[TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
"Kampanakis, Panos" <kpanos@amazon.com> Fri, 10 October 2025 03:00 UTC
Return-Path: <prvs=371f8d6b6=kpanos@amazon.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E8D63706A107 for <tls@mail2.ietf.org>; Thu, 9 Oct 2025 20:00:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=amazon.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9zokK6Xnf2c9 for <tls@mail2.ietf.org>; Thu, 9 Oct 2025 20:00:54 -0700 (PDT)
Received: from iad-out-014.esa.us-east-1.outbound.mail-perimeter.amazon.com (iad-out-014.esa.us-east-1.outbound.mail-perimeter.amazon.com [50.16.246.183]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 75FCD706A0F8 for <tls@ietf.org>; Thu, 9 Oct 2025 20:00:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazoncorp2; t=1760065254; x=1791601254; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=syZGE93Bm6ZYGJGFi3+AGGv1oGDdFSEYyxSPMgK0pd4=; b=DCmjHHF542uwscrBKOTFQBsgphNF2icHEtMIzRLzmqGG15ToTKofyllS K5AGRVu6CCI9H9RW4HogVZGgPpZyHiWAIpHlOTx7FkuXK8zNyqt2CCHQT 7yXxuyH3cO/4Lx3B10Kyw+SZMdrqOBSKpPzpbEFW9WwHO3DxX/UCSw2k5 vTdqMjj40u1NZF0HwYjMORuPSNAbhVl38U6RUvkI3GnUMqeXSlT3eQGfj 3IFgn/rfTQK5mzO7XojSSc13pm2Hv5l2Dlo3yenBd7nwDVeKjeHu/qXJO UEz+xO5tWd1tWAwjgSe2zYvhAYiWtio09GONuyURUdqZNKJwJja/zdM/K Q==;
X-CSE-ConnectionGUID: KutO71G7RA+DbwCKCJ+bSA==
X-CSE-MsgGUID: 08kll8e0TsmpC7Z0xiR9Ew==
X-IronPort-AV: E=Sophos;i="6.18,263,1751241600"; d="scan'208";a="3699910"
Received: from ip-10-4-3-150.ec2.internal (HELO smtpout.naws.us-east-1.prod.farcaster.email.amazon.dev) ([10.4.3.150]) by internal-iad-out-014.esa.us-east-1.outbound.mail-perimeter.amazon.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 10 Oct 2025 03:00:52 +0000
Received: from EX19MTAUEA002.ant.amazon.com [10.0.44.209:25354] by smtpin.naws.us-east-1.prod.farcaster.email.amazon.dev [10.0.11.5:2525] with esmtp (Farcaster) id 90a7b796-390f-4cd3-a6fa-afa4670bdca7; Fri, 10 Oct 2025 03:00:52 +0000 (UTC)
X-Farcaster-Flow-ID: 90a7b796-390f-4cd3-a6fa-afa4670bdca7
Received: from EX19EXOUEC001.ant.amazon.com (10.252.135.173) by EX19MTAUEA002.ant.amazon.com (10.252.134.9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20; Fri, 10 Oct 2025 03:00:50 +0000
Received: from EX19EXOUEA002.ant.amazon.com (10.252.134.207) by EX19EXOUEC001.ant.amazon.com (10.252.135.173) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20; Fri, 10 Oct 2025 03:00:50 +0000
Received: from DM2PR0701CU001.outbound.protection.outlook.com (10.252.135.42) by EX19EXOUEA002.ant.amazon.com (10.252.134.207) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20 via Frontend Transport; Fri, 10 Oct 2025 03:00:50 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=EQi29foOkzLXYpYUWZCLA5xp4cLcQrqBrLr0FxwYWRCG9iUZ3mJ/c69fPkm35ESDA4TakHhp04+uLfDhCVYAiTeJwIhGjAm6zByx/9yHYW+hSNQTjUmDIC3tsna/m9pXQbLJxLa7INrJBinsphqrM3qRNKdJPSKfeD9CxtxPKEiPTjY60XyZQvCVcIu0YtfI3rv25F7JZ+I8Ygrec0ISsPvHFSE+9sw2bDm+jt/sFnQiXL6B7bjugctO8rl02D5F1kjeBH2msdI7rKIld3P4IGMnymWgGyukEEmLnC1zcJqWdScZIs8uzIo0CaBdYvu5H3gslnPk4OWGV3kM2VQ0YQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=syZGE93Bm6ZYGJGFi3+AGGv1oGDdFSEYyxSPMgK0pd4=; b=na+mhb7Bvie5CIG8AQ27/6fR0CyG+QgACDMqrsPIS9UalIJZL4g+LBA8wBwr5vyTjBG48HSvnqUvXe3K+HkLYjMSo7HDmrG2Pmma+Jpp/jflmsOl3dK2syLdY/hFM5L6M9ZChLMPZSiZJ3Q6CSx+oyAcLcgzSdZK5SN8sPULb1ZIKgN50LGqvaOXsYRegmU/boSRG3YdEOHtPTtr+JolA7w78QNufhWrLqZMmr17ddURqSTlk1EXSw/xZr54PUzdJekTWxHDlkL7LWTYh89mrHd6dmsrIJ3xOfZczRMYbn4yYxou3lGHi3zbDU6FTAtvCM09KgrpQYzHbVXbzSjAhg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amazon.com; dmarc=pass action=none header.from=amazon.com; dkim=pass header.d=amazon.com; arc=none
Received: from DM5PR18MB2326.namprd18.prod.outlook.com (2603:10b6:4:b9::33) by IA2PR18MB5862.namprd18.prod.outlook.com (2603:10b6:208:4b4::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9203.10; Fri, 10 Oct 2025 03:00:48 +0000
Received: from DM5PR18MB2326.namprd18.prod.outlook.com ([fe80::6dd6:86fd:258:83be]) by DM5PR18MB2326.namprd18.prod.outlook.com ([fe80::6dd6:86fd:258:83be%4]) with mapi id 15.20.9182.015; Fri, 10 Oct 2025 03:00:47 +0000
From: "Kampanakis, Panos" <kpanos@amazon.com>
To: Simon Josefsson <simon=40josefsson.org@dmarc.ietf.org>, "tls@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
Thread-Index: AQHcOZITL7CWMUSnFkeHfb7N0pZCkg==
Date: Fri, 10 Oct 2025 03:00:47 +0000
Message-ID: <DM5PR18MB2326F8190E5DA714786D92C1ABEFA@DM5PR18MB2326.namprd18.prod.outlook.com>
References: <CAOgPGoA+c8kXDizwsvFG5tLz9+Kxk0HqiN1skKp5jMvvpxeu0Q@mail.gmail.com> <CABcZeBO+3u=1=ueNscq+O74Qv=7PC5NedsGsugp=GZjVqtODoQ@mail.gmail.com> <CAMjbhoVcxTfppSrkC27F8uf9hKvqTDBsG_-dzGtWbjia5YhmXw@mail.gmail.com> <aOVWcf9JFllri-vG@netmeister.org> <87h5wapnqf.fsf@josefsson.org> <87ikgozi00.fsf@josefsson.org>
In-Reply-To: <87ikgozi00.fsf@josefsson.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=amazon.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM5PR18MB2326:EE_|IA2PR18MB5862:EE_
x-ms-office365-filtering-correlation-id: a352bf87-39bf-498b-4db8-08de07a93651
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|366016|1800799024|10070799003|38070700021;
x-microsoft-antispam-message-info: NDxxGggexQQWcmxHrvS9/V49Il+rGl+X8+mre14IJTND4NnYUt8w5TPqsL2NAgAo6YuwnaMJnCZCLQYI8pphABc2AfonQHOiukVpb67/7PAOxrRvhMQVF5IvWFDNBML9y9Kdyy423vGsvpF+NDGV00MSOHB7RCfNj7/c36/Lo2mel+RGnW9lX/mOHm3iY4sfEhVjkSq6hCh6xr8zaT3W9b4lrWPXGEzmTYuHdasyd5oWm6rlrCAKDu9UDZSR+4oetkRvCxiF/+DcUPx0TLWodaCKTBE17uSGjuiqlgFRiA4Y27TIpxow4hCSuGS16CtGOtjwxWwuHkt93uP0VjfC29ei2OShcS/VZUsJjduLXvs5whXg8ko9d6gbmb7KQc7FnNTiUJ6wiLS5nVC78ywjJmLemapkZDPuAQJjRE6RUseQ9QDLwBw8zv9mrPLAuTbogRo++WNyuyDgc3f1iaOem7j4sB+XDemIU/QM+Y+b2ICqjHF6YKSWVP6ZKTv3geRaA024syj+PoKwx48JqrV5dpacxbaLQDzmuTWqk3ZL33hY+16IudrrcwOqL/tX1bOKdxD9lNVUn7G2GndXoG2Q7o0pdeDeXGdLIkA9ccqUBl+FhH+vt+Y4NPpYKRs+lDMcxoIzvKvKKKnA+4zGfnayVdfWeqgSonmNPLQQKlYKloAhDtZ8bfXFadCzusCnohzdhcGf/CY12uMpxSsEScWprKps0DFTiAQMkz+3/TNkCHkLlcv5xK5xHf9Ky4uasJODNNUccyItr41780hdczAv3pjyGd9Mj7P7GW5RGbiVS3m/wwcFvDl2VqmFF1tDZY3Q3vGIyX4b8hZkUDcSigsrL76EdSUQwu9rPym6l3kqrLlrpmAkiSPHXBr/6RvsLlXBW0EH7sPIhg5fIy6xO3+rus6mFXmQzJfIHBFuVk0bgi7P/b3NVS/vPGNPRJXmypvt67LU73rKqyJ68zyGLcj8Hwnr+mG/bBvxIUiOIh5VFLr3/gA8tPjJYACs6sZZ1KNJaoT0mc8xM5mygRxG70WImhgLdOSPQFogl7dsUMV2Wn8xMrKZW/eLTJG9XLrNOJeBlZszrlHJx6vhGkUHMHPqT1qDwLRdUdfj3tqWL48zoO2Y9w/HbedjpBgUKR1ZclmvUlJteNau84vkkEHsl6XTykRImuwXiKAv57UUgNaryy+aPSJX/WV69Xc3Jt5CbFfi1POrpCltBLcyEZDiEeJkFe94ihCQuVBgas5PsUQ6eFDeGBwAR5cwq/1zu/HpiogGwQlRHz+SjvzSvQwJbBwoxKd7fzTgFUkKD0FqAyyATU5Ni3Kgv5mHUm689RvU3gtHnTujvQHdb7etEBrD4f0B5l+Eb63PsjBjAQWo2niVZwwkhzG7F3IFhbihMXtyo4f2NjaWJ4Qh3K5OZ39qosvXW1AE7CP+jVncY3NnEF+1Sr2ig8AlSCGYl6M573JkbxvYFD7LVQiLVyxYAKI+kozbnChNglAE9YBh7me2p4KjEJ+qbKTDQBqccUqmXFnI0Vs/
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DM5PR18MB2326.namprd18.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(366016)(1800799024)(10070799003)(38070700021);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: mO5nTHmC7Za0mTRqUwaRj2kfEBrLJrGYWOeZ9x8d2XDiDtgFmlr8V3FLMSb/egKCJx4khHiOMOTs9rGMAxMByqBcdYPHzJV9osx6hFO/dSKEWaTWo2TAMNTWg6B9SHCfUqJRhfPF41XgyFZPRGZeO31bDX6DuMeBIpafh+TL0y2oBL4BUgix6jL4lUQaCRoYGNf7tEySbETf4nV5d10uQhTkPppOvMkpHBG7BM/HP8TZfqR9L3VQxSDgTwta5Qt5GniGIHD9PGcLs/Tm0szf1tV6wvGO7VCFkwmNCeKCtQrxR/kVAToSebvX3TnbBibnCcOp1FOrLeofno0Fx+A704JfJ3ffzqbQo7XaH+Zaw23Q2oK6V1o9D9xHyS4yN0fCTMLUDIn2q0APZrqzKFqguY7nVqB2b5K4XI6JAsOYzBry2PxLO6mswzl6aqmaru1GGKeN8egscaDn5Y0+3qesd6PP0STaRaRugiAhF6z1LA/Bp5viW5bJbQWs18fkPD6LSuCgjbWoxddvVAQK+LHW7gBPkDjF774R/awNyvLUpjSVrgFJ4xbv4DhTB39IMrUTdhkD5v4CjpJkFn7Myt7UNTITq5Ld1jDiXStNcOihFdoBGFqpbOesCsN1smcIf3WAhipSjNOX5gfsYe9qLfoh68+P2bMBFJQxcw3t4zEi1xytBWWfh4Qy4WSfUdmg7sbURMwcaTt6fDs7/5swMZk946N0+qI+FxdIDbb3BsAlq2lHeIyxP6b615Yk8L7lZQ6+aT8sp5STXrPjnFM2frpJ5eyMlLGvO/1pW83c8xG/Gu9rtyJu+GQxlzQroYPzWoQzaoTaq8nJhXxOzOvDIANvjOX8ibiYCWybTDX24kFDmrEusZ5XAIWzAoLtWDpE7Ezfk7066NOZfz6RqvA8lU6q9bjDOe5elkDlVvnKaCb1EUOMrn9SGH2p2hXnudPwb1ULOEVCv9M647Xvd/2LP0SB2eXI08UZZWXPTKZ05+WjiLfph17rB7CSm5cDZJhvYiYc8TYvNs8posDN6IKyAwoys1qrbeXR0rqSVFpGrMoOYsqNo28cqGba8KOgDMpw9baY2cerp/Lpjz2lT+ktVaj6Ylxa6FZT8/DyWyGfQfMKkG/5ZuTCmLKvISzT8/bK8cGdgqKU+aXbVHQFhoeRDmd8SsqsyL5nyDby4DCXfTiqKH4jCK08mUhG2p3NN8t4StJDsZl7vDxBvqnYN5i+Gpwo8hT0uCYuT6qdxVzXxydpiBn4FU7p3ljZuL9jsmu8eNvKBF0fNBzH+Gck90WzbBaHeyIJ7D4J27cORk3BBlpRm17JHbMnySvfOW4swuGfFFMXo3yGn1z93oBXUDL6SPi02bj5bWGrmEOex21AI7gATER+eTLbZXZd3yfQxRJHot6wFyZp5wI8tL/RIYrJogsQVU1GPubCAxNZJP5oYfeFVflZWujE1jlmvyEBeH1XqQvRQfepO0WEdBgLSPHqW8jWqcOR7mHAMrY+/r4EPda0RegOpjVtfsTITEUGd2G19XIXF9ZdTVbRXzb3wtB3qSNpXtyZWUwo0gYOKOeOmgdZC4zrxzTAzfkxIi9VNDcmHwP4Q0RR5IirBiCkt/Ufj1vBl84l3DKe4Tg2pbYGDGlKtkf4HVtraQeaWriIlz7+MZtY
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM5PR18MB2326.namprd18.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: a352bf87-39bf-498b-4db8-08de07a93651
X-MS-Exchange-CrossTenant-originalarrivaltime: 10 Oct 2025 03:00:47.4811 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5280104a-472d-4538-9ccf-1e1d0efe8b1b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: LL3dqpDqd59bheFFODM6DI1k1fI1ebv5DOFDVyyjFH5F3a4o6HPEPnMKEK/bDlvZ7XhfPBm8WQWcAJkWeqUM9Q==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: IA2PR18MB5862
X-OriginatorOrg: amazon.com
Message-ID-Hash: AO466IAPCE6I4E3MG33RIYT7B4K2PT7Y
X-Message-ID-Hash: AO466IAPCE6I4E3MG33RIYT7B4K2PT7Y
X-MailFrom: prvs=371f8d6b6=kpanos@amazon.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/RV8jm2lWq7q1XlmcYosacQb9Ir4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
I understand that we can find any arguments for or against anything nowadays, but let's standardize the codepoints which have already been assigned by IANA. There is no reason to break this document in separate documents. -----Original Message----- From: Simon Josefsson <simon=40josefsson.org@dmarc.ietf.org> Sent: Thursday, October 9, 2025 2:50 AM To: tls@ietf.org Subject: [EXTERNAL] [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3 CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. Simon Josefsson <simon=40josefsson.org@dmarc.ietf.org> writes: > The discussion below suggests to me that X25519MLKEM768 is the running > code de-facto algorithm that ought to be on the Standards Track and > Recommended=Y and the other variants should be split off to a separate > Informational document with Recommended=N for niche usage. I realized that there is another argument for the above, see https://datatracker.ietf.org/doc/html/draft-ietf-tls-hybrid-design-16#section-4 Duplication of key shares. Concatenation of public keys in the key_exchange field in the KeyShareEntry struct as described in Section 3.2 can result in sending duplicate key shares. For example, if a client wanted to offer support for two combinations, say "SecP256r1MLKEM768" and "X25519MLKEM768" [ECDHE-MLKEM], it would end up sending two ML-KEM-768 public keys, since the KeyShareEntry for each combination contains its own copy of a ML-KEM-768 key. So this is an argument that X25519MLKEM768 ought to be the preferred, recommended=Y and Standards Track algorithm, and that the other variants should be actively discouraged by moving them to a separate document for niche usage. This situation could also be seen as a bug in the design of draft-ietf-tls-hybrid-design but I suppose it is a bit late to change that. And the implication to have only one preferred hybrid variant for each PQ algorithm isn't unreasonable. Algorithm profileration leads to fragmented parametrized implementations and security issues. So I think the this "bug" could also be seen as a feature, even if that property probably wasn't intended initially. /Simon
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Paul Wouters
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Working Group Last Call for Post-quantum Hy… Joseph Salowey
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… David Adrian
- [TLS] Re: Working Group Last Call for Post-quantu… Loganaden Velvindron
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Deirdre Connolly
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Loganaden Velvindron
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… tirumal reddy
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Andrei Popov
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Thom Wiggers
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… David Benjamin
- [TLS] Re: [External⚠️] Re: Working Group Last Cal… Yaroslav Rosomakho
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Eric Rescorla
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: Working Group Last Call for Post-quantu… Martin Thomson
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: [External] Re: Working Group Last Call … D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Filippo Valsorda
- [TLS] Re: [External] Re: Working Group Last Call … Muhammad Usama Sardar
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: [External] Re: Working Group Last Call … John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Dennis Jackson
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Stephen Farrell
- [TLS] Re: Working Group Last Call for Post-quantu… Joseph Birr-Pixton
- [TLS] Re: Working Group Last Call for Post-quantu… Robert Relyea
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Sophie Schmieg
- [TLS] Re: Working Group Last Call for Post-quantu… Christopher Patton
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Muhammad Usama Sardar
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Appeal Response to Rob Sayre - was Re: Re: … Paul Wouters
- [TLS] Re: Appeal Response to Rob Sayre - was Re: … Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Peter Gutmann
- [TLS] Re: Working Group Last Call for Post-quantu… Yaakov Stein
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Robert Relyea
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Sophie Schmieg
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Joseph Salowey