[TLS] Re: WG Adoption Call for ML-KEM Post-Quantum Key Agreement for TLS 1.3

David Adrian <davadria@umich.edu> Tue, 15 April 2025 22:04 UTC

Return-Path: <davadria@umich.edu>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id CED771C94AC1 for <tls@mail2.ietf.org>; Tue, 15 Apr 2025 15:04:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.395
X-Spam-Level:
X-Spam-Status: No, score=-4.395 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=umich.edu
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gGYk-i4kUTxW for <tls@mail2.ietf.org>; Tue, 15 Apr 2025 15:04:48 -0700 (PDT)
Received: from quirky-dwyfan.relay-egress.a.mail.umich.edu (relay-egress-host.us-east-2.a.mail.umich.edu [13.59.128.245]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9F55F1C94A45 for <tls@ietf.org>; Tue, 15 Apr 2025 15:04:31 -0700 (PDT)
Received: from unshaken-crocotta.authn-relay.a.mail.umich.edu (ip-10-0-74-179.us-east-2.compute.internal [10.0.74.179]) by quirky-dwyfan.relay-egress.a.mail.umich.edu with ESMTPS id 67FED7EF.B90DD48.F10B65.2789091; Tue, 15 Apr 2025 18:04:31 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=umich.edu; s=relay-0; t=1744754671; bh=Rm1kcjGJbOZJ3KKrVqQC/R4uQ6zQu4m1CB+c1szxoXQ=; h=References:In-Reply-To:From:Date:Subject:To; b=gSGRZHkBRIc7QeHaR3neRd5YEmjJBVWqOWi/rOCTAaKhE/MAwcRSZmK6qrqU7qkwA Rr553YBl+qmkxZFalAmdWeWyKDt79ICo3OvWLC0Jmk1J1TuiNpsM/ffKsG0fDyERV5 9TEUsjHjd1voxRqHg+0K2VlZx8yr70TxQxZJvRNBbOwjYyc96jApOjwr2XIZoqiGEp svBjZq68n1rPXIXJeR8MbZRsgEU+u3QdQwd5m71U8HSGDtxpIG70k8ZCIxU2OrH6S5 017CcnDkISAPm7zfHtrwFVN/sz175CYoel5jTDpNy5tcRY2ZYPGQjCyn6b8d47pFf5 H1El3H5nYyKuQ==
Authentication-Results: unshaken-crocotta.authn-relay.a.mail.umich.edu; iprev=pass policy.iprev=209.85.222.173 (mail-qk1-f173.google.com); auth=pass smtp.auth=davadria
Received: from mail-qk1-f173.google.com (mail-qk1-f173.google.com [209.85.222.173]) by unshaken-crocotta.authn-relay.a.mail.umich.edu with ESMTPSA id 67FED7EE.355F1DAF.18067624.2163485; Tue, 15 Apr 2025 18:04:30 -0400
Received: by mail-qk1-f173.google.com with SMTP id af79cd13be357-7c0e135e953so634295785a.2 for <tls@ietf.org>; Tue, 15 Apr 2025 15:04:30 -0700 (PDT)
X-Gm-Message-State: AOJu0YxjYUiwL30nyTFDxjWb9TpCm/3Xh4wgySDYeMAvU9MEUzBx12Mj ihHV0eG5AYmXzVb2R+yfnwM0+Pv3Y18mroUInMhUTVoTWk+dsWC+zKPR/+fIbTYGXKCCEmg7S3O ljZl/ChKmf09GQXSLqmsaUgEjWlg=
X-Google-Smtp-Source: AGHT+IEBLXRrkfQND1N0MnBdoZEB9OS1FUrzcDp76/hGghLGydWQ8OW5nAtJFd1hmH5nsdlbOGvxqWH8M2RV5h7Zdlk=
X-Received: by 2002:a05:620a:2a0b:b0:7c0:c469:d651 with SMTP id af79cd13be357-7c9142ba9f7mr164857485a.57.1744754669867; Tue, 15 Apr 2025 15:04:29 -0700 (PDT)
MIME-Version: 1.0
References: <78F26652-C656-450F-A92D-BD53F8E743AD@sn3rd.com> <20250415195351.229309.qmail@cr.yp.to>
In-Reply-To: <20250415195351.229309.qmail@cr.yp.to>
From: David Adrian <davadria@umich.edu>
Date: Tue, 15 Apr 2025 18:04:18 -0400
X-Gmail-Original-Message-ID: <CACf5n78yQ7FMSQoaOx02rKF4VCVzf7nVSmkMaWMmakrmnd8tMA@mail.gmail.com>
X-Gm-Features: ATxdqUGspvoE3DgRPZwY4FtS2JvZyu4-iNlsoZdgmVgGnJ_oF9uB79FOao9vpZc
Message-ID: <CACf5n78yQ7FMSQoaOx02rKF4VCVzf7nVSmkMaWMmakrmnd8tMA@mail.gmail.com>
To: tls@ietf.org
Content-Type: multipart/alternative; boundary="000000000000515c260632d85afe"
Message-ID-Hash: CS542O7VMMEDLALEMG4TS6WL6I33SRMB
X-Message-ID-Hash: CS542O7VMMEDLALEMG4TS6WL6I33SRMB
X-MailFrom: davadria@umich.edu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Adoption Call for ML-KEM Post-Quantum Key Agreement for TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/gBeQTdXRfDrkcsTmyGGyt_RHn7k>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hi Dan,

Draft adoption is based on rough consensus, not unanimous consent. As I'm
sure you're aware, RFC 7282 states that all objections do not need to be
accommodated for rough consensus to be achieved. In particular, the IETF
values running code, which this draft represents. It sounds like you're
advocating that your objections should be treated as a veto. Can you help
me understand why you think the chairs did not account for your opinion?

Thanks in advance,

-dadrian

On Tue, Apr 15, 2025 at 3:54 PM D. J. Bernstein <djb@cr.yp.to> wrote:

> Sean Turner writes:
> > Hi! It looks like we have consensus to adopt this draft as a working
> > group item.
>
> Um, what? There were several people (including me) raising objections on
> list to basic flaws in this draft, such as (1) the failure to provide an
> ECC backup to limit the damage from further security problems in the PQ
> layer, (2) the failure to provide an engineering justification for this
> option, and (3) the lack of any principles that would justify saying no
> to options selected by other governments if this option is allowed.
>
> Your message doesn't explain how you came to the conclusion that there's
> consensus. Surely you aren't relying on some tally of positive votes to
> ram this document through while ignoring objections; voting isn't how
> IETF is supposed to work. So how _did_ you come to this conclusion?
>
> As a procedural matter, this lack of explanation is in violation of
> "IETF activities are conducted with extreme transparency, in public
> forums". Please rectify this violation immediately. Also, please state
> the procedures for appealing your action. Thanks in advance.
>
> ---D. J. Bernstein
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>