[TLS] Re: Charter complaint to ADs regarding draft-ietf-tls-mldsa and draft-ietf-tls-mlkem
Nico Williams <nico@cryptonector.com> Tue, 22 September 2026 11:19 UTC
Received: from skyblue.cherry.relay.mailchannels.net (skyblue.cherry.relay.mailchannels.net [23.83.223.167]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id 1702031; Tue, 22 Sep 2026 11:19:22 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=cryptonector.com header.s=dreamhost header.b=HtJr8Fie; dmarc=none; spf=pass (mx.ietf.org: domain of nico@cryptonector.com designates 23.83.223.167 as permitted sender) smtp.mailfrom=nico@cryptonector.com
X-Sender-Id: dreamhost|x-authsender|nico@cryptonector.com
Received: from relay.mailchannels.net (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTP id F1D457E337D; Tue, 22 Sep 2026 11:19:15 +0000 (UTC)
Received: from pdx1-sub0-mail-a222.dreamhost.com (100-99-162-101.trex-nlb.outbound.svc.cluster.local [100.99.162.101]) (Authenticated sender: dreamhost) by relay.mailchannels.net (Postfix) with ESMTPA id 965FC7E3256; Tue, 22 Sep 2026 11:19:15 +0000 (UTC)
X-Sender-Id: dreamhost|x-authsender|nico@cryptonector.com
X-MC-Relay: Neutral
X-MailChannels-SenderId: dreamhost|x-authsender|nico@cryptonector.com
X-MailChannels-Auth-Id: dreamhost
X-Share-Eyes: 61190f1569aa7b19_1790075955851_247970182
X-MC-Loop-Signature: 1790075955851:1019350998
X-MC-Ingress-Time: 1790075955851
Received: from pdx1-sub0-mail-a222.dreamhost.com (pop.dreamhost.com [64.90.62.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384) by 100.99.162.101 (trex/8.0.2); Tue, 22 Sep 2026 11:19:15 +0000
Received: from ubby (unknown [24.28.102.31]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by pdx1-sub0-mail-a222.dreamhost.com (Postfix) with ESMTPSA id 4hpyKZ6hgBz35; Tue, 22 Sep 2026 04:19:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cryptonector.com; s=dreamhost; t=1790075955; bh=+b511X1Lpm84gwnUlzWUNNzBjdh+BrLxeGH0mw/psZU=; h=Date:From:To:Cc:Subject:Content-Type:Content-Transfer-Encoding; b=HtJr8FieX1PdXxF9gX0X6x2jTkd5hFMGZDnPFG+++7cI9WedZI7274J4Te/Vw7uJi Z3VD5MSq9pUQaLjsPnN+o6Y10zmgLRquKYk/EsFyhvw/HAm+MRbPNlyxfyd8F9Flk9 nu2E/q299xTA80z6fzdq/ayZ1Py2/GucAXY8NLGC4zfT7k/CwLpd/Q8dHDNcd6/U4C xPr539UR2vjBYDbCcUfMuztLAL3D9qapAC3+B0l0s5XGwBtZl3xHXUZZR1BqpVfiH2 1s8pXLqgeqBIIGALbIYGdqi2cTC6pURIR8zPKRKv+5kVndjEp5/vgLmul/l0ZVp0YG iW4wxLsvYxsOg==
Date: Tue, 22 Sep 2026 06:19:10 -0500
From: Nico Williams <nico@cryptonector.com>
To: John Mattsson <john.mattsson@ericsson.com>
Message-ID: <arJkLvRqxjyCl7w3@ubby>
References: <AS4PR07MB88251B87ED337467B8EA6DA989832@AS4PR07MB8825.eurprd07.prod.outlook.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <AS4PR07MB88251B87ED337467B8EA6DA989832@AS4PR07MB8825.eurprd07.prod.outlook.com>
X-Spamd-Bar: /
Message-ID-Hash: ACWTYEOXY4HG532LY7VF6JXYSSP3PJTV
X-Message-ID-Hash: ACWTYEOXY4HG532LY7VF6JXYSSP3PJTV
X-MailFrom: nico@cryptonector.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "D. J. Bernstein" <ietf@box.cr.yp.to>, "sec-ads@ietf.org" <sec-ads@ietf.org>, "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [TLS] Re: Charter complaint to ADs regarding draft-ietf-tls-mldsa and draft-ietf-tls-mlkem
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/fDl3N2vehVJHbjTgVhbNmJ6BCrs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Tue, Sep 22, 2026 at 06:45:19AM +0000, John Mattsson wrote: > >But surely a WG's charter binds the WG, not the IETF? > > The IESG is ultimately responsible for ensuring that documents > published by a WG comply with the WG’s charter. In the case of > draft-ietf-lwig-curve-representations (Internet Area), the charter That one doesn't sound like a LAMPS work item. The ADs could decide that it ought to be a LAMPS WG work item, of course, but it doesn't strike _me_ as such. My point is very narrow: a work item does not fall into a WG then the WG's charter does not apply. > violation was caught by the Transport AD. In the case of > draft-ietf-lamps-pq-composite-sigs (Security Area), nobody appears to > have caught it. > > LAMPS is chartered to specify only the use of quantum-resistant > algorithms from NIST or algorithms vetted by the CFRG. > draft-ietf-lamps-pq-composite-sigs specifies the use of new > quantum-resistant algorithms that are neither from NIST nor vetted by > the CFRG. draft-ietf-lamps-pq-composite-sigs specifies composites of ML-DSA. That seems to be squarely in-charter. If you mean that the resulting composites are not secure, that's another story: > The document in question specifies new quantum-resistant algorithms > with new algorithm identifiers and substantially different > cryptographic properties from the NIST algorithms. In particular, > these algorithms introduce two distinct malleability vulnerabilities > and destroy the BUFF properties. The absence of such properties has > contributed to significant practical vulnerabilities in the past. The > composites do not even qualify as hybrids under EU and Canadian > definitions. These new algorithms have not been vetted by the CFRG. But your point was that it was outside the LAMPS WG charter. Is it? > This casts serious doubt on Bernstein’s accusation that IETF > leadership intentionally violated WG charters to publish standalone > algorithms, which he describes as “playing procedural games to damage > security at NSA’s request.” The apparent facts point in a rather > different direction: IETF leadership appears to have allowed a WG to > pursue the publication of composite algorithms in violation of its > charter, apparently by mistake. That's a subtle distinction. Both of you are saying "IESG bad", but for different reasons. My point was very narrow and not directly relevant to that debate. > If the IESG takes formal procedures and WG charters seriously, which > it should, it should stop publication of > draft-ietf-lamps-pq-composite-sigs as a LAMPS WG document under the > current charter. That requires a careful legalese reading of the charter. Nico --
- [TLS] Charter complaint to ADs regarding draft-ie… D. J. Bernstein
- [TLS] Re: Charter complaint to ADs regarding draf… John Mattsson
- [TLS] Re: Charter complaint to ADs regarding draf… D. J. Bernstein
- [TLS] Re: Charter complaint to ADs regarding draf… Livingood, Jason
- [TLS] Re: Charter complaint to ADs regarding draf… D. J. Bernstein
- [TLS] Re: Charter complaint to ADs regarding draf… Livingood, Jason
- [TLS] Re: Charter complaint to ADs regarding draf… D. J. Bernstein
- [TLS] Re: Charter complaint to ADs regarding draf… John Mattsson
- [TLS] Re: Charter complaint to ADs regarding draf… Viktor Dukhovni
- [TLS] Re: Charter complaint to ADs regarding draf… Yaroslav Rosomakho
- [TLS] Re: Charter complaint to ADs regarding draf… Viktor Dukhovni
- [TLS] Re: Charter complaint to ADs regarding draf… John Mattsson
- [TLS] Re: Charter complaint to ADs regarding draf… Viktor Dukhovni
- [TLS] Re: Charter complaint to ADs regarding draf… Nico Williams
- [TLS] Re: Charter complaint to ADs regarding draf… John Mattsson
- [TLS] Re: Charter complaint to ADs regarding draf… Nico Williams