[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26)

Kris Kwiatkowski <kris@amongbytes.com> Mon, 24 November 2025 22:47 UTC

Return-Path: <kris@amongbytes.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6B3F28FCC84C for <tls@mail2.ietf.org>; Mon, 24 Nov 2025 14:47:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=amongbytes.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YaUCgtzPjnha for <tls@mail2.ietf.org>; Mon, 24 Nov 2025 14:47:11 -0800 (PST)
Received: from 9.mo579.mail-out.ovh.net (9.mo579.mail-out.ovh.net [46.105.58.100]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CE4308FCC7D1 for <tls@ietf.org>; Mon, 24 Nov 2025 14:46:45 -0800 (PST)
Received: from mxplan8.mail.ovh.net (unknown [10.110.37.200]) by mo579.mail-out.ovh.net (Postfix) with ESMTPS id 4dFgt61kxGz5vy3 for <tls@ietf.org>; Mon, 24 Nov 2025 22:46:38 +0000 (UTC)
Received: from amongbytes.com (37.59.142.107) by mxplan8.mail.ovh.net (172.16.2.82) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.1.2507.61; Mon, 24 Nov 2025 23:46:37 +0100
Authentication-Results: garm.ovh; auth=pass (GARM-107S00110312aad-0f45-499a-a624-5fc8e553c3aa, B88A760F7DF0A424B08B0315CCBE9C6B03B63B37) smtp.auth=kris@amongbytes.com
X-OVh-ClientIp: 88.97.253.244
Content-Type: multipart/alternative; boundary="------------KvJDRyxstlhoMyomD0M8q0EC"
Message-ID: <91ec30e5-0ece-46e5-ab77-45ac57dbe186@amongbytes.com>
Date: Mon, 24 Nov 2025 22:46:37 +0000
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-GB
To: tls@ietf.org
References: <176236867319.904123.10146982018394612684@dt-datatracker-5df8666cb-7l4w5> <7C4EF478-FD07-41ED-A32C-082B26D82527@vigilsec.com>
From: Kris Kwiatkowski <kris@amongbytes.com>
In-Reply-To: <7C4EF478-FD07-41ED-A32C-082B26D82527@vigilsec.com>
X-Ovh-Tracer-GUID: 09512c24-5717-4c83-8dd3-e74d9f57f59d
X-Ovh-Tracer-Id: 16162856115315261207
X-VR-SPAMSTATE: OK
X-VR-SPAMSCORE: 0
X-VR-SPAMCAUSE: dmFkZTF9WClgKr6qbOayI0nqruXWbTrJvb8R2rlAQQVXgRDLKs7ZAM29tC9nC0ec4LkMEfwvnMG90JWBsdGWQ5PGT77bpPzkPb0cxSEJ5tT/RQw80GuoonhuhmtbYBt7f5JImVdUdbETUB2fD4Zy5uTxxh5244me6Id4zUACSBvkX21y0DgxF9YSk4MuayjaXjHOpGSxUyTki5jTrYfqwYQ7Oaka0h3L09/PoOqdjPYUzU56QyOlnPg/PlmzuNgKBJxRX/gvWpoVJ9WP4AyqzyW/daTARsCV6GTM2lPCjd9rKRcS+fODb9Y+tsvxBw3NqZ+wrKizP1ch04rCgPHkGYd6A9WhfweSn+4I3Izule4XgiMxUcPMgk3cr+/qhbzfCmHihBwBEUG5i2vEfHaZk+7FL+DX3XXmxeRoDamUCaJtsg9seD4W/O3F+9irt8+GU4VzsuGoY4UCOodG+hLh5DIJDwXMF6I+b1MDOVr9whcldT35bt4Jm3fzq3ZwWJOQpmQPQU2w/Y7gW5TKRMDIywtAm8ySZ5gX9jdXAAXSlYq3P+xEPb4u3TDDvIA6hfHmVRgI65b9wxXtYGXzBafSs8Kz7MNUw8N26w2sGGlEy0UO5ZLNJ5g6WchIa3je45EFwSEZXL2Uqf53K2jbmgjVuk8b1+az3soi4W1IL0C9kJ5CUhcpnQ
DKIM-Signature: a=rsa-sha256; bh=KGJM/LKcYLURHxuC30U7f29d2AlvxQhtjx0yRZlp7ww=; c=relaxed/relaxed; d=amongbytes.com; h=From; s=ovhmo2671616-selector1; t=1764024398; v=1; b=QCt25ekluGtDjH8OZBMpI5pB5yZ09PzGY+WyXliVRGC5FWFAXFH8yTg5hEKPIZhC0YqJ+cr2 UD5luoDqji8adioXhPJRlehTK70kjk7t0mv+G2RyF5c2HZAk2vz9hXxmKdv7GmMuLKM60BDJqrm 0ehg9nMlUO6ixT/1TKn2rdrm4JPip4fa/K0D6bigtYKfZ/JaJLc3vKRTQm4jWQcsZUyv12vDjrL yHLkuTdeqJJOmv7bjShDsBOPCWFDedTB8ArZjn/Lqm5mVHXt81NWcWnHZTAVRKHGB8vRkBfsizi 9f7q5zHB/H7xzyJHM7QHADAhja5P2QwOXbb1dlwQaXfSQ==
Message-ID-Hash: IJ4HXHQU4PXIP5VOKGJ4WMW55RNEDO73
X-Message-ID-Hash: IJ4HXHQU4PXIP5VOKGJ4WMW55RNEDO73
X-MailFrom: kris@amongbytes.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/R_KW2SzE0UFMAae_hIbDxbVMzh0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I support adoption, as long as the RECOMMENDED field is set to N at this point 
in time (which is a case).

Nits:

* draft talks about "expanded keys" and "decapsulation key seeds", but does 
not define them. I think it would be good to refer to the relevant sections in 
the FIPS-203, to make it clear what they are.
* Section 4. ends weirdly "Section 4.2.7 of [RFC8446]" - should this be a full 
sentence?
* Double 'and' in the Abstract "...NamedGroups and and registers IANA..." and 
double 'the' in Section 5.

Kris

On 08/11/2025 15:37, Russ Housley wrote:
> I support adoption.
>
> I am pleased to see the IANA registry entries for the ML-KEM code points as RECOMMENDED = N; at some point in the future the TLS WG might want to change that, but this seems like the right place to start.
>
> Nits:
>
> Abstract: s/and and/and/
>
> Section 1.1: s/key establishment/key encapsulation/
>
> Russ
>
>> On Nov 5, 2025, at 1:51 PM, Sean Turner via Datatracker<noreply@ietf.org> wrote:
>>
>>
>> Subject: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2025-11-26)
>>
>> This message starts a 3-week WG Last Call for this document.
>>
>> Abstract:
>>    This memo defines ML-KEM-512, ML-KEM-768, and ML-KEM-1024 as
>>    NamedGroups and and registers IANA values in the TLS Supported Groups
>>    registry for use in TLS 1.3 to achieve post-quantum (PQ) key
>>    establishment.
>>
>> File can be retrieved from:
>> https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/
>>
>> Please review and indicate your support or objection to proceed with the
>> publication of this document by replying to this email keepingtls@ietf.org
>> in copy. Objections should be motivated and suggestions to resolve them are
>> highly appreciated.
>>
>> Authors, and WG participants in general, are reminded again of the
>> Intellectual Property Rights (IPR) disclosure obligations described in BCP 79
>> [1]. Appropriate IPR disclosures required for full conformance with the
>> provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of
>> any. Sanctions available for application to violators of IETF IPR Policy can
>> be found at [3].
>>
>> Thank you.
>>
>> [1]https://datatracker.ietf.org/doc/bcp78/
>> [2]https://datatracker.ietf.org/doc/bcp79/
>> [3]https://datatracker.ietf.org/doc/rfc6701/
>>
>>
>>
>> _______________________________________________
>> TLS mailing list --tls@ietf.org
>> To unsubscribe send an email totls-leave@ietf.org
> _______________________________________________
> TLS mailing list --tls@ietf.org
> To unsubscribe send an email totls-leave@ietf.org