[TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
"Kampanakis, Panos" <kpanos@amazon.com> Tue, 14 October 2025 15:13 UTC
Return-Path: <prvs=37560969d=kpanos@amazon.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 039BF7348B28 for <tls@mail2.ietf.org>; Tue, 14 Oct 2025 08:13:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=amazon.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vz5drKFd5gIe for <tls@mail2.ietf.org>; Tue, 14 Oct 2025 08:13:00 -0700 (PDT)
Received: from iad-out-007.esa.us-east-1.outbound.mail-perimeter.amazon.com (iad-out-007.esa.us-east-1.outbound.mail-perimeter.amazon.com [3.221.209.22]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 291A57348957 for <tls@ietf.org>; Tue, 14 Oct 2025 08:12:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazoncorp2; t=1760454774; x=1791990774; h=from:to:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version:subject; bh=bUD4Gju7sT8C7SjEmEs102cdaTQNBqx3vGmG7eOfckU=; b=KStjZ5qHn4DeJurLMliqOJ8Ya0Y5JVXZe0hTty/0i3xN0eJe4QWXWyLt T3NnhvLEYkgKeg5vUwtHKMZZ2QSdoPGy9X3ARoxiERupUZ+6sdgvVgsqM No/zKLZJJkZ+81yTbwieEuW6SA8OOl8GGtFIpelIqnC25d3Pk37zfXigm CqyTujuE3T7LUpyVgnpBd1rAVC3lwL222GSDyrGHI+lqMgF+Az9t6WXWt RW63VCh+BpVy7EEfG0aT2Z44qtenEIMJNhzLtyltxuRO0mQWpUuvnctZZ CMNi5YdjbdaR7HSQvaFvvnb6zC7uKVPoJ9XfuuT6ZOOT5Bb4WzJbDG2mO Q==;
X-CSE-ConnectionGUID: F3mqf36JSGyOa3DAEV5b1Q==
X-CSE-MsgGUID: Fjn99kBLTQG3WNNXgMf2Rw==
X-IronPort-AV: E=Sophos;i="6.18,259,1751241600"; d="scan'208";a="4478854"
Thread-Topic: [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
Received: from ip-10-4-17-41.ec2.internal (HELO smtpout.naws.us-east-1.prod.farcaster.email.amazon.dev) ([10.4.17.41]) by internal-iad-out-007.esa.us-east-1.outbound.mail-perimeter.amazon.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 14 Oct 2025 15:12:51 +0000
Received: from EX19MTAUEA002.ant.amazon.com [72.21.196.65:8003] by smtpin.naws.us-east-1.prod.farcaster.email.amazon.dev [10.0.45.233:2525] with esmtp (Farcaster) id d9841750-ce6b-4061-a8ca-8742755b1ca6; Tue, 14 Oct 2025 15:12:51 +0000 (UTC)
X-Farcaster-Flow-ID: d9841750-ce6b-4061-a8ca-8742755b1ca6
Received: from EX19EXOUEA002.ant.amazon.com (10.252.134.207) by EX19MTAUEA002.ant.amazon.com (10.252.134.9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20; Tue, 14 Oct 2025 15:12:50 +0000
Received: from EX19EXOUEA002.ant.amazon.com (10.252.134.207) by EX19EXOUEA002.ant.amazon.com (10.252.134.207) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20; Tue, 14 Oct 2025 15:12:50 +0000
Received: from SN1PR07CU001.outbound.protection.outlook.com (10.252.135.199) by EX19EXOUEA002.ant.amazon.com (10.252.134.207) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20 via Frontend Transport; Tue, 14 Oct 2025 15:12:50 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=X49JruL6Jv5qHRU8kw/ocnUQnw6byWCUX/HQG7azHJBQrupNFplyofMAyjY+fkAZDx7fqTZummdcmpc8tZUFLtgYksbbC6I8gYEjQYsEOapfcGKwSEo51FIIEO1NTlnvbXzOz0v+m8hqxlMnZE+zYQWdBkZAg0RbjO4je1QPT4Z28scWeiZ3VyqFYDlcwnPITKFp7azQKK3bOUDGO+qWAUCiCM4Jm+4FxsIPsc70wKE01Et//UJL7xgeZf3tIp+9KflnnTcFlcfW/uYwx10/U59dC2PFWs5Pr/DjfFz0lm8ZVML0YR5a3VWuThUT7ljPkc0MR71/w3GSfSc1kNj2BA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=bUD4Gju7sT8C7SjEmEs102cdaTQNBqx3vGmG7eOfckU=; b=QK6LQruJpPMrsk2AbOc/Xvb9pyBgBW2WUhs1c0xa6o7vncI8shz4BMIX83PMQUjxV7LA75wx+I0kG+CamhaVm1YaEnZSsQnuy0ey1GjWXJNAt6lKkvLhfUH8x0eEogd1y9i8JmUjfkwY2b7xoQ25Wa2DJr4Iuyi0NtC/bGCfyIEjkm0+Q1U+KR3ZZZlb3EN7sO0BhmMjW2SpRNV/JgJxBOlVsaWrrU5N77SRdaWPa5L+ZZ2Pj4NPoyEv5Sj0H1XvDoakRa1BLZYKHJkny7wuMOMtFdN9h795BhSM1VwLyAkvzO3FMDKhsdvrgznDDFBxrIpK7uji/tqbhbhmGTxbzA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amazon.com; dmarc=pass action=none header.from=amazon.com; dkim=pass header.d=amazon.com; arc=none
Received: from DM5PR18MB2326.namprd18.prod.outlook.com (2603:10b6:4:b9::33) by LV8PR18MB6345.namprd18.prod.outlook.com (2603:10b6:408:25a::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9228.10; Tue, 14 Oct 2025 15:12:46 +0000
Received: from DM5PR18MB2326.namprd18.prod.outlook.com ([fe80::6dd6:86fd:258:83be]) by DM5PR18MB2326.namprd18.prod.outlook.com ([fe80::6dd6:86fd:258:83be%4]) with mapi id 15.20.9203.009; Tue, 14 Oct 2025 15:12:44 +0000
From: "Kampanakis, Panos" <kpanos@amazon.com>
To: "D. J. Bernstein" <djb@cr.yp.to>, "tls@ietf.org" <tls@ietf.org>
Thread-Index: AQHcPGrp4MgT31sga0qMM55YGKYXp7TAo9oAgAELwWA=
Date: Tue, 14 Oct 2025 15:12:44 +0000
Message-ID: <DM5PR18MB232668BC226E074B7F3DDE7BABEBA@DM5PR18MB2326.namprd18.prod.outlook.com>
References: <aO09OHfxq02kKx71@netmeister.org> <20251013221138.350044.qmail@cr.yp.to>
In-Reply-To: <20251013221138.350044.qmail@cr.yp.to>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=amazon.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM5PR18MB2326:EE_|LV8PR18MB6345:EE_
x-ms-office365-filtering-correlation-id: f29c3f56-87eb-4574-6b1c-08de0b3420c2
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|4022899009|376014|1800799024|366016|38070700021;
x-microsoft-antispam-message-info: hx7yKo1N7jcnSfuetMMcLzjU51FJ8tzsaseY/av+grdZOlgz2fTPmzQFyGzcqzxLwvTqjTZpaO5Hv8B5Y4V30phBR8xVo5WS5XHhGKuuz7LA0cBdLAmWMs005jhj3VG5lzLs57mlwPGeuOp7mdkJIHu9KdkJXMT9a0MTTSK+bK2uDVTwo3agVQHXELQ1r+7WToKL1tt/K//vYsNsUws3hEP5cQB9dNeRAxhh/yvQ3BNPPVYUSdrAI8xWSww0ker7jriS/RKInmSZLe4K8QNl67rPBm7ae8Nfe1x3qcQ1KyZgCjAcsaD82KBMSglze2LbDkWA2fMXu789khpjVZBA3wqGOZw4zOog4T5NTBTM6foJ08mCmYc6zqKkIIjnQA24LZeL4pftSzAqP586ElteQ/xIsfjJ5GzelGM6V5l94SYCGgRxztlPk4o4rZZX3pf1yIvJMBsWXHk/TWEcR+G/Gd8Ufgi+GIftwpLMggNuj7aPpjkkWgTv+IFFH52qRBdJGuBlyGTm8Sg1hYlmlAuYj3uPDFeQ5cJ37YNOmsf4L7l2ANCX4GKZ3M0+NP9yH9eOgtE2hMpgHIrMNzEhimNmBuMn/6ZO2+kJRrN3VcQ9p+Bp66aSMcFDCnOx9/1y2N7pq7xki+arVZuvxoyk4h+VIwB70IWyBgiLhPO/O9ERSiNJ5MHuAMT1i8liFBillYTkyox2BmjOrvjumpdC2K/o8FgcCB0f4Pmj9+kj1bMMf+7YJfvJxPicayNcB90b8SOrOgpQRZz7JwGutyE173jw3lfyr29hTp/mvLqMS8+iEioaFfRKz8LgCgXfQm7qMR6MPCjqtxLLDgUyg77FveUH166Zz8gb9mtAlVVn+ACOfytDbrBWxa8LsUhhjdt/eY5zaTnghFU5wRcwYPd6eDD54pYneBlva0uqveDN0DpZf0OR3U9wTkRJGU93GckltKVbT5Cr4L1H3bFOBTSZRoJKZclRfowcMXxu6bSofLtWJf1oFGDlOnPjPmpacfRLnMUSRaWzRrno5xLqr7gg48a/zY3iFRAp189Q/1ggmT2+fI5zz8wdzu70pYP0VDq7uU1IUGL6O7nrnlpMvQgsHFiatc+JHQ+LNvSigEpkZhOeJkzARjlq2LlKadrkUHNvBt1qQbAfValkF+hle88Xqjpadlsb6TIG15F0ISUizU2SvEBYkT274HiE30oyfNwYz08cK1iu30avMVqHGZbFKMaGMcLXp3ZvcdjiT4b75FuRh+lz1uVi5bvSdjg47SQkJwXsaYyH648cSY9eOb8uoHBix5dQMhZfpVRsCEf1KG1PzsQia1tqWZLy+nFPWoWYTIuE6P+hlSVkwG2PLqnxiF0KhJ8Op+qaY7+gnGpkxswChhbqjFsouEOZGDdjO22CXVc6vVkL5/AncQuPMpcZQ1YIkXEvtjQFz4OrxtG+a1ZZ51c01U6/ZkXDeL0F+Gr16H4mJpWFpMRAGJUj72AvxrP5TQ==
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DM5PR18MB2326.namprd18.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(4022899009)(376014)(1800799024)(366016)(38070700021);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: ZXDhq9sG3gTkiBEG2sPuPKrRcxQtGXosren4csBKbNu5hHOXc729NulP+PCQLBofdfuWe5wYxqCrpT2nP/TsSmIYYev4xierLEdfyldlyEBTGKZ9atFKMKfFlXCG4zRYhoJJ0hAr2D3PwUbDgWtB0lBbG3rVIV+IeoN35cdddCP/6r/TumK+NBTZyoxJpYzQY8lpiG9MdelODnYUtQiWwCqgv04e9evciBhVL+qraTmqnP3NdOuAYlZn9aqlhFyAP8IOaxZ792ElPH3xB1ho8EDcSNFXqcdBj2YWSO7A88Uc8R5Z2WhQtPwsBt5EKOkr+vGYtPAWX0kpvWCcLObyc78SLP+vAHvn9J8Fv2VnxNfSK2blCWHBST8kkipvfZpmpbwQWXqkq5UsJEgCXXeAcQkMS6i9EPBExJ/6XMtBtg3TmLtxk+xzWZtQ64RcqTZqgZ4YrCtzg8gIKR639l91y528Z9kfcSmS4zE4zL6/Ojbkf357WKUSUKdw6UwSXRHWIt5mVVYkq7G7tQ0PJChL4hmkMKVo5oL5/zf0Rg5ENxHrlxfaz0eGVwpPvcJZXJYInNp+5XZWNvi1gh/EAW9eVWF1gvZy+VwAH1DhsZzlztCZHu4x6JLqnq3RhIET3i/d69yFulrrmMHQlvPV2jFHXSd7NT9fSGy+TB5ZnuIZyIiKMsnWmcfkNsgUsFe691Rl0vv0zyIuWR30cgbbiKtm0jaxTIh/EJ0wUMZImnyXBjX86xRmGwa6ByPgUCKoSXubg8Qi8Gwl+PHurBmkFtIgULq+KD3kPQky+n+K4ypSy+pSjDvjfuIvI48wDwC2gJefZuiGxB30fKSl4HZjgVGYq+jfPSp6Y2honXYGDAII7WZ0TFyby6n4GDprP734PZGMGmNEb42KW/n+kHIT8tg1Z0IHDOx51EnmQLKfKxV0gmimc5uhi4BnM3Yb2a3f9xhuzFO4qBwUU2149QSTJC25QNM10acQo+7chPZmGI3YHWdtneonMU3ioHjBtAQhjoQw1PWpSjzaj0/ChlOL8hM1+v++d1veVGYjitL7xpPOvc7ShsqOguuwIeWEbIKBOv7aHmj7ed1IduGORUEKVGx0diRmyNZMQ3lyH2hM20uvwSjp0q8GPvu2Q0OSRGcSpz83t3HkdfQ8Zx8BlQMRPXwmtqlwf2SofSe/83w4PGo3xpQAYthFu2Ts1X8nVkRkTrmuu2Wmh8kDaVuGOpXqMt2eT99EmYBDv798qEPP7b3wfFfaSyT6aMxb8pLPhJ2/2aJU58AVlUxsWBV3KjHoDrLARIt0mTWrCGPto0flVf7Ojcj1xqgtcI2W/b28zcGwi47EFD5X8FQf6L9QPxd2aDGrpKnk1iRaGD80I4dA/6T2tcpGZ6hK1hQS9yZ0E6x1nfRnS7UQmO3ff4w/hUshIg0InZ5mm15Nrh8F2EXeBxNThLeqAyXkkpd/OiEk+CZfx+CqIsFOuR50Bu+UdNDzi/Q3C7tqTP12gt3D7wiZ1tkfx5Xx4bfVQysna0LWSZ8Uvu8JqJk6G9SXjdJbm5S1lxy/OH2N756fOwoYTtjOfWS949E=
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM5PR18MB2326.namprd18.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: f29c3f56-87eb-4574-6b1c-08de0b3420c2
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Oct 2025 15:12:44.8746 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5280104a-472d-4538-9ccf-1e1d0efe8b1b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: k3u97LJIX2/qSz5gKH6eZk3e/qK1BHTZjHqgPiZyQ1t6Ve0SH1RPrQny8jNbFCnTQ7f27Tp1tOqkpdpoWQ3CqQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: LV8PR18MB6345
X-OriginatorOrg: amazon.com
Message-ID-Hash: P2P6PUIW3447QQL7QDB6VEOSSRB3RK4V
X-Message-ID-Hash: P2P6PUIW3447QQL7QDB6VEOSSRB3RK4V
X-MailFrom: prvs=37560969d=kpanos@amazon.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/SUnFzF0yFtj0NBgUEWlIoIDALlg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
> As for SecP256r1MLKEM768 and SecP384r1MLKEM1024 in this draft, the current status is that they're basically not supported in deployments at all. acm.us-west-1.amazonaws.com (US), secretsmanager.us-east-1.amazonaws.com (US), kms-fips.us-west-2.amazonaws.com (US FIPS), kms.eu-central-1.api.aws (Germany), kms.eu-west-2.amazonaws.com (UK), secretsmanager.ap-northeast-3.amazonaws.com (Japan), acm.ap-southeast-2.api.aws (Australia) [ and many more ] Feel free to retract your statement as inaccurate and make another one. Maybe one to the effect that the sky is falling in year 2025 with SecP256r1MLKEM768 and SecP384r1MLKEM1024 because there was some new CVE recently or many implementation security issues a long time ago. Or something like that. Reminder for the whole group: TLS is not just the web (origins, CDNs, and browsers). -----Original Message----- From: D. J. Bernstein <djb@cr.yp.to> Sent: Monday, October 13, 2025 6:12 PM To: tls@ietf.org Subject: [EXTERNAL] [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3 CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. Jan Schaumann writes: > I don't think I can follow a logic that says > X25519MLKEM768 should be recommended, but not the others (unless one > were to imply that standalone P-256 and P-384 should not be > recommended). For me, the central point is that P-256 and P-384 create neverending real-world implementation failures, such as CVE-2023-6135 in Firefox. This is an argument against standalone P-256 and P-384 as well as this draft's SecP256r1MLKEM768 and SecP384r1MLKEM1024. For standalone P-256 in particular, the current status---mandated, and according to some reports still used by 10% of TLS sessions---means that the deprecation process should be gradual, starting with announcing the plan, mandating a replacement, tracking deployment trends, etc. Standalone P-384 is easier to get rid of: it's not needed for getting data through, and it has far less usage in the first place. As for SecP256r1MLKEM768 and SecP384r1MLKEM1024 in this draft, the current status is that they're basically not supported in deployments at all. The claims that these are needed for compliance don't seem to have withstood examination. So I'm puzzled as to why they're there. ---D. J. Bernstein ===== NOTICES REGARDING IETF ===== It has come to my attention that IETF LLC believes that anyone filing a comment, objection, or appeal is engaging in a copyright giveaway by default, for example allowing IETF LLC to feed that material into AI systems for manipulation. Specifically, IETF LLC views any such material as a "Contribution", and believes that WG chairs, IESG, and other IETF LLC agents are free to modify the material "unless explicitly disallowed in the notices contained in a Contribution (in the form specified by the Legend Instructions)". I am hereby explicitly disallowing such modifications. Regarding "form", my understanding is that "Legend Instructions" currently refers to the portion of https://web.archive.org/web/20250306221446/https://trustee.ietf.org/wp-content/uploads/Corrected-TLP-5.0-legal-provsions.pdf saying that the situation that "the Contributor does not wish to allow modifications nor to allow publication as an RFC" must be expressed in the following form: "This document may not be modified, and derivative works of it may not be created, and it may not be published except as an Internet-Draft". That expression hereby applies to this message. I'm fine with redistribution of copies of this message. There are no confidentiality restrictions on this message. The issue here is with modifications, not with dissemination. For other people concerned about what IETF LLC is doing: Feel free to copy these notices into your own messages. If you're preparing text for an IETF standard, it's legitimate for IETF LLC to insist on being allowed to modify the text; but if you're just filing comments then there's no reason for this. _______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-leave@ietf.org
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Paul Wouters
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Working Group Last Call for Post-quantum Hy… Joseph Salowey
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… David Adrian
- [TLS] Re: Working Group Last Call for Post-quantu… Loganaden Velvindron
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Deirdre Connolly
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Loganaden Velvindron
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… tirumal reddy
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Andrei Popov
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Thom Wiggers
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… David Benjamin
- [TLS] Re: [External⚠️] Re: Working Group Last Cal… Yaroslav Rosomakho
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Eric Rescorla
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: Working Group Last Call for Post-quantu… Martin Thomson
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: [External] Re: Working Group Last Call … D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Filippo Valsorda
- [TLS] Re: [External] Re: Working Group Last Call … Muhammad Usama Sardar
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: [External] Re: Working Group Last Call … John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Dennis Jackson
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Stephen Farrell
- [TLS] Re: Working Group Last Call for Post-quantu… Joseph Birr-Pixton
- [TLS] Re: Working Group Last Call for Post-quantu… Robert Relyea
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Sophie Schmieg
- [TLS] Re: Working Group Last Call for Post-quantu… Christopher Patton
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Muhammad Usama Sardar
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Appeal Response to Rob Sayre - was Re: Re: … Paul Wouters
- [TLS] Re: Appeal Response to Rob Sayre - was Re: … Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Peter Gutmann
- [TLS] Re: Working Group Last Call for Post-quantu… Yaakov Stein
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Robert Relyea
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Sophie Schmieg
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Joseph Salowey