[TLS] Re: draft-ietf-tls-mlkem-09 ietf last call Genart review

Deirdre Connolly <durumcrustulum@gmail.com> Wed, 02 September 2026 19:25 UTC

Return-Path: <neried7@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 56015134274C6 for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 12:25:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788377103; bh=lSnoqKGs5ZajBzdQgNkF76bxzzdBA7PmvzCY6kcnVd8=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=yqG0wpgxZkB8tsudv60wyC4CCa2eTM2pFTFdzcCUu+MC3m6+1ZnPDHu9aSE3K1QqX gZkGWyJW9vlDFZ3jF5AdZsuxZE0fViSK3zA9S4KeKtWHhT3s5rBup6119LgCw8UtjV TeuDCmes/MV+zPQOtmZVGHcwS5a8LayJGrHEUQTc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.848
X-Spam-Level:
X-Spam-Status: No, score=-0.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BtLCnC_Iy9AS for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 12:25:02 -0700 (PDT)
Received: from mail-lf1-x136.google.com (mail-lf1-x136.google.com [IPv6:2a00:1450:4864:20::136]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 0824B134272E9 for <tls@ietf.org>; Wed, 2 Sep 2026 12:24:58 -0700 (PDT)
Received: by mail-lf1-x136.google.com with SMTP id 2adb3069b0e04-5b4a95ab94fso238595e87.0 for <tls@ietf.org>; Wed, 02 Sep 2026 12:24:57 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1788377097; cv=none; d=google.com; s=arc-20260327; b=awtlRIa0Z7WFRaA0rHuVXAZ8Y0Bq2tKhLeyahdnmfh8CLrKBxrGIVvq+CFjVTpA8Z8 CHV9a8ZwCoMFwcJEX9R+kivRKyZmv/Stz27PKSWi7q3qE1yvdoBvoiI5SQrtToTac2k5 mwfXYmIQjmLcr4mDyE+1gz1QTuAByaOTsyCl8keyqA0Mkk/8MZt2sl4PxJnlR8VSi9gR QgmRfZGZqjJFO5MBB1Uefv+BHZc7Fn81huHeHV5u3rnu8TZsRiIKHDQaGR8fW637Wmxn JrQEfkRllFJKFD8BnMdwqmDBkr0i3unWtyS4yCIWBxV0xfHRI249uqcxw4bZ3k6x1I44 +5kA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=Us4w0MbBwO7DoRamD6oGYET9aujph7hhRVWuEopI3PQ=; fh=k5AZTjj33aAHkyu62QmmgAmhuI3JzfaJIxesqJ+habg=; b=dnwSFhcc4FoHMZCJjoo08tyPtbblYAQiJxsSLCnCPqg02QuCLv0YC3SFgO0KF80nhc 0VFoCi4+VjPnYe4cexUBcAmX1+6bFBBCcJ2O7Z/ctR6H9R6+M1bBksnRpcqvkuURRIB3 F9q9UfkWf0DlCd7cwMcDUrNOEYlfwnyzD3UtxJ0T3lyFrfGXrFPS0fP+nkX7k0QiP30s sivMSI0J+FMU7ya/lfZiLhHX9gjDLI9oAr1Gs2QG4fZvIyWjLHxp9KYK5iLzqvapMyFb MjOMSbMTpzyRxzUIrVE7BLCCxUh6W5TX8FOrkAIjmAX3o5vzgb1CcjtG9qBZg2IRHF6r 7uZg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788377097; x=1788981897; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Us4w0MbBwO7DoRamD6oGYET9aujph7hhRVWuEopI3PQ=; b=qq6Zr/+BFeX4n0E8vyNU9DDYOqHkEfahlmAazpiV+7D5QR2jkaLzkyRpkWj6jBbXId i5KPAyYxCzeXZ/dm09ctfAur5GlWcrwwr6WZs2grAf8Jl1deV56HVAAuEhdRWCdYCJHP wBQSa8+vehQOPMoqi0cb3MrLMiWtkMV9DY1orxpn9WZV53QRsBCchNFOOxkh1aDNBmwf Y2pQwUz2mGQgpcANmgUEhPRxu6u7Gyw04vdhZtHgPIXQeRE102t9375Ll+J3gyKcd+ce kwEhV9uwA9t68innyEJl5CO2ojDRlF2Tj+TpC9caX6USChyHFSfURta19BpRuLJ+qwHi dzJQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788377097; x=1788981897; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=Us4w0MbBwO7DoRamD6oGYET9aujph7hhRVWuEopI3PQ=; b=tKxwnTDn4DWUeAaI2pbXfsDhuAhcQRqf3rvNGWiQy2qSlhuCEPKUp6SbF91YaMi7uh 8nvCMYVkm0FvdygCGjK8UpFM87hNnQTXC3SJFOWR4Mwt/iQ5rcXMSA/IymZSLkNGhfFI sWNxARLGu33qAl+9duyN37jIvsXJ8TUhFN0EPF+tl9+wqKezbTi4P8QOYelJQD+jfJu5 sUaTpiaR0za5XmtDFxxYcZsFPxSrHt+XsppJmUb7cfmVDg2LW33dTE2A7chJKxXSujvM bS2D1I4rrqWwB+wgnA9dChyBvhprZFnYgdZu+uqYylKHYOhq04XmQSUqQAOmeVPMdCDj CfKA==
X-Forwarded-Encrypted: i=1; AKwUvBxmEoDEgCdKDB7ZY4i1XjW5uKjGKtVVfnEquxtzQrK+5QqcIDzGOPPSLK+nam7i2/mwH1g=@ietf.org
X-Gm-Message-State: AFuF++nflm5aqmCr7EF81lcpnJiNhwkMknssqZwmquBdoI1DIpLhNlig IXSCvYiWUdc08tHHqHeYlboH4bYI0QoE0mfFfvCaB/2MWobsQcpH2S5eTpROr2Smz2b6Xv5gMlN t3IlF2aQN7ocqZsluBq2YxYSieUMFZ/s=
X-Gm-Gg: AYBFou3CXek/BqiaVV8BaMUGxG2B8gBe1scNLdNwB82KobNq7g7FnMjRlTg2nml9Yyz WRa7lXw5HJW426GIYfpP8nPpUXvLA54U8du87jAJmpJJXBkqNlsyQRbFYE1p9MmvUHxZTKZpz6c F8iC2vmoZT6av2LrhsgTf1RbTRiAm1/ypEfzqInZz3ogoT+qCkKvC5pBAFidKNqvN0+bvu780lI qr43t2BEy8sORZN5olqMXD0rGBkqoN2VobUkMUz34RZQ4H71r1Rc7yOOZy2O0AqGTevqUHaHHPK BMG1de9wt8Kd+vhWqmnQLnMsxLoLjeH86+NFCp086pSVgglrc8Uy1wyLvCSLv+CVT5DjoplQ0Wf 4KQ==
X-Received: by 2002:ac2:5689:0:b0:5b6:a77:10fd with SMTP id 2adb3069b0e04-5b60e6c24edmr319158e87.4.1788377096495; Wed, 02 Sep 2026 12:24:56 -0700 (PDT)
MIME-Version: 1.0
References: <178611991225.947.15830888118020996145@dt-datatracker-559c48c7fb-9llwz>
In-Reply-To: <178611991225.947.15830888118020996145@dt-datatracker-559c48c7fb-9llwz>
From: Deirdre Connolly <durumcrustulum@gmail.com>
Date: Wed, 02 Sep 2026 15:24:18 -0400
X-Gm-Features: AcwNN1UIyC5vjmdJ5mvQM__pojI5thnmlwFkYCr3FMSGxUERLEf0uQgRLCTJisg
Message-ID: <CAFR824zwZ6qVypZgLzQ6yc-38QutyDojPobxaZJyxKya4tEMuA@mail.gmail.com>
To: Stewart Bryant <stewart.bryant@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000008fa7e6065a84fd41"
Message-ID-Hash: AXIXXWK3DPKUQ4QKBR2NYYTKSHMFH2SB
X-Message-ID-Hash: AXIXXWK3DPKUQ4QKBR2NYYTKSHMFH2SB
X-MailFrom: neried7@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: gen-art@ietf.org, draft-ietf-tls-mlkem.all@ietf.org, last-call@ietf.org, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: draft-ietf-tls-mlkem-09 ietf last call Genart review
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/Vq5HMbUFKtQjwu2RzyiOdWh4GW0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Thank you for your review, I think all of these comments are addressed by
version 10, except for the RFC 9847 normative/informative question— other
RFCs list this as Informative, and I asked my AD if Informative is correct,
she said yes, this is an Informative reference.

https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/10/

On Fri, Aug 7, 2026 at 12:25 PM Stewart Bryant via Datatracker <
noreply@ietf.org> wrote:

> Document: draft-ietf-tls-mlkem
> Title: ML-KEM Post-Quantum Key Agreement for TLS 1.3
> Reviewer: Stewart Bryant
> Review result: Ready with Nits
>
> I am the assigned Gen-ART reviewer for this draft. The General Area
> Review Team (Gen-ART) reviews all IETF documents being processed
> by the IESG for the IETF Chair.  Please treat these comments just
> like any other last call comments.
>
> For more information, please see the FAQ at
>
> <https://wiki.ietf.org/en/group/gen/GenArtFAQ>.
>
> Document: draft-ietf-tls-mlkem-09
> Reviewer: Stewart Bryant
> Review Date: 2026-08-07
> IETF LC End Date: 2026-08-13
> IESG Telechat date: Not scheduled for a telechat
>
> Summary: A well written draft that the can be published. There are no major
> issues and just a few nits that could usefully be fixed for the benefit of
> the
> reader and to save work by the RFC Editor team.
>
> In doing the review I did something I have never done before. AFTER
> reading the
> draft myself and preparing comments I asked Claude for a review. I did not
> do
> blind copy across, but included a few issues that I had missed and thought
> worthy of of drawing to the attention of the IESG.
>
> There was one comment concerning the use of the term hybrid that was
> outside my
> domain of security knowledge and thus I did not know if I should include
> the
> comment. The consolidated AI review is at the end of the following web
> page.
>
> https://claude.ai/share/65e221cd-39c5-480e-b7b0-23a5daff54fb
>
> Major issues:None
>
> Minor issues:None
>
> Nits/editorial comments:
>
> Nits picked up
>
>  == Missing Reference: 'DUALEC-TLS' is mentioned on line 236, but not
> defined
>
>   == Unused Reference: 'DUALECTLS' is defined on line 328, but no explicit
>      reference was found in the text
>
> This is a typo
>
> =========
> 181        Implementations MUST NOT reuse randomness in the generation of
> ML-KEM
> 182        ciphertexts— it follows that ML-KEM ciphertexts also MUST NOT be
> 183        reused.
>
> SB> Perhaps
>
> Implementations MUST NOT reuse randomness in the generation of ML-KEM
>            ciphertexts.  From this it also follows that  ML-KEM ciphertexts
>            MUST NOT be reused.
> =========
> 204        [CHSW22] [CZCJWH25] [ZJZ24]; ML-KEM's IND-CCA security exceeds
> the
>
> SB> IND-CCA is not in the official list of well known abbreviations and
> should
> be expanded (no * symbol in
> https://rpc-wiki.rfc-editor.org/doku.php?id=abbrev_list
>
> =========
>
> 246        Section 6 of [RFC9847].
>
> SB> RFC9847 looks normative, should it be moved to the normative reference
> list?
>
> ==========
>
> 320        [CZCJWH25] "Post-Quantum {TLS} 1.3 Handshake from {CPA}-Secure
> {KEMs}
> 321                   with Tighter Reductions", n.d.,
> 322                   <https://eprint.iacr.org/2025/1748.pdf>.
>
> SB> The documents itself has a date - should this be added to the
> reference?
>
> =========
>
> 398        Thanks to Douglas Stebila for consultation on the
> draft-ietf-tls-
> 399        hybrid-design design, and to Scott Fluhrer, Eric Rescorla, John
> Preuß
> SB> Double use of “design" although perfectly acceptable although perhaps
> "---design approach" would read better
>
> ==========
>
>
>
>