[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Deirdre Connolly <durumcrustulum@gmail.com> Wed, 24 June 2026 17:25 UTC

Return-Path: <neried7@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id DB4AA106A5A27 for <tls@mail2.ietf.org>; Wed, 24 Jun 2026 10:25:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782321951; bh=mcerHOFxPSBf8Ds9Be5v+m//ronCDTLnfykAl4PwZkg=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=YN6xEhTYigeNOWLvk/NWofsxhiBK6K8dWl+ouanIZipfHGq0uxjdgPSuwA6pDOMsL NbZmA3KDny9w1ynNfd6W+1gtSzxY+rdnrhlwSNj+xS9IxGKu4lrBAt88kIrO5oubB6 BEjjY7rHYBhyegDIPP9K297L+ciuLgLeOPC9vC+U=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.848
X-Spam-Level:
X-Spam-Status: No, score=-0.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ndv-Mv4VFavP for <tls@mail2.ietf.org>; Wed, 24 Jun 2026 10:25:51 -0700 (PDT)
Received: from mail-lj1-x229.google.com (mail-lj1-x229.google.com [IPv6:2a00:1450:4864:20::229]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 31459106A5712 for <tls@ietf.org>; Wed, 24 Jun 2026 10:25:23 -0700 (PDT)
Received: by mail-lj1-x229.google.com with SMTP id 38308e7fff4ca-3996f80800bso1032631fa.1 for <tls@ietf.org>; Wed, 24 Jun 2026 10:25:23 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1782321922; cv=none; d=google.com; s=arc-20260327; b=hNM5y9yrQFQMz0M4x+Nep5sEV9ivcdLjqfdTLEojbcSGz78XUBNAYCLEs7U8ZcHooF 2WwmjJQH8w3Soo3iFevkPumEOPBjr3TxwNB5WrLFw+m4dqCN1UAt9tSzZWlMJgbM5BcE obh1MtjY0Q/SGFx7aKWUgcB8UHLsfEGWsBOMAlcd9mMggi/n+OpJDhWjn8/nFNHQfgdF hcybUlkk7DuRWMfFOON1IPy58QMpwfCgkN4yvbT8myRDm3Bn+ijOhvzRYlk98CEhPG2L nTC2O2ttIkLXAiuz+D+05cpfe6wHh8dVroREvd1u2M5bzECu12Y+WTVvtpEiMK2F4kFG ALyg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=mAttAzKn7R6AQImgKz6BI+AbvsvslMWAyInKiPsT1Xw=; fh=0Z+UoFJgLSix4LirSLkWv3xkw3QVAd6P4ALzvMNb75I=; b=CNrEw/IjgyQqUZcdmzSzAhDUUq79Pa1eWd0g2gqHdk4ozE3VGVh86Uf2a2bSv4Nub1 Y1PPwgmXrhj75LQF+/Wnkc1CALJXxRzCSZi1659ckf7ZoT+Wg+gmgS72eav4RxNRWK/L TJC4svwKbWqLoPmQF2jaHpjbdi1Zf4c26HH60asAAVwZcH7jalDovBjWTXRjga+t5U1z etb5q8EQa+w4I5WdAKCWfTzYVgv4GW43UONG/ujhSq0juStkeN+B9x+ctD13JxS/XM/2 0Sv26YINWq2OHeKNc3oHIPSBMTYiXi97XN3voz0LBd6Y6kYuL7tnD1xI24W/tSwIj7vj i4Hg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782321922; x=1782926722; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=mAttAzKn7R6AQImgKz6BI+AbvsvslMWAyInKiPsT1Xw=; b=n+TgBRHBJaMQpeDRplRZter5jONcN99CUL8abjsMCI27dTyqJGjCAjtUyGYhpEoljH zSsKTDDeaF5JJCs6H7T33eTRDpyi2fpin9jJxdbYhJpt6+sKbcMOuWDD+l6aBSTt1Hfe pd63W9ebqeQBap7dP6P20U4ZkTfV6u0CS2WXJ/xjpTNvmOfFwnwKmFckv5kYJLQr9P7A x6YBaBAwvHve9fAsDGqDOQQU8ciSZQxHwU00g887L9keu6UvTMuHWJLy5EG4xEON5etD Lmvh+2L+lLsKJOZMOFTqef05fP9+ama0DIKxY7o3afH2Jn0EgmuD5TfWpj145l0uwJ3B clug==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782321922; x=1782926722; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=mAttAzKn7R6AQImgKz6BI+AbvsvslMWAyInKiPsT1Xw=; b=R27t+LCir8EC//1tyN3ifkTk8S7UGIKK8aTmoYuUp3lb/HSjjQz1AjRfEg4xVfugs1 yNZYSGS0GVQAx9QU1EFRUOqKWLXZ2C6K8H89gK/ec/gOHBKYBUKNXKJKofJajUCijKfR QOKM734g6PD9/BIh/6MKPXloZIijalKuUAPVbRxXr9xDk0hAplMq/Ll4c2U7+UVj9rJf C0VemCrsDNuEu3TuNEZDubUaByyZg9BiXpIheIYZq5XKFwN5Ty5r9eZi0koilOd8mD3i zDlQX+PcnuK1CsVMuN6+z33sBFogEcUnT+ykEpUauZkauFCM/ThoPHk3bjXFcShszkqj vYLg==
X-Forwarded-Encrypted: i=1; AHgh+Ro22i6D65Ij9ZeRfp+CYacbuoJcp143exkF5BwLON4AW6/Bzk1PkWEr5L4zIyTGoUbOIyw=@ietf.org
X-Gm-Message-State: AOJu0YyC7ZZV2y1Ff/B8mgfBTx01PmK1Pm8HBIrRES6a/HqbwNK9ctXS fR/Lnad1du7U4kvrrO9XHY1qxRZa7WlsCDqM3OeSRHV+vCsS0GlMlx1QuKYZB8N5FSdw0G2k77H 27vsAlFwzq6FDKY90p4K+Nyj2MOXfCHs=
X-Gm-Gg: AfdE7ckWMaiojBEzIFVrTpd2E32SGsZI0TzGoL+RWsI41yh4E3p93RhrdG9cKAjVd0T PDLmgXHXabO9HMFhLb/k5mvtUVE6ijPAs90+sVpw/8VvXrgeM8eevQqGfvL21AsySpsgK7hZ7kD lRQ8NCf5XDBfGXfNgBNwzJHKk+DYUgX8/9UPQ6Lm07WB68+4a3Uu7bumrpDb1coVmxt6LdLgiAd Z3vGRgy1AF432NRLakFdB6gV4rJ5obzTPa9fMRUUGc4tszhPTjcdTDQ2jrd2WeD2gerqKqgrcP4 5yAAGseyUzFM5i6JpcCRP57u2QPfKA==
X-Received: by 2002:a2e:bc15:0:b0:38c:c0de:d58f with SMTP id 38308e7fff4ca-399c54a6543mr24857581fa.14.1782321920584; Wed, 24 Jun 2026 10:25:20 -0700 (PDT)
MIME-Version: 1.0
References: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg> <CAHxYnaOm8nZVMjA7c-_0BmiC2wvZNOsAK857hBdkgwGJ7Noneg@mail.gmail.com>
In-Reply-To: <CAHxYnaOm8nZVMjA7c-_0BmiC2wvZNOsAK857hBdkgwGJ7Noneg@mail.gmail.com>
From: Deirdre Connolly <durumcrustulum@gmail.com>
Date: Wed, 24 Jun 2026 13:24:42 -0400
X-Gm-Features: AVVi8CeWboV1539GAI0ucAW-4dZBkG9e8WnwjMNhcW-juB7Y1EBz1EzrUKdPsiM
Message-ID: <CAFR824x5g7uMJqPbaTV-qS7VHN1=HgDPTOYJoY+A8UwXn3ea=g@mail.gmail.com>
To: Nathanael Ritz <nathanritz@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000f3b2da06550328b6"
Message-ID-Hash: KA4VKKNVXMJ22GGXWKHROLDMBQU46TVY
X-Message-ID-Hash: KA4VKKNVXMJ22GGXWKHROLDMBQU46TVY
X-MailFrom: neried7@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-tls-mlkem@ietf.org, tls-chairs@ietf.org, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/eopnbm751W3sqsbSba96IaXnd2U>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

> There appears to be a citation formatting error in paragraph 1 of section
5 for "{KOBEISSI26}",

Fixed:
https://github.com/tlswg/draft-ietf-tls-mlkem/commit/b5d9d55f332121c3f3c92fd25e3c695889827cb8

On Wed, Jun 24, 2026 at 11:53 AM Nathanael Ritz <nathanritz@gmail.com>
wrote:

> I support publication.
>
> There appears to be a citation formatting error in paragraph 1 of section
> 5 for "{KOBEISSI26}", otherwise I have no concerns.
>
> Cheers,
> Nathanael
>
> On Wed, 24 Jun 2026 at 09:00, Joseph Salowey via Datatracker <
> noreply@ietf.org> wrote:
>
>> This message initiates a new Working Group Last Call for
>> draft-ietf-tls-mlkem[1], which defines standalone ML-KEM key establishment
>> for TLS 1.3. The main question before the working group is: "Should the
>> working group publish a document specifying stand alone ML-KEM?". If there
>> is rough consensus then we will push to refine and publish the document;
>> otherwise, we will stop discussing the draft and not progress it. Please
>> respond to this call indicating whether you support publishing a document
>> specifying a stand alone ML-KEM. Please refrain from further discussion on
>> this topic as most arguments have been discussed multiple times.
>>
>> Why are we holding this consensus call now?
>>
>> Significant developments have occurred both within this document and in
>> the broader TLS ecosystem to address the concerns raised in the last WGLC.
>> Therefore, the third consensus call is warranted. We ask the working group
>> to consider document publication in light of these recent changes:
>>
>> - Promotion of Hybrids in draft-ietf-tls-ecdhe-mlkem: Following a
>> separate consensus call, the WG agreed to promote the X25519MLKEM768 hybrid
>> group to Recommended: Y in the IANA registry. Consequently, the IANA
>> registry will reflect a clear community preference for a hybrid because
>> Recommended: Y clearly indicates this while the standalone ML-KEM groups
>> defined in this draft remain Recommended: N. The updated security
>> considerations in [1] reference the IANA registry to emphasize this
>> preference.
>>
>> - Key Share Reuse Prohibited in draft-ietf-tls-rfc8446bis: The WG
>> recently reached consensus to explicitly prohibit key share reuse across
>> connections in TLS 1.3. The new text changes the guidance from SHOULD NOT
>> to a strict MUST NOT. This resolves the concerns regarding static key reuse
>> and its associated privacy and forward-secrecy risks for ML-KEM.
>>
>> - Nadim updated the ProVerif model of TLS 1.3 to evaluate KEM and hybrid
>> KEM groups in TLS 1.3. This supports other results which show that KEMs are
>> secure when used in TLS 1.3 and that hybrid groups are secure even if one
>> of the components is compromised.
>>
>> - Liaisons: We received liaison statements from multiple SDOs including
>> O-RAN[2], IEEE 802.11[4] and from 3GPP[3]  expressing support for the
>> publication of draft-ietf-tls-mlkem as an RFC as they rely on the IETF to
>> provide a stable normative reference.
>>
>> Please note that a third-party IPR disclosure exists [5] against this
>> document regarding patents related to the underlying ML-KEM algorithm. This
>> IPR declaration has not changed since the last WGLC. As a reminder, per BCP
>> 79, the IETF takes no stance on the validity of patent claims, and the
>> working group may decide to proceed with a technology despite IPR
>> disclosures if it decides that such use is warranted.
>>
>> Conduct Reminder: Given the heated nature of previous discussions on this
>> topic, participants are strongly reminded to adhere to the IETF Code of
>> Conduct (BCP 54) and the TLS WG's Mail List Procedures. Keep feedback
>> professional, technical, and focused on the document's text.
>>
>> This working group last call will end on 2026-07-08.
>>
>> Joe and Sean
>>
>> [1] https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/
>> [2] https://datatracker.ietf.org/liaison/2198/
>> [3] https://datatracker.ietf.org/liaison/2151/
>> [4] https://datatracker.ietf.org/liaison/2148/
>> [5]
>> https://datatracker.ietf.org/ipr/search/?submit=draft&id=draft-ietf-tls-mlkem
>>
>> _______________________________________________
>> TLS mailing list -- tls@ietf.org
>> To unsubscribe send an email to tls-leave@ietf.org
>>
>