[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
Ken Kubota <tls@kenkubota.de> Sat, 11 July 2026 11:00 UTC
Return-Path: <tls@kenkubota.de>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E5B82114FDA85 for <tls@mail2.ietf.org>; Sat, 11 Jul 2026 04:00:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783767652; bh=EAnrkwfdv3W6rFf2qlshTVvDMoKJjgYGOh5VTanGX9U=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=mxMfG3vjjqx+4pgUUjbw+0OYkPsX30F8mJR758CDImE8A8If3pRpER8a/fMGAWF30 Pp17fKH8zX8CILQnb8pMVXQrC4uAtGOe6o98fHda5sVUvGtPK0pKuy5zfA6L+qHzU4 mkLvQ8K4/LBwF2kmWqTP76v6BazQ/n7xEFiE2p0I=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.788
X-Spam-Level:
X-Spam-Status: No, score=-2.788 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_PDS_SHORTFWD_URISHRT_QP=0.01] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=kenkubota.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hVNNv-1DWxLy for <tls@mail2.ietf.org>; Sat, 11 Jul 2026 04:00:49 -0700 (PDT)
Received: from plasma4.jpberlin.de (plasma4.jpberlin.de [80.241.57.33]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 84918114FDA71 for <tls@ietf.org>; Sat, 11 Jul 2026 04:00:48 -0700 (PDT)
Received: from spamfilter06.heinlein-hosting.de (spamfilter06.heinlein-hosting.de [80.241.56.125]) by plasma.jpberlin.de (Postfix) with ESMTP id 8B8AFC0827; Sat, 11 Jul 2026 13:00:38 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kenkubota.de; s=MBO0001; t=1783767638; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=+M+9b6vDrrDqkukXfFqZG7b2E2w145Uk0L88/iFzZss=; b=xTrH7v9svZ+ApZW7QDc+I97rOU/5bummuJmesgYPTgA/9iMmcNoeU3eIZbxfuA7/DmnEyS qkfsKwZCRPhEfLuBpykQUc53Ya3psYXaZshZi/fnjHiiMJXsdDz/QqZtTP0QySgyi6cgNk kHdkLyhAOzMefEnWWzvbW5MNHDEQqbfEO/yaVaYZjyxyIlr637VBSKdntbOuzMGgmekGyA nDyaxXDJW19IcJY4S170wagT6tJ7bjgykp7cCH3nin715LFF34NbSaxbtuuumAE6LfCzkh wPpRs+3H78F1W5WRuN0KJ5jx+H4Ul0vehzmBS29WWIOV1wCT3vmdFgcFMSIgeQ==
Received: from plasma.jpberlin.de ([80.241.56.68]) by spamfilter06.heinlein-hosting.de (spamfilter06.heinlein-hosting.de [80.241.56.125]) (amavisd-new, port 10030) with ESMTP id pqrDM3OGSU9q; Sat, 11 Jul 2026 13:00:35 +0200 (CEST)
Received: from smtpclient.apple (pd9e70edb.dip0.t-ipconnect.de [217.231.14.219]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) (Authenticated sender: tls@kenkubota.de) by plasma.jpberlin.de (Postfix) with ESMTPSA id 0FEEFC07DD; Sat, 11 Jul 2026 13:00:33 +0200 (CEST)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0
From: Ken Kubota <tls@kenkubota.de>
In-Reply-To: <CAGgd1Of9BhwYsB79ko=Q5mL=7bqNTTE5a0Uw-TRCKnnZ9KA7+Q@mail.gmail.com>
Date: Sat, 11 Jul 2026 13:00:23 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <0F84D0DF-272A-4CFA-888B-8FA068260A7B@kenkubota.de>
References: <MW4PR09MB94439581AA71CEFDDC98A949C3F02@MW4PR09MB9443.namprd09.prod.outlook.com> <0625D2A5-8FE3-4CD2-8B86-B313FBB4ADEE@kenkubota.de> <MW4PR09MB9443A2F386549C3E8BBED39FC3F02@MW4PR09MB9443.namprd09.prod.outlook.com> <31BBDADF-037C-4D36-9AEC-F1B8E16A9993@kenkubota.de> <CAGgd1Of9BhwYsB79ko=Q5mL=7bqNTTE5a0Uw-TRCKnnZ9KA7+Q@mail.gmail.com>
To: Deb Cooley <debcooley1@gmail.com>
Message-ID-Hash: PADJJIUH2MWSGR3MHS5F66WTNRIPYZXJ
X-Message-ID-Hash: PADJJIUH2MWSGR3MHS5F66WTNRIPYZXJ
X-MailFrom: tls@kenkubota.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "William.Layton@cyber.nsa.gov" <William.Layton=40cyber.nsa.gov@dmarc.ietf.org>, "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/UDvPmpd0jIpcFkLgoZZSWlcH6Ok>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
"I'm not sure what your point is here"
Although strong cryptography (256 bits of security) could generally have been available for every end user for the past two decades on standard consumer devices, the U.S. government is intentionally deploying, through the NSA, degraded (weakened) encryption.
RFC 9151 (2022), which provides only 192 bits of security (curve P-384), is one example.
This is contrary to RFC 8890 ("The Internet is for End Users"), which I interpret as meaning that U.S. government interests must not take precedence over those of end users (i.e., human beings, mankind). Strong cryptography (256 bits of security) should be available to everyone.
In my opinion, the warning email [1] constitutes a violation of RFC 3934 Section 2, and therefore I asked questions 1, 2, 3, and 4 in the section addressed to you [2], which you decided not to answer except for the first part of question 1, even though they could be answered with a simple "yes" or "no" (or a short sentence).
This creates the impression that the rules are applied very restrictively to some people [3], while not being applied at all to others.
"I have no obligations to them"
1. a) Please confirm that you are under neither a contractual obligation nor any legal obligation preventing you from freely disclosing information about the NSA. b) Please explain why there have been no disclosures comparable to Snowden's.
2. Edward Snowden left the NSA and publicly released the documents. a) Why did you act differently? b) Why have no documents been made public? c) How do you support Edward Snowden?
3. Do you really think that, after more than 35 years of service, such a change in mindset and professional and personal distance is credible at all? Following the Snowden disclosures in 2013, you could easily have expressed your dismay, even without disclosing documents, by leaving the NSA. You did not.
Let me note that I regard this as a legitimate conflict-of-interest debate (therefore not covered by the "impersonal" clause), resulting from the pervasive NSA activity in this working group.
Your point 2a. ("is about a draft, not about NSA") is, in my opinion, incorrect, as it is too obvious that the NSA is pursuing a hidden agenda here (in this working group / on this mailing list) with respect to the draft, making it difficult to distinguish between the draft and the NSA.
Multiple NSA employees (together with some people from the aligned so-called "defense" sector) are voting in unison in support of the draft without providing any rationale, except for one, which is little convincing (I am using very polite words here).
The background has already been highlighted by Jacob on this mailing list in the context of an NSA program: "that TLS has long been a high-value target for large-scale cryptographic exploitation. This draft is about a TLS specification that will be targeted when deployed on the Internet by the same machinery, often improved." [4]
Clearly, there is an attempt by the NSA to push through this draft here.
Everybody can see this.
Kind regards,
Ken Kubota
____________________________________________________
Ken Kubota
https://doi.org/10.4444/100
[0] https://www.rfc-editor.org/rfc/rfc8890.html
[1] https://mailarchive.ietf.org/arch/msg/tls/hBFfH4lHo-cLPNfikGfxkoV6hAY/
[2] https://mailarchive.ietf.org/arch/msg/tls/vFu5iq8gPQFByj4L0hkCEAJUR9I/
[3] https://mailarchive.ietf.org/arch/msg/tls/X8-3pmioGxFZX3T0tRsdxPWKx3I/
[4] https://mailarchive.ietf.org/arch/msg/tls/ZWTVxeh52P1LoJEHBJp_WTRsVBA/
> Am 10.07.2026 um 12:25 schrieb Deb Cooley <debcooley1@gmail.com>:
>
> I will only respond to two points (divided):
>
> 1. My warning to the list: Indeed, if a 'new participant' violates any of the stated policies, they will receive a private warning before any further action.
>
> 2a. Recusal: The topic of the working group last call is about a draft, not about NSA, I perceive no reason to recuse. I will also point out that I am retired from the US Federal Government, and I have no obligations to them, just like any other person changing companies wouldn't retain responsibilities of their previous company.
>
> 2b.The RFC 9151 was published in 2022, but in fact was completed much earlier (it had to wait for DTLS 1.3 to be published). I'm not sure what your point is here, but the RFC is a profile of (D)TLS 1.2 and 1.3 for a specific community.
>
> 2c. On the subject of general recusal for all things crypt:
> See: https://mailarchive.ietf.org/arch/msg/ssh/7KRZCX_bvZWUOG50HqDg_KVT77c/
>
> If you want a feature request (attach an archive link to an email), I suggest you contact the tools team (https://www.ietf.org/about/groups/tools/ ).
>
> Deb Cooley
> Sec AD
>
> On Thu, Jul 9, 2026 at 10:48 PM Ken Kubota <mail@kenkubota.de> wrote:
> In this message, I am responding collectively to the following emails:
> - William Layton (NSA)
> - Deb Cooley (Sec AD)
>
> Due to the high volume of traffic from this mailing list, I will create a new email address.
> I would like to mention this in advance to avoid any misunderstandings, as the new email address will be registered before the current one is removed.
>
>
>
> William Layton (NSA):
>
> On Tue, 07 July 2026 [1]:
>
> > The two independent layers is all about implementation, not cryptography. If you look at the more detailed solutions that implement two layers you'll see separate boxes with firewalls, intrusion detection, etc. placed between them. That concept is orthogonal to a discussion of multiple algorithms.
>
> My question was:
>
> > > Why the apparent change of position?
>
> > > In this PDF document, the NSA consistently requires the exact opposite: a hybrid approach (two tunnels/layers).
>
>
> 1. The concept of a (parallel) hybrid approach is to safeguard against failure of a single component. Whether the hybrid approach is applied across implementation boundaries or across cryptographic algorithms is irrelevant to the nature of the hybrid approach.
> In this case, it safeguards against any (future) compromise of ML-KEM (or weaknesses associated with it) by also using ECC.
> Therefore, the distinction between implementation and cryptography is irrelevant in this context.
>
> 2. Post-quantum algorithms are immature. RFC 9958 (Post-Quantum Cryptography for Engineers) [2] from June 2026: "the post-quantum algorithms face uncertainty about the underlying mathematics, compliance issues, unknown vulnerabilities, and hardware and software implementations that have not had sufficient maturing time to rule out traditional cryptanalytic attacks and implementation bugs."
> ECC was far better understood and studied at the time it was standardized.
> I myself found it surprising how quickly the NIST PQC standardization process took place. The subsequent cryptanalytic breaks of several algorithms, including a finalist, are therefore less surprising.
>
> 3. SIKE, a NIST finalist, was shown to be breakable in 2022, only four years ago. Under these circumstances, cutting away the second safety belt introduces unnecessary risk.
>
> 4. Moreover, contrary to the explicit recommendation of one of the authors of ML-KEM/Kyber (Peter Schwabe), the hash was removed even though it would help protect against attacks such as the NSA's Dual_EC_DRBG backdoor, which NIST was ultimately forced to remove: "Should those RNGs include the hash? Yes, of course. [...] Of course, as you stated in a another message, the RNG output may leak through all kind of other sources, but the hash in Kyber's Ecnaps is a cheap "defense-in-depth" mechanism to ensure that we don't add another source of leakage." [3]
> As the Kyber author mentions correctly, adding the hash is inexpensive, and removing it without a compelling justification raises legitimate concerns.
> Given that the NSA's contribution was never disclosed ("The FOIA results show that what NIST publicly labeled as the "Post Quantum Cryptography Team, National Institute of Standards and Technology (NIST), pqc@nist.gov" actually had more NSA members than NIST members." [4]), these circumstances warrant careful scrutiny.
>
> 5. Anything other than using a hybrid approach here is difficult to justify from a cryptographic perspective.
> This is especially true given the risks outlined above.
> For these reasons, the hybrid approach is explicitly recommended in RFC 9958 (Post-Quantum Cryptography for Engineers) Section 15.4. [5]: "Hybrid key exchange is recommended to enhance security against the HNDL attack. Additionally, hybrid signatures provide for time to react in the case of the announcement of a devastating attack against any one algorithm, while not fully abandoning traditional cryptosystems."
>
> 6. Virtually everyone else has also chosen a hybrid approach.
> Not only did OpenSSH adopt a hybrid approach by default in 2022 ("use the hybrid Streamlined NTRU Prime + x25519 key exchange method by default ("sntrup761x25519-sha512@openssh.com")" [6]), but it also adopted another hybrid scheme only a few days ago ("OpenSSH 10.4 was released on 2026-07-06. [...] add experimental support for a composite post-quantum signature scheme that combines ML-DSA 44 and Ed25519" [7]).
> Germany's NIST counterpart, the BSI, reaches the same conclusion. Technical Guideline TR-02102-2 (version 2026-01): "The BSI intends to recommend the quantum-safe hybrid key agreement mechanisms SecP256r1MLKEM768 and SecP384r1MLKEM1024 from the Internet-Draft at https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/ as soon as the corresponding RFC has been adopted." [8]
> BSI TR-02102-1 (version 2026-01): "The quantum-safe mechanisms recommended in this Technical Guideline are generally not yet trusted to the same extent as the established classical mechanisms, since they have not been as well studied with regard to side-channel resistance and implementation security. To ensure the long-term security of a key agreement, this Technical Guideline therefore recommends the use of a hybrid key agreement mechanism that combines a quantum-safe and a classical mechanism. An obvious hybridization is to perform two key agreements in parallel and to derive a combined key from the generated key material." [9]
>
>
> There are multiple significant warning signs.
>
>
> I can only respond intermittently, and lack of response, even for a longer time, does not mean endorsement. Currently, my resources are outmatched by those of the NSA.
>
>
>
> Deb Cooley (Sec AD):
>
> On Tue, 07 July 2026 15:55 UTC [10]:
>
> > This is a public warning to the entire TLS working group, in accordance with RFC 3934 Section 2 [0].
> [...]
> > *not participating in ad hominum attacks (veiled or unveiled)
> > *not sending multiple responses in quick succession
>
> On Tue, 07 July 2026 17:37 UTC [11]:
>
> > I will only engage on a couple of points:
> >
> > 1. Obviously those participants who have been contributing in good faith have nothing to worry about.
> >
> > 2. The new participants should read the rules prior to posting, this warning will help them understand what is expected.
>
> RFC 3934 Section 2 [12] explicitly states that a public warning is the second step after communicating directly with the offending individual:
> "Unless the disruptive behavior is severe enough that it must be stopped immediately, the WG chair should attempt to discourage the disruptive behavior by communicating directly with the offending individual. If the behavior persists, the WG chair should send at least one public warning on the WG mailing list."
>
> I feel it necessary to seek clarification, since the warning and the subsequent email referring to "[t]he new participants" (plural) were issued shortly after I entered the mailing list and someone accused me of an ad hominem attack, although my point clearly concerned a potential conflict of interest related to NSA activity on this mailing list, and, in that context, specific actions (or failures to act) by NSA employees [13].
>
> Andrew Lee made a point [14] with which I agree and which I would rephrase as follows: an indiscriminate warning can have an intimidating effect and therefore is detrimental to an open discussion.
> The same holds for any vagueness in the interpretation of rules.
>
> He also wrote:
> > > *not sending multiple responses in quick succession
> >
> > Participants on both sides have posted multiple messages throughout this WGLC. This standard has never previously been cited or enforced. Further, this warning starves debate during a WGLC; whether that's intentional or not doesn't matter.
>
> To avoid intimidation and ensure the fair application of the rules, all parties should strictly adhere to the RFCs and avoid any uncertainty caused by vague wording.
>
> My understanding is the following:
>
> 1. RFC 3934 Section 2 states that, in the case of disruptive behavior, the WG (working group) chair should first contact the individual directly. Ideally, the relevant passage should be quoted and the reason explained.
>
> 2. RFC 3934 Section 2 states that a public warning should be issued by the WG chair only as a second step, and the wording implies that the individual should be identified in the public warning (and also not to intimidate others).
>
> 3. RFC 3934 Section 2 states that neither individual correspondence nor a public warning should be conducted by the AD (Area Director), but by the WG chair.
>
> 4. RFC 3934 Section 2 does not state that "new participants" should be greeted with a warning message.
>
> 5. The term "contributing in good faith" is subject to interpretation, and in order to avoid intimidation, any person to be warned should be mentioned by name instead. For example, not only many researchers, but probably the majority of the world population would reasonably question whether the pervasive NSA presence in this working group qualifies as "contributing in good faith."
>
> 6. Discussions about conflict of interest related to the NSA, including their behavior on this mailing list with regard to a potential conflict of interest - as NSA employees, not as members of a specific ethnicity or some other outward property - constitute neither an ad hominem attack nor some other violation of any rule.
>
> 7. The criterion "not sending multiple responses in quick succession" is not part of any RFC, as the RFCs define criteria based on content rather than frequency (e.g., RFC 3683 Section 1 [15] mentions "unsolicited bulk e-mail" or "discussion of subjects unrelated to IETF policy" etc.). (If a numerical criterion is unavoidable, it should be exactly defined, e.g., more than two emails per hour.) I find such a vague formulation problematic, as I sometimes edit several emails in parallel, and later send them at the same time, which would formally satisfy the criterion "sending multiple responses in quick succession" although my overall email volume is no higher than that of others.
>
> 8. An AD (Area Director) who has retired from the NSA after 35+ years no less than three years ago [16] and published RFC 9151 in 2022 as an NSA employee [17] would present a conflict of interest when dealing with questions concerning the NSA, including whether a debate constitutes a legitimate discussion of a conflict of interest related to the NSA. In such a case, that AD should therefore recuse themselves in accordance with RFC 7776 Section 7 (Conflicts of Interest) [18]: "Furthermore, a conflict of interest arises if the person involved in the process of handling a harassment report is closely associated personally or through affiliation with any of the Reporter, Respondent, or Subject. / For the avoidance of doubt, recusal in this context means completely stepping out of any advisory or decision-making part of any process associated with handling a harassment report, remedy arising from a harassment report, or appeal into the handling of a harassment report. That means that a recused person has no more right to participate in or witness the process than any other person from the community in the same situation." One example of a potential conflict of interest is the publication of an RFC authored solely by an NSA employee [17]. When NSA announced Suite B Cryptography in 2005 and published the corresponding webpage in 2009 [19], the obvious strategy was to make the security levels of 128 bits of security (e.g., curve P-256) and 192 bits of security (e.g., curve P-384) publicly available as Suite B, but withhold the security level of 256 bits of security (e.g., curve P-521) as part of Suite A [19, 20, 21]. (From the beginning, only AES-256 was used to "to enhance interoperability" [22], and in August 2015, the security level of 128 bits of security was removed [23].) This may explain why RFC 9151 Section 5.1 [24] lists only curve P-384 (192 bits of security) as the sole acceptable curve without providing a rationale in Section 8 (Security Considerations) [25] for this limitation. While providing a minimum security (a lower bound) for commercial applications is a legitimate concern, establishing a limitation (an upper bound) by withholding 256 bits of security is not. RFC 8890 clearly says "The Internet is for End Users" [26], and this means strong cryptography (256 bits of security) should be available for everyone. Notably, Bernstein explicitly praises curve P-521 (256 bits of security): "To be fair I should mention that there's one standard NIST curve using a nice prime, namely 2^521−1" [27].
>
>
> Please confirm this understanding or, if you disagree, provide an explanation or clarification.
>
>
> It would be helpful if every email received from the mailing list included a permanent archive link in its signature, so that participants do not have to search the archives manually when quoting previous messages.
>
>
> Kind regards,
>
> Ken Kubota
>
> ____________________________________________________
>
> Ken Kubota
> https://doi.org/10.4444/100
>
>
>
> [1] https://mailarchive.ietf.org/arch/msg/tls/5lGA_ObJ5Z58PqIRyF8nC3Lj1Po/
>
> [2] https://www.rfc-editor.org/rfc/rfc9958.html#name-post-quantum-and-traditiona
>
> [3] https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/WFRDl8DqYQ4/m/o2XJ2YvfAwAJ
>
> [4] https://nist.pqcrypto.org/foia/highlights.html
>
> [5] https://www.rfc-editor.org/rfc/rfc9958.html#name-hybrid-key-exchange-and-sig
>
> [6] https://www.openssh.org/txt/release-9.0
>
> [7] https://www.openssh.org/txt/release-10.4
>
> [8] https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TG02102/BSI-TR-02102-2.pdf?__blob=publicationFile&v=11#page=12
>
> [9] https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TG02102/BSI-TR-02102-1.pdf?__blob=publicationFile&v=14#page=29
>
> [10] https://mailarchive.ietf.org/arch/msg/tls/hBFfH4lHo-cLPNfikGfxkoV6hAY/
>
> [11] https://mailarchive.ietf.org/arch/msg/tls/X44P3cF-H4s8kX-RzyZEeQYTkbo/
>
> [12] https://www.rfc-editor.org/rfc/rfc3934.html#section-2
>
> [13] https://mailarchive.ietf.org/arch/msg/tls/xTiYQnK8uS181kRlFe7xiFjdD20/
>
> [14] https://mailarchive.ietf.org/arch/msg/tls/LvUiinuyMPCXTFMrbeYB0aa1Iw4/
>
> [15] https://www.rfc-editor.org/rfc/rfc3683.html#section-1
>
> [16] https://datatracker.ietf.org/person/Deb%20Cooley
> "Deb Cooley
> Pronouns: she/her
>
> Retired Senior Cryptographic Vulnerability Analyst, National Security Agency Cybersecurity Directorate (NSA/CSD) with 37+ years of service in Dec 2023. Most of Deb’s career was spent as a security evaluator on many different technologies including IP encryptors, satellites, radios, and key management devices.
>
> Previously, Special Government Expert for the Department of Homeland Security, Cybersecurity and Infrastructure Security Agency’s Cyber Security Division. Previously, acme working group chair."
>
> [17] https://www.rfc-editor.org/rfc/rfc9151.html
> "Published: April 2022
> Author: D. Cooley
> NSA"
>
> "Author's Address
>
> Dorothy Cooley
> National Security Agency
> Email: decoole@nsa.gov"
>
> [18] https://www.rfc-editor.org/rfc/rfc7776.html#section-7
>
> [19] https://web.archive.org/web/20090117004931/http://www.nsa.gov/ia/programs/suiteb_cryptography/index.shtml
>
> [20] https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-56ar.pdf#page=30
>
> [21] https://csrc.nist.gov/files/pubs/fips/186-3/final/docs/fips_186-3.pdf#page=101
>
> [22] https://web.archive.org/web/20090117004931/http://www.nsa.gov/ia/programs/suiteb_cryptography/index.shtml
> "1. CNSSP-15 correctly states that 192-bit AES keys are sufficient for protecting even TOP SECRET information. However, Suite B uses only 256-bit keys to enhance interoperability."
>
> [23] https://web.archive.org/web/20150815072948/https://www.nsa.gov/ia/programs/suiteb_cryptography/index.shtml
>
> [24] https://www.rfc-editor.org/rfc/rfc9151.html#section-5.1
>
> [25] https://www.rfc-editor.org/rfc/rfc9151.html#section-8
>
> [26] https://www.ietf.org/rfc/rfc8890.html
>
> [27] https://web.archive.org/web/20260628050821/https://blog.cr.yp.to/20140323-ecdsa.html
>
>
>
> > Am 07.07.2026 um 23:54 schrieb William.Layton@cyber.nsa.gov <William.Layton=40cyber.nsa.gov@dmarc.ietf.org>:
> >
> > The two independent layers is all about implementation, not cryptography. If you look at the more detailed solutions that implement two layers you'll see separate boxes with firewalls, intrusion detection, etc. placed between them. That concept is orthogonal to a discussion of multiple algorithms.
> >
> > Get Outlook for Android
> >
> > From: Ken Kubota <mail@kenkubota.de>
> > Sent: Tuesday, July 7, 2026 5:47:51 PM
> > To: William Layton (GOV) <William.Layton@cyber.nsa.gov>
> > Cc: tls@ietf.org <tls@ietf.org>
> > Subject: Re: [TLS] WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
> >
> > Why the apparent change of position?
> >
> > In this PDF document, the NSA consistently requires the exact opposite: a hybrid approach (two tunnels/layers).
> >
> > "The security against a passive attack targeting Data in Transit
> > (DiT) across Public Black networks is provided by the layered
> > encryption of two independent tunnels (Inner and Outer)
> > using a specific selection of security protocols as instructed
> > in each CP. The two independent Encryption Components
> > provide confidentiality and high-level assurance for the
> > solution, because the adversary should never be able to
> > exploit a single cryptographic implementation to
> > compromise both tunnels.
> >
> > Two layers of Data at Rest (DAR) Commercial National Security
> > Algorithm (CNSA) encryption are employed to provide
> > confidentiality and mitigate passive attacks of stored data.
> > The DAR components are independent in a number of ways
> > to mitigate the ability of an adversary to exploit a single
> > cryptographic implementation to compromise both layers."
> >
> > This document is available at: https://web.archive.org/web/20260425180701/https://www.nsa.gov/portals/75/documents/resources/everyone/csfc/threat-prevention.pdf
> >
> > It is also still available on the NSA website.
> >
> > Originally referenced in: https://mailarchive.ietf.org/arch/msg/spasm/ytjNpbERE-YgKw-7c_w-ZRUA1Fw/
> >
> > The questions raised there remained unanswered: https://mailarchive.ietf.org/arch/msg/spasm/WJMl6inph8t8m898kcBzhpWZC0o/
> >
> > Kind regards,
> >
> > Ken Kubota
> >
> > ____________________________________________________
> >
> > Ken Kubota
> > https://doi.org/10.4444/100
> >
> >
> >
> > Am 07.07.2026 um 22:08 schrieb William.Layton@cyber.nsa.gov <William.Layton=40cyber.nsa.gov@dmarc.ietf.org>:
> >
> > I support publication.
> > Implementors will make their own decisions. This algorithm choice looks likely to be implemented in multiple places, so having clear documentation of both security considerations and technical details (as provided by the draft) is worthwhile for those who might choose to use it.
> >
> > -Bill
> > _______________________________________________
> > TLS mailing list -- tls@ietf.org
> > To unsubscribe send an email to tls-leave@ietf.org
> >
> >
> > _______________________________________________
> > TLS mailing list -- tls@ietf.org
> > To unsubscribe send an email to tls-leave@ietf.org
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
- [TLS] WG Last Call: draft-ietf-tls-mlkem-08 (Ends… Joseph Salowey via Datatracker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Russ Housley
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kampanakis, Panos
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ann Krieger
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Songbo Bu
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nathanael Ritz
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thom Wiggers
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Schäfer, Pascal
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Deirdre Connolly
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Ryan Appel
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Wang Guilin
- [TLS] Re: [External] WG Last Call: draft-ietf-tls… Michael Jones
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter C
- [TLS] Re: [EXTERNAL] WG Last Call: draft-ietf-tls… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] WG Last Call: draft-ietf-tls… Andrei Popov
- [TLS] Re: [EXTERNAL] WG Last Call: draft-ietf-tls… David Adrian
- [TLS] Re: [EXTERNAL] WG Last Call: draft-ietf-tls… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Thomson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bas Westerbaan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Thomson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Thomson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bas Westerbaan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter C
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Thomson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaroslav Rosomakho
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christopher Patton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Van Geest
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… nhgajco@uwe.nsa.gov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Apon
- [TLS] Complaints/Appeals Response (was: Re: WG La… Sean Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sean Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sean Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jan Schaumann
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… santosh.chokhani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… D. J. Bernstein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sean Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Joe Birr-Pixton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Lincoln Stoll
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jack Grigg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… steve
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jeff Hodges
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yuto Nakano
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Marc Penninga
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Antony Vennard
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bas Westerbaan
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Yaakov Stein
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Bas Westerbaan
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Yaakov Stein
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Bas Westerbaan
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Antony Vennard
- [TLS] Re: [EXTERNAL] Re: Re: WG Last Call: draft-… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Richard T. Carback III
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Richard T. Carback III
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Henrick Hellström
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… David Stainton
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Henrick Hellström
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Kris Kwiatkowski
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Flo D
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bertrand Jacquin
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Rob Sayre
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Soatok Dreamseeker
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Rob Sayre
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Rob Sayre
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Patrick Duc
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Tanja Lange
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Soatok Dreamseeker
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Peter Gutmann
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Salz, Rich
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Peter Gutmann
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter C
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Valery Smyslov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Michael P1
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaroslav Rosomakho
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Hammell, Jonathan F - [he/il]
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tim Bray
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Cooper
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wilman Lee, Vodafone
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wilman Lee, Vodafone
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wilman Lee, Vodafone
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… tirumal reddy
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eren Eroğlu
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Carlos Aguilar Melchor
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Livingood, Jason
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tony Patti
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Livingood, Jason
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tony Patti
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Livingood, Jason
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Turner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bas Westerbaan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter C
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bellebaum, Thomas
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bellebaum, Thomas
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Neuhaus
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thom Wiggers
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jan Zerebecki
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Algorithm agility (Re: Re: WG Last Call: dr… Nico Williams
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Soatok Dreamseeker
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Nico Williams
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Soatok Dreamseeker
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Nico Williams
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Soatok Dreamseeker
- [TLS] Re: Algorithm agility (Re: Re: WG Last Call… Nico Williams
- [TLS] Algorithm agility, was Re: Re: WG Last Call… Paul Wouters
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Soatok Dreamseeker
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Peter Gutmann
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Salz, Rich
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Peter Gutmann
- [TLS] Re: Algorithm agility, was Re: Re: WG Last … Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jan Zerebecki
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Erwin Hoffmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Richard Barnes
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thom Wiggers
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Jacob Appelbaum
- [TLS] Re: [EXTERNAL] Re: Re: [EXTERNAL] Re: WG La… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] Re: Re: [EXTERNAL] Re: WG La… Jacob Appelbaum
- [TLS] Re: [EXTERNAL] Re: Re: [EXTERNAL] Re: WG La… Dang, Quynh H. (Fed)
- [TLS] Re: [EXTERNAL] Re: Re: [EXTERNAL] Re: WG La… Jacob Appelbaum
- [TLS] Generation of 'm' in ML-KEM (was Re: Re: [E… David Cooper
- [TLS] Re: Generation of 'm' in ML-KEM (was Re: Re… Jacob Appelbaum
- [TLS] Re: Generation of 'm' in ML-KEM (was Re: Re… Wang Guilin
- [TLS] Re: Generation of 'm' in ML-KEM (was Re: Re… Jacob Appelbaum
- [TLS] Re: Generation of 'm' in ML-KEM (was Re: Re… Erwin Hoffmann
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Verbücheln
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sven Schäge
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Henrick Hellström
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Erwin Hoffmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Campling
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nick Sullivan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… William Whyte
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Lucas Prabel
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ilari Liusvaara
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Orr Dunkelman
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Benjamin Kaduk
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Quynh Dang
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tanja Lange
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Joseph Salowey
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wang Guilin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kevin Milner
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… BRUNGARD, DEBORAH A
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mjjenki@cyber.nsa.gov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Yee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sam
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Pretty Hot And Tasty Bits
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: [EXT] RE: Re: WG Last Call: draft-ietf-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ian Palmer
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Yaakov Stein
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Duc
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Grothoff
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Leonid Shamis
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mStar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Shane Killian
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Lauren Amsterdamer
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Willow Liquorice
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Dmitry Belyavsky
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Frieder Hannenheim
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Shane Killian
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Martin Guy
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Abhinav Gottumukkala
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Kuehne
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… michael
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Adam Firestone
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ludovic Perret
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Roland Shoemaker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Justin Schnurbusch
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Justin Schnurbusch
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mike Ounsworth
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Watson Ladd
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Marc Stibane
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Patrick Dalrymple
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrey
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nicola Lazzari
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Alexandr Burdiyan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Florian König
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Neuhaus
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mark
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tim Bray
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Neuhaus
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Filippo Valsorda
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Verbücheln
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Roald Van Glabbeek
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Charles Cazabon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Travis Burtrum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Koos
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Wessel Jacobi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Hunter
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… stellakiritoy
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… STProjects Security
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Aaron Gable
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Fe Lix
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Fe Lix
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Travis Burtrum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Sigsbee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mathieu Bilodeau
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Brian Resnik
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tony Patti
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Daniel Tams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… marios.thoma
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bartlee Anderson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… marios.thoma
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… mhalikosen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Joseph Diragi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nicola Tuveri
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Alexander Burke
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Tommy Pauly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Dan Harkins
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Levine
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Carl Wallace
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Michael StJohns
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Q Misell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Simon Josefsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Hoffman
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Charles Cazabon
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Daniel Apon
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Daniel Apon
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deirdre Connolly
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Matt G1
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Andrei Popov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Brian Resnik
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Peter Gutmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Brian Resnik
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thomas Hardjono
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Preston Maness
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Thomas Hardjono
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sofia Celi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sofia Celi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sandip Dholakia
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Stainton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Brent Zundel
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… ghostkill73
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Hook
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sven Reissmann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Motley
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jim Fenton
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Vladimir Támara Patiño
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Tehrani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mr. G
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… DA PIEVE Fabiana
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Markku-Juhani O. Saarinen
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Tehrani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Tehrani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Mark Tehrani
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: [EXTERNAL] Re: WG Last Call: draft-ietf… Andrei Popov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nadim Kobeissi
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jan Schaumann
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sophie Schmieg
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stephan Verbücheln
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kris Kwiatkowski
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David McGrew (mcgrew)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Naveen Nathan
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… scosol@scosol.org
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Salz, Rich
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Campling
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andreas Bartelt
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… DA PIEVE Fabiana
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Roger Grimes
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Chris Miller
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Dan Collins
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… William.Layton@cyber.nsa.gov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… William.Layton@cyber.nsa.gov
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Deb Cooley
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Employment or other personal history Salz, Rich
- [TLS] Re: Employment or other personal history Daniel Apon
- [TLS] Re: Employment or other personal history Sean Turner
- [TLS] Re: Employment or other personal history David Stainton
- [TLS] Re: Employment or other personal history Andrew Campling
- [TLS] Re: Employment or other personal history Stephen Farrell
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Ken Kubota
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stange, Miyana
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Gessel
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Paul Wouters
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Scott Fluhrer (sfluhrer)
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Benjamin Kaduk
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Benjamin
- [TLS] Generation of 'm' in ML-KEM (was Re: Re: WG… David Cooper
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… David Gessel
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Viktor Dukhovni
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Kai Page
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sam
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Bruno Henc
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Sam Smith
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Josh Cepek
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… BARNETT Anthony
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Rob Sayre
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… PEIRANI-MERCELOT Beatrice
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… BARNETT Anthony
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… James
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Harry Halpin
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Roger Grimes
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Andrew Lee
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Soatok Dreamseeker
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eric Rescorla
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Stern, Morgan B
- [TLS] Re: [EXT] Re: WG Last Call: draft-ietf-tls-… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Muhammad Usama Sardar
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Christian Huitema
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Eliot Lear
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Nico Williams
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Jacob Appelbaum
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… John Mattsson
- [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (… Orr Dunkelman