/32NlaGkvbl WrebIjX65rbr2yP3yG0DYw0xXAQYts/flcMd1HbU7Vcd0oNKYQxO9ZENg+yfnnq+VxTz Eaa1ZmU8coSWlgl1l5VQMEhMHvRC9YkeKWSic=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1743512303; x=1744117103; h=to:date:message-id:subject:mime-version:content-transfer-encoding :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=LSpJ73V+Mva4DiqDvQRrle6EmpvBPlcXTs/EclsRx6M=; b=tALUHHsp6rcftv12sn7qiTZNoviKlf29XaNdJj071Md8NSck+o38vC86lF88DVtNcz gDVP6V3bZqeAG3BRW0aTVxj15cZT5BfzMdpBLiZL89BE7LpysOStju2uPsn1wrhSJJw7 u2ffP3ItCyo2bY62eFMpz4n1eiwvtObJKiwcfEHj8lIKUrz/rDM+Fafq3cZ6C6C5WEIu P6wUnJ8KRCflWIRHMcIOUeubcXas4UJqrn75K/WmvLCAcVX64EwgEaxp98gxYO+QHz27 sNFCni050wDjNeYT4W550Ii6TST4GMrvTgV2Gk5L2LzhISyji3dDnNZn6+Hl8phR0qrO QEZA==
X-Gm-Message-State: AOJu0Yy3fZ0fN3fDPxG4bLAA9Be2XI0LAT7webqRq19OVNoVGSVgBgdZ 9OoQRwjfft9gpuLsNV6HrkKCfyHLh+0SaJx/Yug5yOS+Z2Njv3zXNk5iF5S9nFXHZ4ai9sl88g2 d
X-Gm-Gg: ASbGncvi9NCYCh97+iWTmC40zmTBnITcTj7+2hfrH5DJCt3zVWnOpjyuP9XzYerF7Wn 3+9CN234jJqP6cLLSWgXLpjSPY4yhFed2LDYDtc7s5OQj/juDVrmPTfSWwWDTaus42jarYbdyFJ um0lapGkJhh5cmAluWLUQQueV6Xcg2td4HIPD6gMM/KJPsV5JDt0gL3Be1mqPseEbgU2VVpQDp3 96JgFvxYRix1JeOLCvfdl5uDYtQhVbGDde432MEA9j//PsMqThDBa9BfPmaf+M/XMGt9CMXpUZx 7dvF/YVdFuPY5ybjmKN+MgbCk+UfZMyDHYS/2xqslPTpasqNbkeLgJ4YShNpwgrOT9FxX90=
X-Google-Smtp-Source: AGHT+IEvsTqcHrV3MoVZoSwA84+Lxn5VCWZx3o/vLL45JcxOPwlU7U2EG6IlqFklM95EHgjIyYwavA==
X-Received: by 2002:a05:620a:408c:b0:7c5:af68:5019 with SMTP id af79cd13be357-7c6865dc9e0mr2043727785a.13.1743512302883; Tue, 01 Apr 2025 05:58:22 -0700 (PDT)
Received: from smtpclient.apple ([2600:4040:252a:8d00:143b:c28f:72d3:4acf]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-6eec964bff4sm61293466d6.36.2025.04.01.05.58.22 for <tls@ietf.org> (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 01 Apr 2025 05:58:22 -0700 (PDT)
From: Sean Turner <sean@sn3rd.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.500.181.1.5\))
Message-Id: <582917A1-F936-4A15-AE9D-342076605BE7@sn3rd.com>
Date: Tue, 01 Apr 2025 08:58:01 -0400
To: TLS List <tls@ietf.org>
X-Mailer: Apple Mail (2.3826.500.181.1.5)
Message-ID-Hash: BJOJRXRAJPKPWDA4MT25BMSNM2VJPUK6
X-Message-ID-Hash: BJOJRXRAJPKPWDA4MT25BMSNM2VJPUK6
X-MailFrom: sean@sn3rd.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] WG Adoption Call for ML-KEM Post-Quantum Key Agreement for TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/PpVAwrBTuRb5pR6D0C1ipdQuvYc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

We are continuing with our pre-announced tranche of WG adoption calls; see [0] for more information. This time we are issuing a WG adoption call for the ML-KEM Post-Quantum Key Agreement for TLS 1.3 I-D [1]. If you support adoption and are willing to review and contribute text, please send a message to the list. If you do not support adoption of this draft, please send a message to the list and indicate why. This call will close at 2359 UTC on 15 April 2025.

In response to other WG adoption calls, Dan Bernstein pointed out some potential IPR (see [2]), but no IPR disclosure has been made in accordance with BCP 79.  Additional information is provided here; see [3].

BCP 79 makes this important point:

  (b) The IETF, following normal processes, can decide to use
    technology for which IPR disclosures have been made if it decides
    that such a use is warranted.

WG members can take this information into account during this adoption call to determine if we should adopt these drafts.

Reminder:  This call for adoption has nothing to do with picking the mandatory-to-implement cipher suites in TLS.

Cheers,
Joe and Sean

[0] https://mailarchive.ietf.org/arch/msg/tls/KMOTm_lE5OIAKG8_chDlRKuav7c/
[1] https://datatracker.ietf.org/doc/draft-connolly-tls-mlkem-key-agreement/
[2] https://mailarchive.ietf.org/arch/msg/tls/mt4_p95NZv8duZIJvJPdZV90-ZU/
[3] https://mailarchive.ietf.org/arch/msg/spasm/GKFhHfBeCgf8hQQvhUcyOJ6M-kI/