[TLS] Re: Deployability of DTLS 1.3, HRR, and MLKEM512X25519
Marco Oliverio <marco@wolfssl.com> Mon, 31 August 2026 11:53 UTC
Return-Path: <marco@wolfssl.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6A94A1322F3A3 for <tls@mail2.ietf.org>; Mon, 31 Aug 2026 04:53:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788177195; bh=M11UfFxa6KHT5/UVr0ecY5VeVuRgUDcjYkYmmvbHg/g=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=tfnU1pHRrQIobyylarLxFkPy+iw6f6sZwfduEtrNcCs5r8Dq7px3OmfMPo429zYlG DkMcbrTaVrv0zK1aZWPRkIM7bwoK4rt9ejq42pebFnPoiCKdFjvI+K2WRGV+Ac/PsH lqZZFAR78hdUECKxmC3IU8Yrb7jZrZIBvzuj+auo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=wolfssl-com.20251104.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cfvTYnTnrQg1 for <tls@mail2.ietf.org>; Mon, 31 Aug 2026 04:53:14 -0700 (PDT)
Received: from mail-oa1-x2e.google.com (mail-oa1-x2e.google.com [IPv6:2001:4860:4864:20::2e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 97FBD1322F39C for <tls@ietf.org>; Mon, 31 Aug 2026 04:53:14 -0700 (PDT)
Received: by mail-oa1-x2e.google.com with SMTP id 586e51a60fabf-4472500e25fso1346186fac.1 for <tls@ietf.org>; Mon, 31 Aug 2026 04:53:14 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1788177188; cv=none; d=google.com; s=arc-20260327; b=VFsrsLZ4PqfietnIaYiZ0EsixQnL58w0V8nbWotD23Erv/tnIIukraathiElXJqEKQ yD0RzIGQhYQCcp77zg0vwrzPTf+Xg0ADckR6md7/bak0tblf/Ec6i2cH0czg9jlceXvJ dxbLoJb4OftEa5tuyR2bQihztN+bDEqtJK0hO6NFxmM0EJdefGTeOw1yCvMbHn9BTs/l yex1hUZ+RyYGUSE7HO0vIOwvQBS7DHDhEvavJE0km4kkY6rOQyh7R4FYRks0Xk6dQAyr YvDpMzQHqi60ZXpncw2owf7IShpGxCN8P3ymsa31oYzKJTVv/wUNwuXLjHVVyUkB5PMr qcPQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=cJfm2pwScwzyJ7KzoKI1GwBhjSVJR6kA9uvvfqaCEC4=; fh=ArqDbyx3420glejuUWlZs3c3AEPm39ANS3In/CmvwEU=; b=apx5Xf5VDV8IEWp5OVG3rDB0FmbLO2A5obkMmTksaQMephXQXQY/4zvJEzKbvMwf7X zSnaCN8i5WA5LtFNft6TFNcYWy1BxwhHLCAfIAwTM3jmaP5aa2zLeNKyV3/AeXCbZzg8 Pu2Ib38MluqCbZzJxx8qSZ25ypplvo8n0l5ZCJxJ1gOiJjng6sg/EJeezrgqMpW30Lsq ONIS1/+/dxzwXDzgIrivBiURZlJyXmqK6moVBWET3jPJMyiKMy3zWI6YKcMNXlCi/mA0 PJ+s2cUlEf+mvGuRtat3uoIE22PXkwMOBaUxwUmfHtaet3Fw40cZsk9/h0lrpL3E/yEX r/vA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wolfssl-com.20251104.gappssmtp.com; s=20251104; t=1788177188; x=1788781988; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=cJfm2pwScwzyJ7KzoKI1GwBhjSVJR6kA9uvvfqaCEC4=; b=r4w6TwhodNZPI1pO/Pq/qripSS6uwhl9+DB0uGH67Iy4P6FxRCQ4jGTi+lYVg/QH9x rR2w27bGsgmwwyPq85Pj+busoENLlux3cVnFcgwDL4wVvCHIpLiaGF18K6iAiD19HRAF pjKoI8CZjWI0UdKUsIvBU0TTTLcgd97Lf/UVS+WkaiHkQaezc+MX8FO4sfl7/b8FN82V 96vaP3Jk91qLDe4UeW6CgTLxBCYw1SmcqTH1zmQEx/s60NrA7igpg5BLhcLTUDXAJ92f EbqI1AV98hi8w5N2+qJ7PYXbAbK2C6+hPbR0y6vvJzVXoWtbJL/O3uuIWhL6plexYpiX DK2g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788177188; x=1788781988; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=cJfm2pwScwzyJ7KzoKI1GwBhjSVJR6kA9uvvfqaCEC4=; b=QqMeqXSdJcu/a17HpbI3dZoHgkmpBX98qcxvXscHhzlGuSZrirlWFPvZUhPafYlUgU oTiIZbFo8j9xrwdJIEsWBI3oc4emCKNzMViMoRasTHN1+OomT/EDYV7zsk5ZW52vku2z q+92yJssSrqJsefTPdQ+BpwAT1NGQUeDv5Zma1r0PHitLhJ3UjD/AdnmmmM2umzhKrN7 YsJNxHek2AG/7J/+PbEzEWORX83eGaHyEeiKR1hQn1GL7KPxusjVXrQq+dBYP134laXD vX+eErGN3s0dPjzgqhwRjaaP9N6Gk9L/qtdKs1IqvK/dZrrR2xtv6ol4XDpTcOsWGv9A FdOg==
X-Gm-Message-State: AFuF++mU6A8xGx2BTo/EQHDDUqpG++KJcix0n7jNbZwRWH3FRZLQfQ5f cmhItf1p30FAR50SXShatU0bsEAiakqql2albFBo3VOlossOZFBPmqfQ4owKsDXk+xqNx12QQBG /fV2TYeX7dfIiiQmdcmDPt+8GsLFS/jcOOlFCaCCcBykPnRj7Jmq7Ins=
X-Gm-Gg: AR+sD12We+3JK/VyRB5riqDrGit988g7Y73AaKL4/5Ezz4lttwwWvyyH0EN+flW/aEY XZQm36QShQTyD61kw3eZOiqciAmHffUYO8LZEkuExIyKyEM8CAvSnL/5/MNVshitdIbz12NtrfB v9HVZWJvz78yePe4WOGcnqYvqZTIibJNtqERyVglUBs77gj5HdkazC95A8NwTN87SQWpiE0U2bk Q9judC1LSzq65ZPDLrFw7S5zqcU1lAyzI4jc1RpGcVN4CdejEjfjga3T50J+RiA9lxqhguanCzD 0/jjPyYaQnHj3O08cXUizhiL3A2jvBz8Tp+0jLhdecZ7t3CzlCF6eBpUyuLNpDZbgaJT6Dxga3o eo/CdZASSRx2SI0RN+zREODL8TLp4Dkc8cA==
X-Received: by 2002:a05:6808:180e:b0:492:9e13:d5a7 with SMTP id 5614622812f47-4b39802d87emr26860726b6e.6.1788177187855; Mon, 31 Aug 2026 04:53:07 -0700 (PDT)
MIME-Version: 1.0
References: <AS4PR07MB882587C4F9F2AE3F9447B25189A92@AS4PR07MB8825.eurprd07.prod.outlook.com> <11c93a79-05e5-4323-b7a4-8a521f4d2f4f@app.fastmail.com>
In-Reply-To: <11c93a79-05e5-4323-b7a4-8a521f4d2f4f@app.fastmail.com>
From: Marco Oliverio <marco@wolfssl.com>
Date: Mon, 31 Aug 2026 13:52:56 +0200
X-Gm-Features: AcwNN1UxAW7_jKG_oih4s4-CvrdVJO4LlHy6auzSFeJvBbULWOIxJ3nm8_8_l7Y
Message-ID: <CAEGZyHV-8mwAyhMOwuqpLE53G0c1UnhpPMPHBq2vt132zcPutg@mail.gmail.com>
To: Martin Thomson <mt@lowentropy.net>
Content-Type: multipart/alternative; boundary="00000000000013f420065a5672a8"
Message-ID-Hash: QBFWQVCSYIZELYUHDE27GXRHSJBYVLBZ
X-Message-ID-Hash: QBFWQVCSYIZELYUHDE27GXRHSJBYVLBZ
X-MailFrom: marco@wolfssl.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Deployability of DTLS 1.3, HRR, and MLKEM512X25519
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/SSpPI5bGCk0CbkUKbppexxvi-aw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Hi, Clients sending ClientHello messages larger than MTUs (because of PQ keys) can't be serviced statelessly while the client's return-routability is not asserted. The problem was discussed here: https://mailarchive.ietf.org/arch/browse/tls/?q=draft-ietf-tls-rfc9147bis wolfSSL defaults to sidestepping the problem by requiring a non-fragmented first ClientHello, this breaks interoperability. wolfSSL can disable these requirements (as NSS does), trading off DoS protection for strict RFC adherence. wolfSSL is actively working on improving interoperability support and testing. Regards, Marco On Mon, Aug 31, 2026 at 12:58 PM Martin Thomson <mt@lowentropy.net> wrote: > Have you tested NSS? We've had that deployed for a pretty long time now > in Firefox and - aside from some early problems - we haven't seen problems, > including with HRR. > > We have no plans to implement ML-KEM-512, in either form. Our early > estimates showed that it doesn't always fit in an MTU when other TLS > ClientHello overheads are considered, so I'm not sure if it really saves > much. And if HRR is as broken as you suggest, that leaves a serious risk > of ecosystem fragmentation. > > On Mon, Aug 31, 2026, at 12:38, John Mattsson wrote: > > Hi, > > > > We frequently conduct interoperability testing using our internal test > > suite, CipherSnake. We recently expanded the test suite to cover DTLS > > 1.3 and HelloRetryRequest (HRR). > > > > * DTLS 1.3 appears essentially undeployable in its current state. As > > far as I know, BoringSSL and wolfSSL are currently the only libraries > > claiming support for RFC 9147, and in our tests they do not > > interoperate. I assume we will have to wait for RFC 9147bis and > > subsequent implementation work before DTLS 1.3 can realistically be > > deployed. > > > > * Relying on HRR for middlebox traversal of large ClientHellos is > > questionable. When discussing the need for ML-KEM-512, several people > > argued that it was unnecessary because HRR could be used instead. > > However, after testing HRR interoperability across 11 TLS libraries, > > our conclusion is that several libraries do not interoperate, making > > reliance on HRR problematic. It is therefore good to see that > > MLKEM512X25519 has recently been registered, although future library > > support remains uncertain. In contrast, support for standalone > > ML-KEM-512 appears to be good. > > > > Cheers, > > John Preuß Mattsson > > _______________________________________________ > > TLS mailing list -- tls@ietf.org > > To unsubscribe send an email to tls-leave@ietf.org > > _______________________________________________ > TLS mailing list -- tls@ietf.org > To unsubscribe send an email to tls-leave@ietf.org >
- [TLS] Deployability of DTLS 1.3, HRR, and MLKEM51… John Mattsson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Martin Thomson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Marco Oliverio
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Martin Thomson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… John Mattsson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Frederik Wedel-Heinen
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Ryan Hooper (ryhooper)
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… John Mattsson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… Martin Thomson
- [TLS] Re: Deployability of DTLS 1.3, HRR, and MLK… David Benjamin