[TLS] Re: WG Adoption Call for Use of ML-DSA in TLS 1.3

John Mattsson <john.mattsson@ericsson.com> Wed, 16 April 2025 09:00 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id F312C1CDCE61 for <tls@mail2.ietf.org>; Wed, 16 Apr 2025 02:00:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ericsson.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Edt10R-9k5ha for <tls@mail2.ietf.org>; Wed, 16 Apr 2025 02:00:34 -0700 (PDT)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2080.outbound.protection.outlook.com [40.107.20.80]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4D75E1CDCE4C for <tls@ietf.org>; Wed, 16 Apr 2025 02:00:34 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=h3b762Malw2NsWn/3ZFicXAv4MF3x3/5j+0WKrAoZ5uicnKY/nlFl2SXe6WKFfvnqi/u5dQHhMIAQtDEBhs8Q63JInAs1DWltifw5rND5kXrNzwhtdjzy3OcUKsMBsC3hfb6/zlpBX3CJF3gIwoKiP+ioh2O9sMDMlvES8ZYMuIrpDerPoqJUZJBs98/V28NrBd+rvC9xijmYddsgJT7HlsUu5Ch2l0g7ivL8vWPgma45qNixYK0ukE4SI2mG/svxfhwBFIw3Iu6Pnfsa0hk1Aqr8NWKpidJAyILnYjpI01Qdn2Ubaa9qYLuTjVC4edj6tPV+Qo/lUYD8gkdnSZIog==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=o8ELUdFaVcpF+s7q0z2u5huW1vy1D6iYT/x5cQwkz6g=; b=MWC+1T9te+n3h3pkItRpQRgqvPtR5chHJ+0l2ww/9hVzMgqFUxzKQfNnRYDN2F1PEZH+uhNH7QKRU/d55WSMMNTtfiO7aFM3N4apsUuJegbvZXcJrDfdCe7QOqCzxAFDwCtfi1VW6O//Ye1pxDVJpLJ6EOwF9w4JB043diEUcFTvqbkYFVlwpFhH1vkNCHQWw5cGx7HpxFbzuCj/jgTJws+12WU2xt/Nye+4ajOYURyp7ykE/Y+mtfPmfEoXmV87w20a9vBMWKblLnM581AGlJjbhGNKnLbEDPat8tYHilysjVFxuJERW4RpgS8Svre+y54ucVCqjpvLgn/4xK6k4A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=o8ELUdFaVcpF+s7q0z2u5huW1vy1D6iYT/x5cQwkz6g=; b=T/hlQ4mMnuwV3YfnrlCX6o+6bsab5+ME16jrt6l1JINkBg5RoWHh52cN0GaPlRzGoDh7q93U8Lz6znTc3CoRznmaacQEgs/fz9E0Ne5Ecxka8LkxSRQqnDacLgiTPi4pxny88KHLRwJ3DXJHZNvNOvFlvv+HWWaCWKqljX6n3fTPT9NaCy/MJV9MQqSYgfM8aMsGaSKxjBO0rrkCEE15Z4C+eYxPXoiLh3ndqHleyadVB4OzhOxBQMIqFCODZkOXv0KIgp4ErwGfmPIPo1GZyhSRrQt0JWT2eo7+3IQ0WHQM3Nu0Lm/Zre7OaMKuxIFUhktBD43bDchxA9g6V5L91A==
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com (2603:10a6:150:114::10) by AS8PR07MB7592.eurprd07.prod.outlook.com (2603:10a6:20b:2ae::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8632.36; Wed, 16 Apr 2025 09:00:32 +0000
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::bcf3:3f45:888e:a4b8]) by GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::bcf3:3f45:888e:a4b8%7]) with mapi id 15.20.8632.030; Wed, 16 Apr 2025 09:00:32 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>, Eric Rescorla <ekr@rtfm.com>
Thread-Topic: [TLS] Re: WG Adoption Call for Use of ML-DSA in TLS 1.3
Thread-Index: AQHbri1aZih/BbJQIUmdRYk9gIX73rOlFreAgADGY4CAACJkkg==
Date: Wed, 16 Apr 2025 09:00:32 +0000
Message-ID: <GVXPR07MB9678CFC5FB54B1171A30231689BD2@GVXPR07MB9678.eurprd07.prod.outlook.com>
References: <07CB46EC-758E-4204-901A-CC8812B33A5F@sn3rd.com> <CABcZeBMDKGQtMMaKASsV74U7p-vXQr8Fj+AbqAjHwpsQJY_B9Q@mail.gmail.com> <CAMjbhoViK19e6vYf1JwVJz9pJATCtKodgSPXMfQbC9yGaeVifg@mail.gmail.com> <CAMjbhoWxD-_N7dNhEMW8X4PAF8NvsT8Mt8fGYPu68=J1H6KRbw@mail.gmail.com>
In-Reply-To: <CAMjbhoWxD-_N7dNhEMW8X4PAF8NvsT8Mt8fGYPu68=J1H6KRbw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GVXPR07MB9678:EE_|AS8PR07MB7592:EE_
x-ms-office365-filtering-correlation-id: cbde41c2-84a0-43c1-e11b-08dd7cc52498
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|4022899009|376014|366016|1800799024|7053199007|8096899003|13003099007|38070700018;
x-microsoft-antispam-message-info: OFxnjLYlyqKWl74h0bL3iblSPprZofah/4cGD4Ssuvei5o7INQYAkQxKbPOtFeFAzr8uH+kSlX4gBJCLbXtePM6wKOyhcMci4HrYLIqGyLyb8DE6yALWGes7WBqFd4YNGIqkImiUIQ2GF+/aQN3ZclmlLBRD32jdvMGqdUXpVjdnJMx74lUMf5J+8y7SmjlWe4W8zQCLngSBW/7fLOVLCat554H9tJuiei6r9GgBxMiPwRgtpKFYzoqBku6KDWm/zGk2AQo6dOix2+ykMGqz3h0W1l7fFEIc8URL1M3nlr5pWzFROyXLl8kk4nh28BpGoL+vJ5Atsfdou2tQ4hRRCaF+TyM3KOADbGicM+VJjFlyhuSwi2KaDFbQZXUXP44M3jU7xMgWJqstv+9PbiPIuAYOODHq19vzq5xWDqHMqJyTIl55w/T9u8Lbk/YByJ1RZrdbf/hJ3e1b0fhIzGY+l5u3xYa7WTbsZA5TFFDreyxnjV0fpksQ0b9yB8ZjXzm2S07/3eyNnNpYwZu4CizlnsBs1zPfXEDfplcnYmtZYUckV4m3y813Kxrr+pdbldVoRa6sgHSlB8mtzpgFvto4jpQHtWy48MT+JcIlquGrw7PYrRa38xsT0dIXTZt4/8LtCopDhpw/di7nIKiaGHRgaeL9hu+iCzPl2nQno88soRvviQ+dolHtyq/y3JMPhpM4/+qluTGey1cscC/mh0ADBTaFPapC5b1q4TgjUslitRXwd4vu1fXke/h056Zb74NsMt12MNlssWI2LXVOTpNwR1Jhswd1HDKvgJNGOqXd0ywKv2/KzM7hXP7R4z03ctp8KvCsW+mAyDFgRl7VfFhrd8L3TqlDZ1r8nHAndTJpo8UxiMu60xQss/Se+1ZvtxoU0jtc7+0qr7qssrEbrVqmUQ8bZyhO0UC0NeYi1GSGpqCmNWFsNVw2LsTCmA9A+z+PzkBJX7x8jAqEnut930C/z8PRJHgagxr5vESeIHeEfx1rfvR0KreSwW71TYWYmIr3G1EwZRcqxCvzqYD3amtdNfD6WYd76zSm5qn6miojSprUSrsTZ4IB9A6i/M6yOtXnggpaJhBv0uwY6sFxP0FCQJX51KzHcQmGPbplhnquwOUpNCGVSyQ9q8DglSmQj7Zs5W3E5c3fCwXYuixSh58kk52V7l204cgAclR1MJIayk8t+0N5INlL9nrvJk5ZFHX/m7up8esaJKQyFj5cRB9bZ9PhJUeGNLU96liV5ZdNLqlNVWBh8HsI0S2lYRj9YcCPXw9sh9ZNvsAt4UdKGIqpMZQ7whOJ7fL6ZBQu+zpct3EZwn0ULYdtMaV8FgHtK8OZ3L3JCkGgqy8qW5OyutySWo2daOHUPB+Bj2U4zcDDMEkhinjEgiownk1WKkarqYGxTviPL1MvsLrAcOBBz2khBsAmq3ep8nLYONSUC7dt95ORiHAYdlQOHlDUNm23I6dS42yfdSioQ62BzkpdC435GMNM0Y4BGd2uENPGYGDirLU=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:GVXPR07MB9678.eurprd07.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(4022899009)(376014)(366016)(1800799024)(7053199007)(8096899003)(13003099007)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: jpfleEMswyBUH3J+oshhkLRWqSuZo0X1zWLqoTD6av4U+w+XffgXFsCQEq2f25qn7wrS0EyaKagM+DBwk++kDZDbTxVcq96LsnnyH0DFbSAmOGtZ4bigoOiNFpue/c3hATeHyczdXF4x2oZ/U9l7q+gNbXaxM6yCLChLa34W9Gl1sNkiSQoO8wZ/UnDWMqHJaTjdOV+EvJ66N5O2qObpcYLT9IAgCucyal6uZB2ST7K+UuQ5dsH1/3qnNlWCdQdFRtkfaLGGAhCswyqmr4w/JNDeJwSIlg51WKjbjziqzfXSqhq3QzQBJru1KFhftyqSsQKLD1gDGX6mykb+m6g7iK9BKQm6RVw5Qfo0orSAdBQhMQACkJ/RIuCcj7PGI/nvJcW6PuXnYDbwmZdSTJl8SLxEIlOrj8KVBLNRhY+faxE94AQ7t55SE5JzaTkVIyLQ0K8fnvTLgKitQB3l0G+ntoqOM7zLvE56aXh8pQh6jOLTHkKZTtQo+NhQ6fS2hL5Ev9LKY88/GYwPhBtuJ6iffkWEQY/7J5zBgPLaMuw8q2Y405rlty18A76Jfe+Di4XHOdbMQGnir9dh64mufC/dvfVWXoE+AfYtPS0GE/RrZsuM21k1YDkv0ZbO8FnSaS4LERUij8v+mXWc91GGu10WfOGeR+CnbJzh3yQ6Hox5Jxc+2jM4qjGRLJEl+3UnMuq832g7Rr+xVVjZE67j7qSfoZry2NuB4OxCgaHtWEzb20Ok2WyBn3xKNDwKAPuQGw89lCECjJ3G6TCYjf68hWZaAE39ZLDa+s7SWr4RZvTLJPEwze0F4QjC4OayRhYHN4KPIsZM9TK9AhNTNXSi7tFtxR/NEf7IXM4I6gdKxS7WerMtUkAbHvPZx3jG4VvWPtzXOL19e1iULFIVwUOrXsvaGZj+0b78uZoq0jqeZoYXCRKN0LUos+GKduaQHFqWCJaWRaVzR8gBpy6azO3trGH96JnBHBeL1PpcqmGN5n6O0fXJpuHjmgLfc7Cg5xnLdH6R4PIEo1VFWQ6k7xfFcoCZ0SrwMUDXKJAg45P+8amdR37pLcPA1wCU4aNAPa59fm6BI/dm+mhO9Qe3KNrj14OhGQm8VGxUC3LyRuGRniESrml8r1f2xLnVS0V57UVOGTJysYc+emIqq7wMd7Y2MSFEpfub5G1pXPQbRbzuZmfa4TyOUIsz8p7FDPgTOHaKu0WLECtrStZL52D7e+oWGAZspTP8sjbvmNQ4Me+7abLT7kdex/0yzFo+fY6whSvB3Gww50BpEN6mAsQcditMCflnMBW078SJRMjOiTcn2u/dJln528O3NVWWQCiEgXvr/SDc6JR30WvZJTJmYLWJfz3+8K7ZcJ1p+1vtr3tj7T9MqpPIMJ6vZwhQ4yeKLgbXBJUqNvCle8g2qfTJ45COOYqJKeUWsHDN2NqAS5c3wz5OA+CHFH+cDvJeq7U7VHOqM12bQbEvlr53tUgu+0sxT+iIMQXiTrjhUySJvXNFjDdN8FznDOOmrOY2LM6MaoSRZSwxb+lYKeG63J11k1g+2VDYgFbfF4s3GgUlJqgVnlsA+CJzRSc40oGqMha1plDgDPZkH7LkSQHbU/5nRTfHVS8FBVGCD45EvychT19TwunB3nA=
Content-Type: multipart/alternative; boundary="_000_GVXPR07MB9678CFC5FB54B1171A30231689BD2GVXPR07MB9678eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GVXPR07MB9678.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: cbde41c2-84a0-43c1-e11b-08dd7cc52498
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 Apr 2025 09:00:32.0254 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: nxY9b66zAgo2NS7/l+z3d1HwkaxQ7v7QpNZvVbBkF9dqdN5HISg2cdhVnUDyieKB6JmqKHO+GlR9FfkIQ9Ye09xkEdLu9uCi6Nu6tJoS2o8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR07MB7592
Message-ID-Hash: JKTLXL7T2MX6N24SM54AUKVNEIEI6PDM
X-Message-ID-Hash: JKTLXL7T2MX6N24SM54AUKVNEIEI6PDM
X-MailFrom: john.mattsson@ericsson.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Adoption Call for Use of ML-DSA in TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/i-uykqLx6zNS0OfjZiCAPM6BrCw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I strongly support adoption. OpenSSL 3.5 LTS already support draft-tls-westerbaan-mldsa. TLS is far more than the Web and the WebPKI. And PKI is far more than CABF Baseline Requirements. Critical infrastructure like telecom and national security systems will deploy PQC authentication soon.

Cheers,
John

From: Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>
Date: Wednesday, 16 April 2025 at 08:57
To: Eric Rescorla <ekr@rtfm.com>
Cc: TLS List <tls@ietf.org>
Subject: [TLS] Re: WG Adoption Call for Use of ML-DSA in TLS 1.3


On Tue, Apr 15, 2025 at 9:06 PM Bas Westerbaan <bas@cloudflare.com<mailto:bas@cloudflare.com>> wrote:
This working group has wisely focussed its efforts on post-quantum key agreements for the last five years. It's basically done. I have no doubt that if any unforeseen issues might arise in the final stretch, we'll rise to the occasion.

I suppose adoption of the draft.

* support.


Best,

 Bas

On Tue, Apr 15, 2025 at 7:41 PM Eric Rescorla <ekr@rtfm.com<mailto:ekr@rtfm.com>> wrote:
I do not think we should adopt this draft at this time. I would prefer the WG focus its effort on key establishment.
Once those documents are complete, we can reconsider signature.

-Ekr


On Tue, Apr 15, 2025 at 10:34 AM Sean Turner <sean@sn3rd.com<mailto:sean@sn3rd.com>> wrote:
We are continuing with our WG adoption calls for the following I-D:
Use of ML-DSA in TLS 1.3 [1]; see [2] for more information about this tranche of adoption calls. If you support adoption and are willing to review and contribute text, please send a message to the list. If you do not support adoption of this draft, please send a message to the list and indicate why. This call will close at 2359 UTC on 29 April 2025.

Reminder:  This call for adoption has nothing to do with picking the mandatory-to-implement cipher suites in TLS.

Cheers,
Joe and Sean

[1] https://datatracker.ietf.org/doc/draft-tls-westerbaan-mldsa/
[2] https://mailarchive.ietf.org/arch/msg/tls/KMOTm_lE5OIAKG8_chDlRKuav7c/

_______________________________________________
TLS mailing list -- tls@ietf.org<mailto:tls@ietf.org>
To unsubscribe send an email to tls-leave@ietf.org<mailto:tls-leave@ietf.org>
_______________________________________________
TLS mailing list -- tls@ietf.org<mailto:tls@ietf.org>
To unsubscribe send an email to tls-leave@ietf.org<mailto:tls-leave@ietf.org>