[TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3

Nadim Kobeissi <nadim@symbolic.software> Wed, 06 May 2026 16:26 UTC

Return-Path: <nadim@symbolic.software>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3E0E9EA084FB for <tls@mail2.ietf.org>; Wed, 6 May 2026 09:26:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1778084765; bh=SWDHWlV5Y/nXXrGSe8GXa4vtNSffLlPCipZImFswH14=; h=From:Subject:Date:In-Reply-To:Cc:To:References; b=KHnmo4sHF29CB1eXd5zbXbBKZxTTqumzAu6Y8Xtp/RNs+ACDgoDiLm7TuiLrRBF4d jKIdfIkLn6Xq6UpUuYFEFSRBJyW3/7rdjMy8ULgL8UIzUMepOoArSO275STMiaDvsh u+44IRrjKnR5cRX21siqty4RdbnAH6lx//dlQmdM=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.699
X-Spam-Level:
X-Spam-Status: No, score=-0.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, PDS_OTHER_BAD_TLD=1.999, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=symbolic.software header.b="IuvwKat0"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="Yaw6FO+L"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TbOlCrq29x4y for <tls@mail2.ietf.org>; Wed, 6 May 2026 09:26:01 -0700 (PDT)
Received: from fhigh-a2-smtp.messagingengine.com (fhigh-a2-smtp.messagingengine.com [103.168.172.153]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 80511EA084B5 for <tls@ietf.org>; Wed, 6 May 2026 09:25:55 -0700 (PDT)
Received: from phl-compute-01.internal (phl-compute-01.internal [10.202.2.41]) by mailfhigh.phl.internal (Postfix) with ESMTP id 9F43D14000BD; Wed, 6 May 2026 12:25:49 -0400 (EDT)
Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-01.internal (MEProxy); Wed, 06 May 2026 12:25:49 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= symbolic.software; h=cc:cc:content-type:content-type:date:date :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm3; t=1778084749; x=1778171149; bh=+/KTxOidAnF4/vbaOm+JtjMNRFNldpGUVhPnNuG5N7A=; b= IuvwKat07/IoC6g2vustAvSS4vsdoXs+jpRs6BSF1hK6J1OYrg98bw1aOEpSHSKD wtfWgjxGoPIjCt6z62sTXnTw2JxUMbPwQ+NxkU6Ld57TvRtCKOHaCORGoR6WpSyK G84w9WhEnYpg5NvDqbpyOwlglgbaQPU08ObCavqfwP7GOL3ZoJY/Xxlh5kaSE7LG w9u0i1ilWMYXct1OcF3xINFC5dcxYoxB/6SyKsfQPIc87cmwmihQGSz+6imko7Mv 2msm7tmrjB0rDv5YjKyg5qdoJygF962lo3wyRfnkM9Xiu+zTKWEvD0n++/+OQUQD i7idtvW3TtXIucT7cGBeZQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t= 1778084749; x=1778171149; bh=+/KTxOidAnF4/vbaOm+JtjMNRFNldpGUVhP nNuG5N7A=; b=Yaw6FO+LdJCbtbWf28KJ4HgDc+HDw8LhO3veb9mT2HlzOIRppTZ rB8ICMhC9sfCU0lSkE7RzCaSsysOJJCXbWiG5CqJWetcB+/HZOzZTSv5ALsVNYEP fgThlVixys/Pq8MxtzeNv/+mkIfkbv9gyCC/rsplmy1YPN1Y38oBT91TvbHZae6i DG5hbXb0iagUsNWIGXFxhBLdVfILCuwVJ/hqXzoMikbOuHQWWOHZ4mFpnJt6rAqM shVQnMjJGzLcUTs1uZpuQ3JozyPRG+kuRFTjGAt+w8KDxuasTw2cT9bSC1vVtOzU /K4yBNSKV7CIMtpdGdz3DTXt9PwJTje4VUA==
X-ME-Sender: <xms:jWv7aSCdt4_R5PraoyGc7DargL48D1NJTtxYcr-619in9yKvvCxK2w> <xme:jWv7aeDQeUePV7zW9cWVir_oRZPFCYg2gLJiaFZUKgjMg0rm0UJ2lEz_f_9TL3F5W FGtlcnOQd_pUFB06SqSvnM4F56RULDWx_LBRFsaeWIoMJpY6wfe2C4>
X-ME-Received: <xmr:jWv7aVrsHOTMkIGV5iayM4F_gjTJy94tpDmY5bachRgzMahY3sUjFL4JyWEBZWVFzXaovW7ZqBdPIbdnPJeAwzXfnUS1XIrREFPCEKTKxSunPM0ldd5drBKsLw>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefhedrtddtgddutdehtdeiucetufdoteggodetrf dotffvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfurfetoffkrfgpnffqhgenuceu rghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmnecujf gurhephffktgggufffjgevvfhfofesrgdtmherhhdtjeenucfhrhhomheppfgrughimhcu mfhosggvihhsshhiuceonhgrughimhesshihmhgsohhlihgtrdhsohhfthifrghrvgeqne cuggftrfgrthhtvghrnhepleeiffeklefhgeevieefueefgfelvdfghfehfeffgeelteev jeevveelieeguedtnecuffhomhgrihhnpehshihmsgholhhitgdrshhofhhtfigrrhgvpd hivghtfhdrohhrghdprghvrghnrghnrdgtlhhitghknecuvehluhhsthgvrhfuihiivgep tdenucfrrghrrghmpehmrghilhhfrhhomhepnhgrughimhesshihmhgsohhlihgtrdhsoh hfthifrghrvgdpnhgspghrtghpthhtohephedpmhhouggvpehsmhhtphhouhhtpdhrtghp thhtohepthhimhdrhhholhhlvggsvggvkhepgedtughighhitggvrhhtrdgtohhmsegumh grrhgtrdhivghtfhdrohhrghdprhgtphhtthhopehjohhhnhdrmhgrthhtshhsohhnpeeg tdgvrhhitghsshhonhdrtghomhesughmrghrtgdrihgvthhfrdhorhhgpdhrtghpthhtoh epuggrvhhiuggsvghnsegthhhrohhmihhumhdrohhrghdprhgtphhtthhopehsvggrnhes shhnfehrugdrtghomhdprhgtphhtthhopehtlhhssehivghtfhdrohhrgh
X-ME-Proxy: <xmx:jWv7aQnYnQ8qgvW0HkrCsh2sU4ZkO4vzvpWA08Hd1FpL2lszKUuabg> <xmx:jWv7adxZ0sL-0rTffDDvTq3vv7E7J_9BL3M6p3rOZ0vhyPXUWEwOhw> <xmx:jWv7aQ8sjYbQbY5BRRwXQeif3eXjq_nu9EZqRnHD6NXrauI1agTUvw> <xmx:jWv7aRKXSAiC9WYVR8zyTUvQ_-9g-5RutnksSih3Ogoic7Fz32p5wg> <xmx:jWv7aQ9kIuwVPCnDx0dBQBWRldKqKL5__JyAJcnRHBMaghaEQzLlJCRo>
Feedback-ID: i6d3949ed:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 6 May 2026 12:25:48 -0400 (EDT)
From: Nadim Kobeissi <nadim@symbolic.software>
Message-Id: <69FDA4A3-4644-4E29-B3D0-295F32D6FF8B@symbolic.software>
Content-Type: multipart/alternative; boundary="Apple-Mail=_DCC58D57-8D3C-4927-9382-79EB362D7032"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.500.181\))
Date: Wed, 06 May 2026 18:25:47 +0200
In-Reply-To: <SN7PR14MB649251F88FCDAECCCB57160C833F2@SN7PR14MB6492.namprd14.prod.outlook.com>
To: Tim Hollebeek <tim.hollebeek=40digicert.com@dmarc.ietf.org>
References: <AS4PR07MB8825B35E02C4A5F0BDEAB4EE893F2@AS4PR07MB8825.eurprd07.prod.outlook.com> <SN7PR14MB649251F88FCDAECCCB57160C833F2@SN7PR14MB6492.namprd14.prod.outlook.com>
X-Mailer: Apple Mail (2.3864.500.181)
Message-ID-Hash: LTCGFRLAGMFCJK5C6NUEJBTHYAT2NR6M
X-Message-ID-Hash: LTCGFRLAGMFCJK5C6NUEJBTHYAT2NR6M
X-MailFrom: nadim@symbolic.software
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/aVdAm7ojeeHO7Tt5UhQDYAWMVkg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Yes, in all honesty, one must admit that the chairs deserve some credit. There is always room for improvement, but that’s a given in all cases.

Nadim Kobeissi
Symbolic Software • https://symbolic.software

> On 6 May 2026, at 4:41 PM, Tim Hollebeek <tim.hollebeek=40digicert.com@dmarc.ietf.org> wrote:
> 
> Thanks Deirdre, Joe, and Sean for all your hard work, and being willing to serve in roles that might be a strong contender for hardest chair role at IETF.
> 
> -Tim
> From: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>
> Sent: Wednesday, May 6, 2026 10:36 AM
> To: David Benjamin <davidben@chromium.org>; Sean Turner <sean@sn3rd.com>
> Cc: TLS List <tls@ietf.org>
> Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
>  
> Agree, thanks Deirdre, Joe, and Sean for your hard work and leadership!
> 
> From: David Benjamin <davidben@chromium.org>
> Date: Wednesday, 6 May 2026 at 15:20
> To: Sean Turner <sean@sn3rd.com>
> Cc: TLS List <tls@ietf.org>
> Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
> 
> -- 
> 
> Thanks, Deirdre, Joe, and Sean, for all your hard work in navigating these WG discussions!
> 
> On Wed, May 6, 2026 at 9:09 AM Sean Turner <sean@sn3rd.com <mailto:sean@sn3rd.com>> wrote:
> Replying to the original consensus call message.
> 
> RFC 2418 Section 3.3 lays out the criteria for “rough consensus”:
> 
>    Working groups make decisions through a "rough consensus" process.
>    IETF consensus does not require that all participants agree although
>    this is, of course, preferred.  In general, the dominant view of the
>    working group shall prevail.  (However, it must be noted that
>    "dominance" is not to be determined on the basis of volume or
>    persistence, but rather a more general sense of agreement.) Consensus
>    can be determined by a show of hands, humming, or any other means on
>    which the WG agrees (by rough consensus, of course).  Note that 51%
>    of the working group does not qualify as "rough consensus" and 99% is
>    better than rough.  It is up to the Chair to determine if rough
>    consensus has been reached.
> 
> In this case, during WGLC there was an almost 4:1 ratio for progressing this draft, which we judge fits within the numeric “more than 51% and less than 99%” range suggested by this text for “rough consensus” and represents the “dominant view of the working group”.
> 
> In assessing rough consensus, we also considered the nature of the objections. In reviewing the list traffic, the majority of objections related to the status of pure MLDSA versus composite MLDSA-ECC, including (1) we should not publish a pure MLDSA specification at all; (2) we should recommend composites over pure MLDSA; (3) we should publish the composite and pure MLDSA specifications concurrently. While there was substantial disagreement on these points, we believe that the discussion on-list sufficiently aired the respective points of view and that the right approach is fundamentally a judgement call based on weighing various technical factors, which each WG participant needs to make for themselves. We see no reason to believe that participants were not able to make informed judgements.
> 
> Conclusion: The chairs believe there is consensus to proceed with publication of this draft as an RFC with Recommended=N for those people that want to use this algorithm, and a future Standards Action will be needed to make a change to Recommended=Y, if anyone has the willingness to undergo this heated discussion again.
> 
> For transparency purposes, the chairs note that we received a complaint/appeal about the consensus call. The message was moderated due to a previous notice of moderation; see [1], and the complaint/appeal contains a derivative work notice. As a result, the message was not sent to the mail list and we will not process the complaint/appeal as-is. If the message is resubmitted without the notice, the message can be posted to the mail list and we will process the complaint/appeal.
> 
> The Chairs,
> Deirdre, Joe, and Sean
> 
> [1] https://mailarchive.ietf.org/arch/msg/tls/no0lW8r_wIPGF1ZXWB3EaGywh9Q/ <https://url.avanan.click/v2/r01/___https://mailarchive.ietf.org/arch/msg/tls/no0lW8r_wIPGF1ZXWB3EaGywh9Q/___.YXAzOmRpZ2ljZXJ0OmE6bzo1MDE2ZjM5NjQ0Y2E5M2ViODdhMjQxNDFmYjMxNDFhMjo3OjUxNGE6OTkyYmQzYjEzMmY0YmM1MjY4NDg2ZTMyYmExYjhlZjNhMGE3YzA3N2QzZjRiOGE3NTc4MTk5YzY5Yjc5NTMzMzpoOlQ6Rg>
> 
> On Apr 28, 2026, at 16:24, Sean Turner <sean@sn3rd.com <mailto:sean@sn3rd.com>> wrote:
> 
> Hi! The chairs have judged that there is consensus to progress this I-D. We will work with the authors to get a new version submitted and we will get to work on the Shepherd Write-Up.
> 
> The Chairs,
> Deirdre, Joe, and Sean
> 
> On Apr 9, 2026, at 15:30, Sean Turner <sean@sn3rd.com <mailto:sean@sn3rd.com>> wrote:
> 
> This is the working group last call for Use of ML-DSA in TLS 1.3. Please review draft-ietf-tls-mldsa [1] and reply to this thread indicating if you think it is ready for publication or not. If you do not think it is ready please indicate why. This call will end on April 23, 2026.
> 
> REMINDER: If you have not done so recently, review the TLS WG's Mail List Procedures; see [2].
> 
> The Chairs,
> Deirdre, Joe, and Sean
> 
> [1] https://datatracker.ietf.org/doc/draft-ietf-tls-mldsa/ <https://url.avanan.click/v2/r01/___https://datatracker.ietf.org/doc/draft-ietf-tls-mldsa/___.YXAzOmRpZ2ljZXJ0OmE6bzo1MDE2ZjM5NjQ0Y2E5M2ViODdhMjQxNDFmYjMxNDFhMjo3OjY1NDg6NzljOWU4ZmYxZDhiMWI4ODQ0MDEwNTk2MzVhOTdmZGQ0Y2VlMTk5ZWQ3NzgzYmFmMWU0NDU1YjdhNzIzNjVjYjpoOlQ6Rg>
> [2] https://mailarchive.ietf.org/arch/msg/tls/ucdImHExlbOf4Q3BCG81gjzi2xE/ <https://url.avanan.click/v2/r01/___https://mailarchive.ietf.org/arch/msg/tls/ucdImHExlbOf4Q3BCG81gjzi2xE/___.YXAzOmRpZ2ljZXJ0OmE6bzo1MDE2ZjM5NjQ0Y2E5M2ViODdhMjQxNDFmYjMxNDFhMjo3OjhlNGE6Zjc2ZTk4ZDc2MTZjZTg4NDdkNjJiNTNlOTBmMWI1ZmU0YzZmNDAwZTVmNGM4YjczNWM1YjM0YTQ4NmZjNjVlYzpoOlQ6Rg>
> 
> 
> _______________________________________________
> TLS mailing list -- tls@ietf.org <mailto:tls@ietf.org>
> To unsubscribe send an email to tls-leave@ietf.org <mailto:tls-leave@ietf.org>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org