[TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt> (ML-KEM Post-Quantum Key Agreement for TLS 1.3) to Informational RFC

Christian Huitema <huitema@huitema.net> Tue, 11 August 2026 18:55 UTC

Return-Path: <huitema@huitema.net>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 54B44128026D9 for <tls@mail2.ietf.org>; Tue, 11 Aug 2026 11:55:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786474525; bh=ry8D5UPHGE0eivZBtO7ZIm429nz+lICmZQIOea1dMLo=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=jBjDduZOe4s9TrVrpT1TmMIJUm4fmgCt8zR7vept8dVXhC8+FhUGnztkwMrBjHzDz M/0Kfp7zBiIDK70CMjga36C3fVwkd9dCO/u8zmMmssWetiBBzESjusHRHaTnY6G33i vuAwKcX5EjJO6bPd0Iu9h6lkjap2CzgdUkVYtCOU=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dFmC72wA34sG for <tls@mail2.ietf.org>; Tue, 11 Aug 2026 11:55:24 -0700 (PDT)
Received: from semf12.mfg.siteprotect.com (semf12.mfg.siteprotect.com [64.26.60.175]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BDDA9128026D4 for <tls@ietf.org>; Tue, 11 Aug 2026 11:55:24 -0700 (PDT)
Received: from smtpauth02.mfg.siteprotect.com ([64.26.60.151]) by se05.mfg.siteprotect.com with esmtp (Exim 4.94.2) (envelope-from <huitema@huitema.net>) id 1wtrUn-006nPL-AP; Tue, 11 Aug 2026 14:55:16 -0400
Received: from [192.168.1.104] (unknown [172.56.170.210]) (Authenticated sender: huitema@huitema.net) by smtpauth02.mfg.siteprotect.com (Postfix) with ESMTPSA id 4hKLR44fkKzCSFvKH; Tue, 11 Aug 2026 14:55:12 -0400 (EDT)
Message-ID: <5d8e6a16-551a-4c95-8afc-1b492f1822e5@huitema.net>
Date: Tue, 11 Aug 2026 11:55:09 -0700
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Nadim Kobeissi <nadim@symbolic.software>, "D. J. Bernstein" <djb@cr.yp.to>
References: <20260811153812.2807121.qmail@cr.yp.to> <DAB4D103-B9F1-4401-A766-4222583CF727@symbolic.software> <F369AAC6-3031-477F-BB36-F9097E2950F2@symbolic.software>
Content-Language: en-US
From: Christian Huitema <huitema@huitema.net>
Autocrypt: addr=huitema@huitema.net; keydata= xsBNBFIRX8gBCAC26usy/Ya38IqaLBSu33vKD6hP5Yw390XsWLaAZTeQR64OJEkoOdXpvcOS HWfMIlD5s5+oHfLe8jjmErFAXYJ8yytPj1fD2OdSKAe1TccUBiOXT8wdVxSr5d0alExVv/LO I/vA2aU1TwOkVHKSapD7j8/HZBrqIWRrXUSj2f5n9tY2nJzG9KRzSG0giaJWBfUFiGb4lvsy IaCaIU0YpfkDDk6PtK5YYzuCeF0B+O7N9LhDu/foUUc4MNq4K3EKDPb2FL1Hrv0XHpkXeMRZ olpH8SUFUJbmi+zYRuUgcXgMZRmZFL1tu6z9h6gY4/KPyF9aYot6zG28Qk/BFQRtj7V1ABEB AAHNJ0NocmlzdGlhbiBIdWl0ZW1hIDxodWl0ZW1hQGh1aXRlbWEubmV0PsLAeQQTAQIAIwUC UhFfyAIbLwcLCQgHAwIBBhUIAgkKCwQWAgMBAh4BAheAAAoJEJNDCbJVyA1yhbYH/1ud6x6m VqGIp0JcZUfSQO8w+TjugqxCyGNn+w/6Qb5O/xENxNQ4HaMQ5uSRK9n8WKKDDRSzwZ4syKKf wbkfj05vgFxrjCynVbm1zs2X2aGXh+PxPL/WHUaxzEP7KjYbLtCUZDRzOOrm+0LMktngT/k3 6+EZoLEM52hwwpIAzJoscyEz7QfqMOZtFm6xQnlvDQeIrHx0KUvwo/vgDLK3SuruG1CSHcR0 D24kEEUa044AIUKBS3b0b8AR7f6mP2NcnLpdsibtpabi9BzqAidcY/EjTaoea46HXALk/eJd 6OLkLE6UQe1PPzQC4jB7rErX2BxnSkHDw50xMgLRcl5/b1bOwE0EUhFfyAEIAKp7Cp8lqKTV CC9QiAf6QTIjW+lie5J44Ad++0k8gRgANZVWubQuCQ71gxDWLtxYfFkEXjG4TXV/MUtnOliG 5rc2E+ih6Dg61Y5PQakm9OwPIsOx+2R+iSW325ngln2UQrVPgloO83QiUoi7mBJPbcHlxkhZ bd3+EjFxSLIQogt29sTcg2oSh4oljUpz5niTt69IOfZx21kf29NfDE+Iw56gfrxI2ywZbu5o G+d0ZSp0lsovygpk4jK04fDTq0vxjEU5HjPcsXC4CSZdq5E2DrF4nOh1UHkHzeaXdYR2Bn1Y wTePfaHBFlvQzI+Li/Q6AD/uxbTM0vIcsUxrv3MNHCUAEQEAAcLBfgQYAQIACQUCUhFfyAIb LgEpCRCTQwmyVcgNcsBdIAQZAQIABgUCUhFfyAAKCRC22tOSFDh1UOlBB/94RsCJepNvmi/c YiNmMnm0mKb6vjv43OsHkqrrCqJSfo95KHyl5Up4JEp8tiJMyYT2mp4IsirZHxz/5lqkw9Az tcGAF3GlFsj++xTyD07DXlNeddwTKlqPRi/b8sppjtWur6Pm+wnAHp0mQ7GidhxHccFCl65w uT7S/ocb1MjrTgnAMiz+x87d48n1UJ7yIdI41Wpg2XFZiA9xPBiDuuoPwFj14/nK0elV5Dvq 4/HVgfurb4+fd74PV/CC/dmd7hg0ZRlgnB5rFUcFO7ywb7/TvICIIaLWcI42OJDSZjZ/MAzz BeXm263lHh+kFxkh2LxEHnQGHCHGpTYyi4Z3dv03HtkH/1SI8joQMQq00Bv+RdEbJXfEExrT u4gtdZAihwvy97OPA2nCdTAHm/phkzryMeOaOztI4PS8u2Ce5lUB6P/HcGtK/038KdX5MYST Fn8KUDt4o29bkv0CUXwDzS3oTzPNtGdryBkRMc9b+yn9+AdwFEH4auhiTQXPMnl0+G3nhKr7 jvzVFJCRif3OAhEm4vmBNDE3uuaXFQnbK56GJrnqVN+KX5Z3M7X3fA8UcVCGOEHXRP/aubiw Ngawj0V9x+43kUapFp+nF69R53UI65YtJ95ec4PTO/Edvap8h1UbdEOc4+TiYwY1TBuIKltY 1cnrjgAWUh/Ucvr++/KbD9tD6C8=
In-Reply-To: <F369AAC6-3031-477F-BB36-F9097E2950F2@symbolic.software>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Authentication-Results: mfg.siteprotect.com; auth=pass smtp.auth=huitema@huitema.net
X-Originating-IP: 64.26.60.151
X-SpamExperts-Domain: mfg.outbound
X-SpamExperts-Username: 64.26.60.150/31
Authentication-Results: mfg.siteprotect.com; auth=pass smtp.auth=64.26.60.150/31@mfg.outbound
X-SpamExperts-Outgoing-Class: ham
X-SpamExperts-Outgoing-Evidence: Combined (0.03)
X-Recommended-Action: accept
X-Filter-ID: 9kzQTOBWQUFZTohSKvQbgI7ZDo5ubYELi59AwcWUnuWN8hzwoa+35oiH7GjR8Mbq8+SeTedEP815 uvBeVT419Su2SmbhJN1U9FKs8X3+Nt127hcteP1p0NVNV47moiZtUnZMMMyaNBeO+OvFQHUlG4JL M0i5ZAms0EHrvcCaVIPuFWM968awC4/iTj9wKBEkGnT3EFAinyrilm9zau/FuzkQt9Nb4Ml7QXdk EetczWDLE03raa/FEALf0Z8wGU5oeB7itP8hgjDRserKv4bhbzi838DBmUKWhOLHfo543wbEMzer JfQa9UAYKsgEV8p+MUJTS2Jsxpkx+IHIsDarm2U3gyy0nlbakKK22WPBaizjKzb+JrnOTbl8FYp7 CIWjverajYy2yB71RZy29b9HL7yliuqXZvH3i216cQum167MYH6FhGw6h8DCIlZPuTwFqscJlIur GxwpQMD4ZvWNUZKl1gco+ua8LGbi2LqkQvq4jZ0wsOIhDTGYHmdLTJXPeBGzQqlalufIKjjMaDuT w37KNmzQeIjNKbtlrCkjPH093SsS4aMXJmiJ2G0eb5ahoREkx21rnkcPLu0AmuzkmCgbe7gajn4V Nr1c9Ancwoogr/U0flMcy2Vi/IcBgY4a40xysD3asope6RfxdWjd/f8nFQ8lH63meGJi990LHVOH KT8I62f8AwNLqH0zruPSIziHhiJsUMgg3/SrqwMULAQ74357qugh0cnJCNRKqK3qf32HRAIXLxSx jQIuPQZeE7PuIuMZhIuPZ5EwGkCpVooqpelI9UNgCvkc8wkUC9dwV76ywZSglUY43T240OB5+kpv ery/hf4Toec6jFriivYuw20Pp9zkgurw6GLyDE+puSMj5GClrnAFwFRqfsSK5VwOaIcUJUlV1/Dd 0c6Ub/eWlW2AhVmLwclHwfNqjSAeV43+o32px0aJ3B+F2Ma3Ibtf63VNbf0lrvssY+k7ANV9vSRo /1xTrPwmBTZdNGMFvj0x1+0Va1IwBHy92M3yM//fqrFkKtukEv/gqfGElzxvOFsZtiumh0uu8B3Q oJFRxzb5bMUOev8XhS0yaSfeThzzznW3MnIr9e4R6pidWBjgvu7pAn+NdcA8i2i+TTi3yztQOKsU oaz9x3nssV+cNh535BFsGGG34oMougVpHMfewmGTRwxX79sHxFhUiAA=
X-Report-Abuse-To: spam@se02.mfg.siteprotect.com
X-Complaints-To: abuse@se01.mfg.siteprotect.com
Message-ID-Hash: FJ3VV6W2YMDTXZBRIVQPYQGL3QOI2CYO
X-Message-ID-Hash: FJ3VV6W2YMDTXZBRIVQPYQGL3QOI2CYO
X-MailFrom: huitema@huitema.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt> (ML-KEM Post-Quantum Key Agreement for TLS 1.3) to Informational RFC
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/RlzMQluGzLB69vwlx29-nPBwq_o>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On 8/11/2026 9:18 AM, Nadim Kobeissi wrote:
> Hi DJB,
>
> Sorry, let me try to be more constructive.
>
> I really think that the way you’re communicating your concerns is 
> simply impossible to digest by most of us.

I think deployments now have the choice between "hybrid" and "solo" 
deployments of PQ algorithms. There will be reference documents for 
both. The IETF has expressed a clear preference for hybrids through the 
"preference" flag, and also by pushing the hybrid specification on the 
standard track and the solo specification as an informational document. 
I understand the concern that this may be too subtle, and that many 
would prefer a more forceful way to steer deployments away from the solo 
option. On the other hand, I don't think that belaboring the point in 
e-mail to the TLS working group would achieve that goal of "steering 
deployments away from solo PQ".

If Dan and others do think that there are good arguments to steer 
deployments away from solo PQ, then by all means publish these 
arguments. Nadim suggests using web site or scientific publication, so 
as to obtain a permanent reference. Another possibility would be to 
prepare an RFC explaining the issues with solo PQ. As stated in its web 
site (https://www.rfc-editor.org/authors/rfc-independent-submissions/) 
the Independent Stream covers a number of classes of submissions, 
including discussions of technologies, ... and critiques of the IETF 
process, so I think that would be an appropriate venue. There are also 
examples of such documents in the IETF stream like RFC 8900 (IP 
Fragmentation Considered Fragile), or in the IAB stream like RFC 4840 
(Multiple Encapsulation Methods Considered Harmful), but doing that will 
require consensus within a working group or within the IAB, which may 
delay the publication for some time.

-- Christian Huitema