[TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3

Robert Relyea <rrelyea@redhat.com> Sat, 11 April 2026 00:12 UTC

Return-Path: <rrelyea@redhat.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3D356DA22997 for <tls@mail2.ietf.org>; Fri, 10 Apr 2026 17:12:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775866345; bh=Q7s2/LgaKO5/mNduM7Y1a+NtW8+FGJy4+SVjokd5eWA=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=uhgEGFDa5GOvvlp0GflwS+oAvQFEA0wmzs+PbCHWquXEzbU+LXA60r8KIXe1R3+6S jk4z/ID4gIXgyB5Ebhp6jrdLHHw/i3nJhb6YS6lzeY+iZQO85mzQ0KhsYrAIUbLxD2 S+PvpCl/oWNuvjDFxBlBWvpVrBUMtdh5exoXVcr0=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=redhat.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uWGMkcmKow6N for <tls@mail2.ietf.org>; Fri, 10 Apr 2026 17:12:24 -0700 (PDT)
Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9F2B5DA22990 for <tls@ietf.org>; Fri, 10 Apr 2026 17:12:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1775866338; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=YhZvwlZO25Gjh8jPf0u12PC9nVOwMDq2A0wkBCmAnXY=; b=U+YCjRejNt+MnpxHJVumaSLC6JtMsinZq7OKdK7SNaQBFW52tdR4mWAo91lzO0/glasDGK rc7xmj8SmcSybyx8j/t/1phrOBgap94G8AW8gRyWKiILxwqKUAbkVS8t/pMixO1rzp99i6 qFQSX3hqwvJnWmrxfJWjBFP8BqgpZCE=
Received: from mail-qk1-f199.google.com (mail-qk1-f199.google.com [209.85.222.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-552-6WWJUSheN4O0sNEQa-86pg-1; Fri, 10 Apr 2026 20:12:17 -0400
X-MC-Unique: 6WWJUSheN4O0sNEQa-86pg-1
X-Mimecast-MFC-AGG-ID: 6WWJUSheN4O0sNEQa-86pg_1775866337
Received: by mail-qk1-f199.google.com with SMTP id af79cd13be357-8cfbfac0e05so658201385a.1 for <tls@ietf.org>; Fri, 10 Apr 2026 17:12:17 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1775866336; x=1776471136; h=in-reply-to:from:content-language:references:cc:to:subject :user-agent:mime-version:date:message-id:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=YhZvwlZO25Gjh8jPf0u12PC9nVOwMDq2A0wkBCmAnXY=; b=TY0xqbD2Rx5eX9Biz5XPokJ3KIOusIJC6PnnRLAy671gVl+N2akKtag218+7t9gcyY dPgIYZFKfnXWEOaI+TpROHSXHzz6SJNqrmgTgmq1DgFg0bjNLYPtoBUNE9SlmNxlP8R6 IEl/jSYzpBPHy8ImcK0DpJx+j/JvFn8P5g3sAHPeTaubUmEU5Xeft8Veqoccb+mFYfdW x8B4bI0KGzXAzCr526/NkhipNTCIU9g7VNBhI+d0qO/P5XsXYDzcLRmsLA0MJlbrWOBF SeuCdm8U1gO4q1uTsazv/wPrbRfEpT3fCzA88a8q6RJnHIS5CHvhs2UhRd0qo5Xe22A6 wZoA==
X-Gm-Message-State: AOJu0Yx1LTZ1mFgG2ZzDdLGkZWT9FqbsjtkefRFY++xTWOl16x4a7bcR YTdkxgcIyHDuNoLOHWj8DX6EzI7G9ilX4dorwH/iQUhTkIOUtPg/4IbIfbzWatKjP/3ioiJpmOY IayHxRSeI1b5QWfavslSMtN4nnVqB0scBcsIe/D11B93dk9UKyyhG
X-Gm-Gg: AeBDievDBvdcZiIZEucd5Lp+cCbL9cbaNZDBGAUEvr6sMrd/LFvPS7p/o7XezL+4U9W ScNxH2ugXDw5274O1d0bdgXr+hFafhLXHDdVTpBuhOrmWVoFw49TwR/v5+iom2EAbGTcsaCTea7 mO0L0aHtLA6zkuXLzGw8QYZ9qtEKQXv2F9njT/teE60m+I1LxIsZEAAW6mIZXbKgNeG3wALjUu+ pK9e1e/Si9KblshUY2r5uuaz+jQ4Q231axhbr514iQlDy3ZsJ8STCjHqjYB5r47w5RFZuO+J/aX VXKrN+3eR5UwdxX7+qlTnv+XFj2cClQ/m854aVHpjY3evJBlBtTBf1F1VT+6t5GlYEZ0+eEo1q0 VHXFCLjqTTUg3MNtJhCpbcaS0kxYbX+/WVaiQqPB6ZNrMfs1w4gYuTrwbM3M=
X-Received: by 2002:a05:620a:408e:b0:8d7:6899:9b6f with SMTP id af79cd13be357-8dc45d29bc0mr1223929085a.26.1775866336386; Fri, 10 Apr 2026 17:12:16 -0700 (PDT)
X-Received: by 2002:a05:620a:408e:b0:8d7:6899:9b6f with SMTP id af79cd13be357-8dc45d29bc0mr1223925485a.26.1775866335924; Fri, 10 Apr 2026 17:12:15 -0700 (PDT)
Received: from [192.168.1.172] (c-24-23-245-90.hsd1.ca.comcast.net. [24.23.245.90]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8ddb915b46bsm340361585a.33.2026.04.10.17.12.15 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 10 Apr 2026 17:12:15 -0700 (PDT)
Message-ID: <245f27ce-486d-4211-b6b1-94c9e177f829@redhat.com>
Date: Fri, 10 Apr 2026 17:12:13 -0700
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Rob Sayre <sayrer@gmail.com>
References: <16CF0FDA-7263-461A-9F2B-D37DBEAF5DD9@sn3rd.com> <14ab877f-40de-4ece-92a6-4b06ccac3da7@redhat.com> <CAChr6SxMMCviLyVyS6eee7XHKHqD3Q2hjkF+uZv=yTwgQjr69Q@mail.gmail.com>
From: Robert Relyea <rrelyea@redhat.com>
In-Reply-To: <CAChr6SxMMCviLyVyS6eee7XHKHqD3Q2hjkF+uZv=yTwgQjr69Q@mail.gmail.com>
X-Mimecast-Spam-Score: 0
X-Mimecast-MFC-PROC-ID: elNjpkJQhleEU8TT0LCGqhHO9oHhlhZfwJGsijR0WpI_1775866337
X-Mimecast-Originator: redhat.com
Content-Type: multipart/alternative; boundary="------------Rsv4V12EWGUnsdh0Qzlr0jce"
Content-Language: en-US
Message-ID-Hash: TDITSEYXQ2IU5HDLDQ55W46LKYXKRSL3
X-Message-ID-Hash: TDITSEYXQ2IU5HDLDQ55W46LKYXKRSL3
X-MailFrom: rrelyea@redhat.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/ieGtkSYx-gv5Jjg_bIg-WgfVLWE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On 4/10/26 4:35 PM, Rob Sayre wrote:
> Not sure it's ready yet.
> So, I am surprised Red Hat shipped it.

Why are you surprised, we've been pretty open about  our plans. We've 
blogged about it a lot (this is only a sample):

  * https://www.redhat.com/en/blog/how-red-hat-integrating-post-quantum-cryptography-our-products
  * https://www.redhat.com/en/blog/post-quantum-cryptography-red-hat-enterprise-linux-10
  * https://www.redhat.com/en/blog/prepare-post-quantum-future-rhel-97
  * https://www.redhat.com/en/blog/whats-new-post-quantum-cryptography-rhel-101

> A matter of concern.
>
> thanks,
> Rob

Openssl have already shipped this. We've supported projects that were 
experimenting with this for a couple of years. We are on the front end 
of they PQ deployment requirements. The infrastructure needs to be in 
place long before other applications deploy these algorithms. If other 
applications that depend out our security libraries need to be PQ-ready, 
we need those libraries to be PQ-ready. We can mitigate algorithm breaks 
with our policy files, but we can't mitigate breaks in RSA or ECC if we 
don't have those other algorithms deployed.

It's true that we usually hold up implementations until the file ietf 
spec is released. In this case the risk was lower because openssl 
already deployed, the spec was simple enough, and out ability to turn if 
off was relatively simple.

bob

>
>
> On Fri, Apr 10, 2026 at 4:22 PM Robert Relyea 
> <rrelyea=40redhat.com@dmarc.ietf.org> wrote:
>
>     On 4/9/26 12:30 PM, Sean Turner wrote:
>     > This is the working group last call for Use of ML-DSA in TLS
>     1.3. Please review draft-ietf-tls-mldsa [1] and reply to this
>     thread indicating if you think it is ready for publication or not.
>     If you do not think it is ready please indicate why. This call
>     will end on April 23, 2026.
>
>     I have read this draft and support publication.
>
>     We have already built and deployed and implementation based on
>     this draft.
>
>
>     >
>     > REMINDER: If you have not done so recently, review the TLS WG's
>     Mail List Procedures; see [2].
>     >
>     > The Chairs,
>     > Deirdre, Joe, and Sean
>     >
>     > [1] https://datatracker.ietf.org/doc/draft-ietf-tls-mldsa/
>     > [2]
>     https://mailarchive.ietf.org/arch/msg/tls/ucdImHExlbOf4Q3BCG81gjzi2xE/
>     >
>     > _______________________________________________
>     > TLS mailing list -- tls@ietf.org
>     > To unsubscribe send an email to tls-leave@ietf.org
>     >
>
>     _______________________________________________
>     TLS mailing list -- tls@ietf.org
>     To unsubscribe send an email to tls-leave@ietf.org
>