[TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3

Nicola Tuveri <nic.tuv@gmail.com> Wed, 22 April 2026 16:14 UTC

Return-Path: <nic.tuv@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id F0937E0ECF51 for <tls@mail2.ietf.org>; Wed, 22 Apr 2026 09:14:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1776874497; bh=DZcg725u31XwsZisTgyznd9JwDKCP5YBUjJOOXwRNVI=; h=From:Date:Subject:To; b=IaUZ1SaISFHMSksKJUjwtNz7gSNv+TVBXZ4WsuNMPrGwcmxXDSzmhScZTXEXdx7Pg TZnHhZINqQ0dWd/FBUBo3odUOUfDvzSEXWFoKIfqrm6A2yNY+SSWpWN71Kf3T1vYBj 61B+hSxhDzYBnMrwmtUNvOWBEoWtHo160rz9Uj0s=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id exPAJeGBi6HS for <tls@mail2.ietf.org>; Wed, 22 Apr 2026 09:14:53 -0700 (PDT)
Received: from mail-ot1-x334.google.com (mail-ot1-x334.google.com [IPv6:2607:f8b0:4864:20::334]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id F00C3E0EC9AD for <tls@ietf.org>; Wed, 22 Apr 2026 09:10:39 -0700 (PDT)
Received: by mail-ot1-x334.google.com with SMTP id 46e09a7af769-7dcd689829eso1979661a34.3 for <tls@ietf.org>; Wed, 22 Apr 2026 09:10:39 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1776874232; cv=none; d=google.com; s=arc-20240605; b=O3W5O+sT03i9goHuZgfY54QJzLJiJ+M/5CkScv4SDMDPBo2nXz/FSZr/FxKJs0xvgJ 7qWSWcoq2yw5A4UQUL+QN9tXk5vYZF/MBKhRsMjWs0AHygUtpbuVN2bsTtGCxzBsIYah gd5LkFE1A+wzvBnWgUTHonvDctu37D09mYs5esH/zBdI3abxkqQ7XO5JeVD48RCWlknX yORbhervokJ4RurRQrxoeIr7ips6t7zFyarc6D7cVz+oBSntKuH1rupJr4Hbhxgxq4Ky t3KO6Hyeeybv8ATAAYTpv0pMTkD0+1GgB9OLLUhtPdsbkxYj10u0erV8lu9cTUQqVKob aAWg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=DZcg725u31XwsZisTgyznd9JwDKCP5YBUjJOOXwRNVI=; fh=xAG10IiJPP4GOmlOfCntepTVUPXOLNYiPXFwzwy9dzI=; b=Ulf89jaQ+eyk7di5S5dzvHeJVpKkQCv1CKNNMmeZ2spsdSTlxE/pvsWmKOwdElocEo Xc4Jzgzq8oSzMhnrXzF50eCiOIQJBcpsV9YwKTZFp1XNOCKkgSCWMh7UIrcQiKqPI25A 22oATUzLtO86tcZmcAhOfUQxD/v+aBseAAYeEq/0n/QKLnjJ8GI1EiTCTpr0SuyrhnQw 31QWh0TZG5dkyXdmq8Yi7r8dbzT24EMdlbChQx69Mym/nmGVwzlxxke5Rg0OT2gy02yI JSBMBPHI3adlzQy3U/cFunqJQarY8z9ekCKnHk9Ye1BEqjsbUmcB8awyT5Yc+m6wEH7Y zjBA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1776874232; x=1777479032; darn=ietf.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=DZcg725u31XwsZisTgyznd9JwDKCP5YBUjJOOXwRNVI=; b=BtXZoqT7Jul5BtGlxZDJzUXDsVLkWTy9/CvFltnukKalvd3eQlB8dPo5SU9BaWnMfg p08qVX6S9aKTRP/0TSHBoo+1jGe+cYuYRfygmd7DLP+CuHVcF0w9yQdyqPMwPA2m1stH kJlppDAAETu5bk0CAM8M3xrLvtwhL1dR7r1AD7JyLDy2TMLfduLgXKYAqyQks+5eG502 4UR12ANxBUXbhuszl2mdEy7lVn3YtnxBhx2dCbHrc1+QzwZI79UCDkgsc0h/YhSdhx80 lOo66JecITNsOhj5azdG95Pzf++IXk4JQ15vaLFsjLPgaSJRIMDjicxqEiQopVliLua6 aFcw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776874232; x=1777479032; h=to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=DZcg725u31XwsZisTgyznd9JwDKCP5YBUjJOOXwRNVI=; b=p0BMshczTd10ph+IbAyteVOm8ciyWMAwvsWp3iKR0oiOFJDIR2xkz8U/NtgRl76juy PB7SnrOZu8iPXMrYKRdDdanXEvXNRAE96zXLaLqmTQ46pmEESHMSqmpcjyOYGK+xCacj GoWUSWfDMwgevAGIcJyhX4wJG+E9xhb+X+iC+wR8WPBRvtcNhuNVmqsiDsqJhZMfbmxD ID3p/MHTBydOzxtZ/pt5oFciKooKt/F1mv1bCs9clom1/udaVXdZI14tT82/BR5YuDH/ wE6P5CzXfi1wOV6D15Kkf9m4jAiHW1ztCI/9csDXX5CJf2GOf0d+HulbyB+TBJB7Oa7a tIag==
X-Gm-Message-State: AOJu0YwTrN4DGdKyvj1OEp2qnaGbWNt5p9GUnGOgDHRZMNVTbNj3Fjl1 +XygtDW6qMhynbWKcg0IfUDdHma9izdHgiBllog9YfYBCySVSQ2jSiUALhX4D3PpsQ/vGi+792H vpTLZvna625PyH9N0QBG6zfL/sB3BfRIRzw==
X-Gm-Gg: AeBDieutB8K9EHndq9SMKdNjCB5w8o41X2DXnzGYNF98aq7uwtwMbqN4wdk++kM7ODh 8TAc0MFjocPlmKqwmui3ILEHh7GjAEX0qvrPpnYpd7N/MJ3DnExE+TwI9YgLJumhzq3gJC72YQx BtRdrG9Bmc9zTEf+WRn4nofNBCa35WHjJ/2usneOLqP79qScoZPCrJ60K4kAQvV8hkrQI94iW+S 5axC1kLQMpxGyj6vvlxL5sLELWWlfvn2zd1UY1OTOYfiV6GtNHnKFR9gfNpHdDXB3sABTWmilFf lRDjtcgpW77+ScDwkxqGqdUG2aHF0QyQvHsveganfYXfQ9YbTaw=
X-Received: by 2002:a05:6820:4de7:b0:694:9a67:edf6 with SMTP id 006d021491bc7-6949a67fadcmr4081688eaf.17.1776874232259; Wed, 22 Apr 2026 09:10:32 -0700 (PDT)
MIME-Version: 1.0
From: Nicola Tuveri <nic.tuv@gmail.com>
Date: Wed, 22 Apr 2026 19:10:18 +0300
X-Gm-Features: AQROBzBaXGATLib5Hy_XKROeQieAIusLOEPQGYr4Sy8_Pwap4R5tQZ74MIsLSmo
Message-ID: <CANm5x_MjhTwo6hkg1nnuMPF7EBjpJkj19pGnxd_3eZyOpKtPSA@mail.gmail.com>
To: "tls@ietf.org" <tls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000006ca8d206500ec5fc"
Message-ID-Hash: 6R5IFHAN3UMM2AYOKB6ZWAWFYPXD6ID3
X-Message-ID-Hash: 6R5IFHAN3UMM2AYOKB6ZWAWFYPXD6ID3
X-MailFrom: nic.tuv@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/ZbAItygixZANXUbzdchImvqSUW8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I have read the draft, but I do not support its publication at the moment.

I’d rather hold the evaluation of its publication until the composite-mldsa
TLS draft process is resumed.

My rationale is that this draft adds complexity by adding extra code points
for pure mldsa.
There are jurisdictions where the current recommendations mandate hybrid
deployments, and even in those where that is not a mandate, hybrids do
offer an extra layer of protection to the users in the current ecosystem of
PQC implementations that have not yet matured as much hardening as the
traditional implementations.

For this reason, given that this WG does put emphasis in keeping a limited
number of negotiable code points, I’d prefer the choice between this and
the composite draft to be taken on equal basis rather than just on which
group of supporters managed to put more pressure on the WG to win the race
to last call.

Many have reported on their experimental deployments of this draft: in
support of delaying the publication of this draft, I’d complement that in
the QUBIP project [0] we do have a successful deployment of TLS 1.3 using
both the composite-draft and the pure-draft.
I can report that the deployment of composite-mldsa did not exhibit any
higher complexity level than the pure-mldsa deployment.

Best regards,

Nicola Tuveri

[0]: https://www.qubip.eu