[TLS] Re: [EXT] Re: ML-DSA in TLS

tirumal reddy <kondtir@gmail.com> Sat, 16 November 2024 06:58 UTC

Return-Path: <kondtir@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8D0A8C14F748 for <tls@ietfa.amsl.com>; Fri, 15 Nov 2024 22:58:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T4S6EVlVTvZQ for <tls@ietfa.amsl.com>; Fri, 15 Nov 2024 22:58:20 -0800 (PST)
Received: from mail-ej1-x62d.google.com (mail-ej1-x62d.google.com [IPv6:2a00:1450:4864:20::62d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B16CAC14F726 for <tls@ietf.org>; Fri, 15 Nov 2024 22:58:20 -0800 (PST)
Received: by mail-ej1-x62d.google.com with SMTP id a640c23a62f3a-a9f1c590ecdso246593566b.1 for <tls@ietf.org>; Fri, 15 Nov 2024 22:58:20 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1731740299; x=1732345099; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=Hlth+GociqnPgTqQVm8s3L+Ybq0coF+rwqnES13tdpc=; b=fPo6asn6J6XWA8gqUWgOpZnpS3wAJHYJWlgWmCa/5OwcKmFMCIVUrq+vu4BLC0Uxfw 8UyY/uAiT7BCKYsHngwONoTjx1jcHxqbv5u/hA+TBdy8evplR3S0n7siMeSwJuNS1Sgh GytH2+d6JNAjnLRr9G+SpCaO8dOyGyfk73XRNxw7GjjMwp0XNRE8zT1cEMatw6HH8DAA eVstYMCi+X5obP1y5I4lbr6JeVTd8ZkvTrYIeheIFmxp31GgoihVhg9aDDrVFb5g6Jq8 e7yujmoAltmKhzxP9Ra0Lo9aj28XnOqbPMIt3pD+x2NgK0g8nysIwPK/Uc01jaB1q+Xx wmmg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1731740299; x=1732345099; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=Hlth+GociqnPgTqQVm8s3L+Ybq0coF+rwqnES13tdpc=; b=d9raD990Z7+2Sex05SjU/2JxvvVvp9XHvBUxqlwZh3c4xJQQ1h2vxX6WsxkIHXILVn TtKPZkeUjykFaV4jFwCQdc5NrPVwjaHg4J38k94wP6g1lD1Da/cWzQv3HTWTBEgAnMIZ cqvSwI45C4B2XJirdw3+ufxmfyox7WfyHzF0jsuk3ARYAfY1QeTGT2cxabkLAhP+r7iY zO1e0e5clKxASsD3oOOMiw2+NoW6zEOfmKaSCqbB6hxp8vSb2daCLbJh75k5gTT3SMxG V5BQDXrtHwlk5qV9HCVkF4yHj63u+BozSWm/zAKqjLcVdCYJT+MkHL1VMeiwA4U8SMUg ThvA==
X-Forwarded-Encrypted: i=1; AJvYcCXLHAiCbjI2EtyNrEtqvgiTAGwXCWhWgMN/mNH59ZM1g3KpgyRDmei8zQD8c7U211UBx2k=@ietf.org
X-Gm-Message-State: AOJu0Yz5SeqNONnmdgn8BE+Kmo1jDu0pN1Lew/aMT9Q2QXpv6A7iF9k+ dqbqcOERETCwBoMBPjfaPSCvAIiig52iDWxx6nC1+3ucW3DzRM++Ongak/K4TnA4+FmjefvytnB UyWuhnWlvtXnk2Z1uSfYUw/t9fv0=
X-Google-Smtp-Source: AGHT+IEIPRIMrddVE3ngyf7gVTV/nNvUw6PsLVcCdjd9+9BFWw5uBZgSljpCT61OzamNuQ34V8b/MBnhyF1RPGgtcM8=
X-Received: by 2002:a17:907:3e14:b0:a9a:684e:9a64 with SMTP id a640c23a62f3a-aa48357944bmr425790266b.61.1731740299056; Fri, 15 Nov 2024 22:58:19 -0800 (PST)
MIME-Version: 1.0
References: <CAMjbhoUFkL=UT0Pt2xjPLm998=j1ef+wdm0WO14_W7OJDJ-hOg@mail.gmail.com> <CAMjbhoWY+1Km_=+PbXfEjab02AfWpbd4WwKwuBN_5KZZpCkXZg@mail.gmail.com> <bd714bdc-5bf9-47a6-8e66-b2e4624c9df0@cs.tcd.ie> <GVXPR07MB9678722E47C82B14B0F296F389242@GVXPR07MB9678.eurprd07.prod.outlook.com> <CAAWw3Rh-2A1zuEWOLuoaQ5DMcDGb_oQXRc8ZNYNVoO8KDsqzTA@mail.gmail.com> <e855562b-2bce-4bd4-ab58-074550c34475@redhat.com> <CAAWw3Rj7L8v9OOJtGHMvCXRtcHYAMU3TLPJ_etf8EP8MSiSHGQ@mail.gmail.com> <BN0P110MB141974314450179F48B424D99024A@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM> <CAAWw3Rgy7qonCMqKmYiCQZi3RCq=t4J94NA817ONYGOTwP3FDw@mail.gmail.com> <CACsn0c=8J4S00mzOWpHgKSudnpp=zzRjGmVQ5tRNTOnN5ekWfw@mail.gmail.com> <CAAWw3RjCk1hhjapG5r6F0NEo83G=XzyNuscSrzJMeefuZm_cJA@mail.gmail.com> <CACsn0ckf57w-6xg+-d2WrvoY-RGM+BQbZFP-fo=OTC11kNdRYQ@mail.gmail.com> <CAAWw3Rg9YW5=Gd3E-XvthsU6-N=zx_N0Ss2uZsaVcB5c8HoQFA@mail.gmail.com> <CACsn0c=ubuOzJbvRegg+J5=Rs9oQRwoZN35_CCqoVsynPQbTew@mail.gmail.com>
In-Reply-To: <CACsn0c=ubuOzJbvRegg+J5=Rs9oQRwoZN35_CCqoVsynPQbTew@mail.gmail.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Sat, 16 Nov 2024 12:27:42 +0530
Message-ID: <CAFpG3geGKJMHyaB=HwQtnE+JyEbCJsHmLedsZur0G2PYwYiO3w@mail.gmail.com>
To: Watson Ladd <watsonbladd@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000005e5fe1062702358d"
Message-ID-Hash: YGXYDUU3FMQKYALBWMIH3UGF2XIE2J53
X-Message-ID-Hash: YGXYDUU3FMQKYALBWMIH3UGF2XIE2J53
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>, TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [EXT] Re: ML-DSA in TLS
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/W9puwUJ0gye0ye2bV1kJZgfvJfw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hybrids are mandatory for protocols like IKEv2 over UDP to handle
fragmentation (traditional key exchange followed by a PQ KEM), see
https://datatracker.ietf.org/doc/draft-kampanakis-ml-kem-ikev2/.

-Tiru

On Sat, 16 Nov 2024 at 11:43, Watson Ladd <watsonbladd@gmail.com> wrote:

>
>
> On Fri, Nov 15, 2024, 8:52 PM Andrey Jivsov <crypto@brainhub.org> wrote:
>
>> On Fri, Nov 15, 2024 at 3:56 PM Watson Ladd <watsonbladd@gmail.com>
>> wrote:
>>
>>> ...
>>> Why not hash based signatures?
>>>
>>
>>  I think that the stateful ones are perfectly suited for certifications
>> in X.509 certs, but in the TLS handshake this has to be Sphincs+, at 16.2KB
>> per signature at the AES-192 security level. In addition to size concerns,
>> it's not allowed in CNSA 2.0. Are vendors considering SPHINCS+ for this
>> purpose?
>>
>
> If CNSA 2.0 is the guide why consider hybrids?
>
>> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>