[TLS] Re: Fwd: New Version Notification for draft-sheffer-tls-pqc-continuity-02.txt

Ilari Liusvaara <ilariliusvaara@welho.com> Tue, 09 June 2026 16:56 UTC

Return-Path: <ilariliusvaara@welho.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 9F49CFE2C035 for <tls@mail2.ietf.org>; Tue, 9 Jun 2026 09:56:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1781024211; bh=jI+/gSuSe2iU+P+nI+hoFLKhmtDMVjFPIAs/MIJQ+PA=; h=Date:From:To:Subject:References:In-Reply-To; b=bTA7pHG0X2Jpniaacdg3VzJAXMhaYct0jAho9TFK6Vza6Hj+OP2lJnhczArJYftBj fXbeoJs3Nj7OkEmvcfcYsE0eHjTQn+lLswUSN0CupFOYIm/4AyXeyF8Muringw7Xwj jjC3pHisO8F1BwIS68fwBUh2oDNOdwBslzyY8FgY=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=welho.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lFkpis-9OIZ2 for <tls@mail2.ietf.org>; Tue, 9 Jun 2026 09:56:50 -0700 (PDT)
Received: from smtp.dnamail.fi (sender001.dnamail.fi [83.102.40.178]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 87FF1FE2BD4B for <tls@ietf.org>; Tue, 9 Jun 2026 09:55:51 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by smtp.dnamail.fi (Postfix) with ESMTP id 882792113903 for <tls@ietf.org>; Tue, 9 Jun 2026 19:55:44 +0300 (EEST)
X-Virus-Scanned: X-Virus-Scanned: amavis at smtp.dnamail.fi
Received: from smtp.dnamail.fi ([83.102.40.178]) by localhost (dmail-psmtp01.s.dnaip.fi [127.0.0.1]) (amavis, port 10024) with ESMTP id ZAD7MkFAFtTR for <tls@ietf.org>; Tue, 9 Jun 2026 19:55:43 +0300 (EEST)
Received: from LK-Perkele-VII2 (87-92-117-27.bb.dnainternet.fi [87.92.117.27]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: hliusvaa@dnamail.internal) by smtp.dnamail.fi (Postfix) with ESMTPSA id 8AD2B2113FD6 for <tls@ietf.org>; Tue, 9 Jun 2026 19:55:43 +0300 (EEST)
DKIM-Filter: OpenDKIM Filter v2.11.0 smtp.dnamail.fi 8AD2B2113FD6
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=welho.com; s=2025-03; t=1781024143; bh=cSthxAoREQcZeQIlZEEg3zQYsB5XkxLdwGnFVfXxtrI=; h=Date:From:To:Subject:References:In-Reply-To:From; b=kHi61iHWaPMY5R7JptYPfpP3KOc91msyIh9lLxV+lKmmJARwMbsrOEeWbxSqq4jMo qIozcZjj4buMoOXXgXIG3wOe5GNpspq71594xE9UH7Fusk9WdsUdg7zFkLtDTLArqV Mw24xOdOyHPd6nZeiH4Oh5rnVboOvGF+fxKdkbiysrdgJm6HVEDS9d4wKCa9DL8FxO emb2FFzoiHAbJpSFZVDSc9NP9y2EiALg3rJStzfDuD3z202UevlmpcKQVBUt7MvfPH 9Lky82GstckjYV2DfqPnw+JBlEph8DmGbEHBGKxFeKoN2BJUyDi5BNPJFW9cDaQamN WqFSORBFxo/9w==
Date: Tue, 09 Jun 2026 19:55:42 +0300
From: Ilari Liusvaara <ilariliusvaara@welho.com>
To: tls@ietf.org
Message-ID: <aihFjssxluLCfAKo@LK-Perkele-VII2.locald>
References: <178100161553.1166.17557928717720479639@dt-datatracker-56f887f959-hdgj4> <b38dbb8f-1369-4106-8c35-12dd7f5d4281@gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
In-Reply-To: <b38dbb8f-1369-4106-8c35-12dd7f5d4281@gmail.com>
Sender: ilariliusvaara@welho.com
Message-ID-Hash: C76JUHCW4GMOOPM5YMMT2U4GQMZYKX5S
X-Message-ID-Hash: C76JUHCW4GMOOPM5YMMT2U4GQMZYKX5S
X-MailFrom: ilariliusvaara@welho.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Fwd: New Version Notification for draft-sheffer-tls-pqc-continuity-02.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/VcQxV4qQrDvbA36mDWDnpRRBhQk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On Tue, Jun 09, 2026 at 02:09:09PM +0300, Yaron Sheffer wrote:
> This version addresses comments from an extensive discussion on this list,
> as well as our learnings from a POC implementation [1].

AFAIK, Merkle Tree Certificates (PLANTS WG) do not have any indication
in the certificate itself if those are post-quantum or not (nor does
certificate properties from TAI have this information). This might be
an issue for APs. 
 
 
> [1] https://github.com/yaronf/pqc-continuity-poc
> 
> -------- Forwarded Message --------
> Subject: 	New Version Notification for
> draft-sheffer-tls-pqc-continuity-02.txt
> Date: 	Tue, 09 Jun 2026 03:40:15 -0700
> From: 	internet-drafts@ietf.org
> To: 	Tirumaleswar Reddy.K <k.tirumaleswar_reddy@nokia.com>, Tirumaleswar
> Reddy <k.tirumaleswar_reddy@nokia.com>, Yaron Sheffer
> <yaronf.ietf@gmail.com>
> 
> 
> 
> A new version of Internet-Draft draft-sheffer-tls-pqc-continuity-02.txt has
> been successfully submitted by Yaron Sheffer and posted to the
> IETF repository.
> 
> Name: draft-sheffer-tls-pqc-continuity
> Revision: 02
> Title: PQC Continuity: Downgrade Protection for TLS Servers Migrating to PQC
> Date: 2026-06-09
> Group: Individual Submission
> Pages: 14
> URL: https://www.ietf.org/archive/id/draft-sheffer-tls-pqc-continuity-02.txt
> Status: https://datatracker.ietf.org/doc/draft-sheffer-tls-pqc-continuity/
> HTML:
> https://www.ietf.org/archive/id/draft-sheffer-tls-pqc-continuity-02.html
> HTMLized:
> https://datatracker.ietf.org/doc/html/draft-sheffer-tls-pqc-continuity
> Diff:
> https://author-tools.ietf.org/iddiff?url2=draft-sheffer-tls-pqc-continuity-02




-Ilari