[TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3

Tim Hollebeek <tim.hollebeek@digicert.com> Wed, 06 May 2026 14:41 UTC

Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id B2DAAE9F3B5C for <tls@mail2.ietf.org>; Wed, 6 May 2026 07:41:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1778078512; bh=7azWJMameo6QiGjoSza6SRZW/chZ1o+0VUIvy6rkI2k=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=b7azXaJ2JRq3ks5stmEO2a1xykMpM75w7LZLcjwfT8Dnnfg2YXPEIP1FqraK+LHqW HQaH6xRGyVrBKJjyR18WFRooBgYHFThXPpTi+zFPHKE7F1IQHvVwPEfbAaoUpkfUo6 VtcIQu5oxEuIk+vKnUA05BsD9/JlpwpxhOLoQ2Uc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: 0.003
X-Spam-Level:
X-Spam-Status: No, score=0.003 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, PDS_OTHER_BAD_TLD=1.999, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_NONE=0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=digicert.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Qea6mmkMzpa5 for <tls@mail2.ietf.org>; Wed, 6 May 2026 07:41:49 -0700 (PDT)
Received: from CO1PR03CU002.outbound.protection.outlook.com (mail-westus2azon11020136.outbound.protection.outlook.com [52.101.46.136]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D6DC2E9F3836 for <tls@ietf.org>; Wed, 6 May 2026 07:41:37 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=FttvhDAdQ4hx9+3ChJBR3j3kYXcrx3NoOp7OqMaPwby9vk7VGFZnfpwOVj/bUoNuOKgoEE/pjpOc/PffG4bpwo3SyE4hpD4AYvjzylO7dpn3izozwSZJ+u5ig4kQKLZrKRtPT2HLTlxJSDLykMdK2rLpkyM61pJhgMy3rxQ0sHo29VmYz3oPDJtLq2Q5m0ef4/jqj8k94zoo46AhieQjLZz8Aaq9Vrpu+AEILGT72CFMCx7/x9grLjOnmMarBY3Xei4uqA/OT2eDoy3MzDZO5v2kk/SdmpPYvhaDs182kRL7UlafCQ7H6H1tw/FYqYY9fUqfUirckZEy7e03GWwlfQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=7azWJMameo6QiGjoSza6SRZW/chZ1o+0VUIvy6rkI2k=; b=db3vP0mT3wyKmAAK4RLDG5UVr/dMobwfN+7ux0+hKRJbD6UbaCueW/J2kAS9ly6FAGvsGzqCdFtJ2ggIUXJedJ2MfyHgSPXi18aVzahm1X8AZoYkdFu4qUqOtYNFBJJ6XBTN/fZktLHCH2z8IW9QwniaKsV0JE8WdpmEkPzEMq+46+5tTTKaXLcsmpRZp+NGALaBL8tEZOdpev9X8EALJ84prXkj90OFOiqqXWqony3QiIdlcZ3Dbfi5G8001L9jnyPa6B75lj9ht5/I3Vv/43OUVf54pMwztpZacai6H1BdwhXGTGK+iRhlf9sRnbNJI67YnFSnDS/PM4kruLqVzg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=digicert.com; dmarc=pass action=none header.from=digicert.com; dkim=pass header.d=digicert.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7azWJMameo6QiGjoSza6SRZW/chZ1o+0VUIvy6rkI2k=; b=Xw/arfE0ZPDE9JUU0k7dYkX23BDXwknMuOOFraTtUcJl+/s6oN/UgUwVRLsUKF2MUzGMBAv1puUTi7aEddLxuWmJ168VVLvK3hn52yzllghU5Oq08h1G4ghOj4DvppBr/nQRQIB+tV5siXrjlWz+4xSOb9uviXYV43+jg/qeziYNUmO+cLOAIhtkir/FXKYFNH+qkx/DNdPdKW4d033FFB+PON3PIrb/zXh3aUn6Q5eN6zVGCf0ARGE/a8hnu9u2dZP/52UV/bBuQp9IMWaP9QF+STBN9Gt1QoeJGvaG1q3R9XFhZ89Jbv3sEroSADJISPH6zu6/O0IK1yxkU1jX5Q==
Received: from SN7PR14MB6492.namprd14.prod.outlook.com (2603:10b6:806:328::17) by DS0PR14MB7760.namprd14.prod.outlook.com (2603:10b6:8:293::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9891.15; Wed, 6 May 2026 14:41:29 +0000
Received: from SN7PR14MB6492.namprd14.prod.outlook.com ([fe80::e9cb:cd7b:d129:34e3]) by SN7PR14MB6492.namprd14.prod.outlook.com ([fe80::e9cb:cd7b:d129:34e3%6]) with mapi id 15.20.9891.008; Wed, 6 May 2026 14:41:29 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, David Benjamin <davidben@chromium.org>, Sean Turner <sean@sn3rd.com>
Thread-Topic: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
Thread-Index: AQHc3WV38AxRgCphJkmF0laji41srbYBEVa2
Date: Wed, 06 May 2026 14:41:29 +0000
Message-ID: <SN7PR14MB649251F88FCDAECCCB57160C833F2@SN7PR14MB6492.namprd14.prod.outlook.com>
References: <AS4PR07MB8825B35E02C4A5F0BDEAB4EE893F2@AS4PR07MB8825.eurprd07.prod.outlook.com>
In-Reply-To: <AS4PR07MB8825B35E02C4A5F0BDEAB4EE893F2@AS4PR07MB8825.eurprd07.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=digicert.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SN7PR14MB6492:EE_|DS0PR14MB7760:EE_
x-ms-office365-filtering-correlation-id: 433a400d-c8d0-42e4-ff0f-08deab7d8f26
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|4022899009|1800799024|366016|376014|38070700021|13003099007|22082099003|56012099003|18002099003|8096899003;
x-microsoft-antispam-message-info: l9RVlX9l9WV3SiIsF6DeCzyKSVAwd2wajhzAmue4svB7RJD2SKzSHfyso3xWWCenrlIEW5MDU361dXAzJuaY2p4zAbawoUcF6SBVel8beYBtKc05ygayP1E/foNcbJ3e48WaVQ188Hf7bKefI/WaEZ4rPIk+SD3DLXcyIlQANzyazYFkgowVby7EDP62eULyPd02Aaju2QrtY3WXobc+RnZTBstHMAmF0GxO6Pe/l/qDRa69uuoWb6xvGqtMIqyx2Bka3M6/F7Px6C6WzraukN/Pr0FyKdzPuxg+7689dp48Y6mYNwKHBlID2N3Nv7VxF/HXoHiDnpYFyA3V+YCkLth4Vw/eCkj9tVagVIYLiVOBHE2ikIkf63IVXwKV6sml2TuNp9MtTcFAg37DdGLBllt5uztmxqFtLmBtgTcHGHOr5tkyuBVrvmIkaJOP0sYdf4MJex5oLmGDAO9j4wtU2aLdAoUQO1IRl4LdC5K8goqg4hWDmVPuEBKIvBuh8PDDPb6NNNZLXZEsKCbcv7cQYKawKvhKFKUQjGmOY4nE1BoP6p3IOEopcFe0RdDQrs9hFMaPePew85jYbzZDUbFuKHLeYcjg7AdLmeKiVCbxg8ir+j53xbGRLJFqfnG5qUKR1mOVR8Ca4ri41xCfpXyYvZoWckqrv0Av5XCrDzPgE00NWrLYJpz+/PFY+NZTu+deOfptXP2383u3l7bOmJ40jRYqMjuhNueyWKoUPdsTecVTraTT9TXH8bUuDixcj252
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SN7PR14MB6492.namprd14.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(4022899009)(1800799024)(366016)(376014)(38070700021)(13003099007)(22082099003)(56012099003)(18002099003)(8096899003);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: sQMKb7gYxQEWI8ABxeHDwVQvxkf9caj+5YlT5v3HFr0/9grJJOieNOTuvTPKWS6OX80htrkgh7KImNzYr9rQhJ1LXknuH3xJUwxaR+7oLB1htnid53yOarjfmODYW1Eu+hLfz0MiapBILYi+WC7tJZ9ebJd0w624KjhpG3tEe7dSXNe0Og9wX3VktSV6L+M/zKOVcWtRmal6FYJNd8tAy1E9fhZ72hA8NfgA4nMBKF9sij5Vs/Qw1O1AaMSkmRknTdTkv9r53/829tZeVCAiFX27gGdBo4XF+3DeMdhHiTvZPa82gr8BFlACaqU2DbP6Bhi4rJADTsya95X2w2bEF5xeIDSWNvzHR5YTZdu2oppP0MlepgfY4a71KmUHVM1HmwUZCuoSBLpc0yg0wLLWWSHtvKNuyReLsULdtOFMMBzuZRH2z7aLOCXFQpm9EpY5UsGBsOHeLCF6Un25tRQIEBBeZtDmcTyN2JRK7cyZhvfzTd9yd78OG1gIa7ZdRbiYWcS5Z2x6JVzJfgtwjWo78VCT4BomjMZ6HaUXVRHBcumS32GZ/51NiuTcHL+uR1M6YufZOZnqdZvz/aXU0nTlB8TYi8xMo1fpV4Y4ohMeNSTic/6UBVH+ZK3hoRxMRNwpHqS1xdoZ+mCHwAw5P2gvkSqQzlV/5PozEVKDoVesZ1FF0mWbg5tgB2NKVEi2Tz8MU2nJiyYrzi5B2+nh0rz7QpPxV0KlcYIwiG8+hHIPXCv+s8O5HLuGHcyZG3YAx3WN+2RFbWWEYWrEcJNAibEaYROAHIJCENv9dJ9tCf+PYUK/8HGD/mAWau21n4jhNKXdBNJ4bUZuEOfU3JtFaiJBs9x4L5LEU07vat9eOrM3Hpxt/ogHqYhLIKYHWrd0ccRPPVE8RzpqPV4cfEs8gCo4qpSPIXUIzwa0MdocIcJnN1fuwZ1oC1rFUOWigBVmRPtkTIhArV+JYZll18OUK5RA9hxLJpkO74ZYHtr1ypUcznHORQpoqo7EC4ylCPyaM2uXxB/tZFHqoAUl0cyVyl1NClAw9I+BCIurztF5XEg4NPIBOcZeN3jl8aegJXUzhEbP+vkni/D03K/nxCRz1UnHqT9zsjkpHieuOmXrkK1H6BcatWYD6yik9014eSWpD7qgmUwHu5Knn+wRRqFQBP/4nrvFIZJROMkgiqa5shOv+TFCq7V06fZQOLJCvfUqhumecIL3EerFvOVMwlrLQ6FFWTLK8MHmXI04aviSAkAdz8r+D868c14nikOlTTn1uvlTIDUgeCZ5CzEpyhvlg8svAJvZyxjMnK6vzSBxv2m/xCefshcVnJjh8VD3fznCOYNcnYS3LxQgcqFccRgj5XrTvfULvLtPRn5fKvo1R+i+96VTzPVB1+UFjJ4eISRJpPbhWDMNiRoV9BDivXPHh5QgEUURXqx2adXP2PHL8Sz7cIqMdJdGnuODThfBnNJqweRcgi5IfXgOE4ypg+sB5gMGTbEnp/XRfS44AtjyDgXNF8H8/pQNbHl4w1aEGOpAX6kECDn4sRHYWR5/GJtRSrNd/M7wCTOnCRvNIYXSoX/SKznkzFhSia3Yu6Tt+d8Uara8Udar1MQ11URZjJt4Nuk6VIC4KMyKGaIf8IzsxK03kEedoCpk1DIRTcFp1H8xkvCuR9aVdVlMtacaxjvVxOzPhqWzTQuzcvJuPAJMydueNeH06HKAY2QL8SQFaz3YtbgJ+oRU5+ClbF3K7JB1IDNL5w==
Content-Type: multipart/alternative; boundary="_000_SN7PR14MB649251F88FCDAECCCB57160C833F2SN7PR14MB6492namp_"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SN7PR14MB6492.namprd14.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 433a400d-c8d0-42e4-ff0f-08deab7d8f26
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 May 2026 14:41:29.3649 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: uCekG1Rc9q96aNUHw2IAcrG37bxiynHraVoST8e8oiWDvE/mLZcmmqCUjpS5OwNm/xto7iB50OJA/U5ormH8VPWVbhSVTgO4Iu33Z0zBPQM=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS0PR14MB7760
Message-ID-Hash: 36V5AUPAPZV3W62PAO5UU4GP3P7POPDT
X-Message-ID-Hash: 36V5AUPAPZV3W62PAO5UU4GP3P7POPDT
X-MailFrom: tim.hollebeek@digicert.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/Vh9oaVkrvSF2Rn6C9fUHH8T-1IM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Thanks Deirdre, Joe, and Sean for all your hard work, and being willing to serve in roles that might be a strong contender for hardest chair role at IETF.

-Tim
________________________________
From: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>
Sent: Wednesday, May 6, 2026 10:36 AM
To: David Benjamin <davidben@chromium.org>; Sean Turner <sean@sn3rd.com>
Cc: TLS List <tls@ietf.org>
Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3

Agree, thanks Deirdre, Joe, and Sean for your hard work and leadership!

From: David Benjamin <davidben@chromium.org>
Date: Wednesday, 6 May 2026 at 15:20
To: Sean Turner <sean@sn3rd.com>
Cc: TLS List <tls@ietf.org>
Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3

--

Thanks, Deirdre, Joe, and Sean, for all your hard work in navigating these WG discussions!

On Wed, May 6, 2026 at 9:09 AM Sean Turner <sean@sn3rd.com<mailto:sean@sn3rd.com>> wrote:

Replying to the original consensus call message.


RFC 2418 Section 3.3 lays out the criteria for “rough consensus”:


   Working groups make decisions through a "rough consensus" process.

   IETF consensus does not require that all participants agree although

   this is, of course, preferred.  In general, the dominant view of the

   working group shall prevail.  (However, it must be noted that

   "dominance" is not to be determined on the basis of volume or

   persistence, but rather a more general sense of agreement.) Consensus

   can be determined by a show of hands, humming, or any other means on

   which the WG agrees (by rough consensus, of course).  Note that 51%

   of the working group does not qualify as "rough consensus" and 99% is

   better than rough.  It is up to the Chair to determine if rough

   consensus has been reached.


In this case, during WGLC there was an almost 4:1 ratio for progressing this draft, which we judge fits within the numeric “more than 51% and less than 99%” range suggested by this text for “rough consensus” and represents the “dominant view of the working group”.


In assessing rough consensus, we also considered the nature of the objections. In reviewing the list traffic, the majority of objections related to the status of pure MLDSA versus composite MLDSA-ECC, including (1) we should not publish a pure MLDSA specification at all; (2) we should recommend composites over pure MLDSA; (3) we should publish the composite and pure MLDSA specifications concurrently. While there was substantial disagreement on these points, we believe that the discussion on-list sufficiently aired the respective points of view and that the right approach is fundamentally a judgement call based on weighing various technical factors, which each WG participant needs to make for themselves. We see no reason to believe that participants were not able to make informed judgements.


Conclusion: The chairs believe there is consensus to proceed with publication of this draft as an RFC with Recommended=N for those people that want to use this algorithm, and a future Standards Action will be needed to make a change to Recommended=Y, if anyone has the willingness to undergo this heated discussion again.

For transparency purposes, the chairs note that we received a complaint/appeal about the consensus call. The message was moderated due to a previous notice of moderation; see [1], and the complaint/appeal contains a derivative work notice. As a result, the message was not sent to the mail list and we will not process the complaint/appeal as-is. If the message is resubmitted without the notice, the message can be posted to the mail list and we will process the complaint/appeal.

The Chairs,
Deirdre, Joe, and Sean

[1] https://mailarchive.ietf.org/arch/msg/tls/no0lW8r_wIPGF1ZXWB3EaGywh9Q/<https://url.avanan.click/v2/r01/___https://mailarchive.ietf.org/arch/msg/tls/no0lW8r_wIPGF1ZXWB3EaGywh9Q/___.YXAzOmRpZ2ljZXJ0OmE6bzo1MDE2ZjM5NjQ0Y2E5M2ViODdhMjQxNDFmYjMxNDFhMjo3OjUxNGE6OTkyYmQzYjEzMmY0YmM1MjY4NDg2ZTMyYmExYjhlZjNhMGE3YzA3N2QzZjRiOGE3NTc4MTk5YzY5Yjc5NTMzMzpoOlQ6Rg>

On Apr 28, 2026, at 16:24, Sean Turner <sean@sn3rd.com<mailto:sean@sn3rd.com>> wrote:

Hi! The chairs have judged that there is consensus to progress this I-D. We will work with the authors to get a new version submitted and we will get to work on the Shepherd Write-Up.

The Chairs,
Deirdre, Joe, and Sean

On Apr 9, 2026, at 15:30, Sean Turner <sean@sn3rd.com<mailto:sean@sn3rd.com>> wrote:

This is the working group last call for Use of ML-DSA in TLS 1.3. Please review draft-ietf-tls-mldsa [1] and reply to this thread indicating if you think it is ready for publication or not. If you do not think it is ready please indicate why. This call will end on April 23, 2026.

REMINDER: If you have not done so recently, review the TLS WG's Mail List Procedures; see [2].

The Chairs,
Deirdre, Joe, and Sean

[1] https://datatracker.ietf.org/doc/draft-ietf-tls-mldsa/<https://url.avanan.click/v2/r01/___https://datatracker.ietf.org/doc/draft-ietf-tls-mldsa/___.YXAzOmRpZ2ljZXJ0OmE6bzo1MDE2ZjM5NjQ0Y2E5M2ViODdhMjQxNDFmYjMxNDFhMjo3OjY1NDg6NzljOWU4ZmYxZDhiMWI4ODQ0MDEwNTk2MzVhOTdmZGQ0Y2VlMTk5ZWQ3NzgzYmFmMWU0NDU1YjdhNzIzNjVjYjpoOlQ6Rg>
[2] https://mailarchive.ietf.org/arch/msg/tls/ucdImHExlbOf4Q3BCG81gjzi2xE/<https://url.avanan.click/v2/r01/___https://mailarchive.ietf.org/arch/msg/tls/ucdImHExlbOf4Q3BCG81gjzi2xE/___.YXAzOmRpZ2ljZXJ0OmE6bzo1MDE2ZjM5NjQ0Y2E5M2ViODdhMjQxNDFmYjMxNDFhMjo3OjhlNGE6Zjc2ZTk4ZDc2MTZjZTg4NDdkNjJiNTNlOTBmMWI1ZmU0YzZmNDAwZTVmNGM4YjczNWM1YjM0YTQ4NmZjNjVlYzpoOlQ6Rg>


_______________________________________________
TLS mailing list -- tls@ietf.org<mailto:tls@ietf.org>
To unsubscribe send an email to tls-leave@ietf.org<mailto:tls-leave@ietf.org>