[TLS] Re: FYI: Ubuntu 26.04.01 GnuTLS ML-DSA sigalg friction
Viktor Dukhovni <ietf-dane@dukhovni.org> Thu, 03 September 2026 02:46 UTC
Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 780D4134689BA for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 19:46:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788403601; bh=R98tI1975IqExNKCZQMASBEdFkM1KdbVhVNZL+PhuLY=; h=Date:From:To:Subject:Reply-To:References:In-Reply-To; b=LS704WuneE1Gr7FvEI9maJ9pqVtGL8QuBjz3nz/aKnPHbgu1zvlN8gLAPFijVzL1s nmRcqU1i8MKUxecsQxuMkDsJJm+hig2RiUY8LBH3ii+SKBn/tkhODLXnNvZhoBbslq GrAfvchGP6k35Wu7Qc1mdYwvjg7cERMsjOliJBZY=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.398
X-Spam-Level:
X-Spam-Status: No, score=-4.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=dukhovni.org
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V0wZvk7oShB3 for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 19:46:40 -0700 (PDT)
Received: from chardros.imrryr.org (chardros.imrryr.org [144.6.86.210]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id A1BAB134689B5 for <tls@ietf.org>; Wed, 2 Sep 2026 19:46:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=dukhovni.org; i=@dukhovni.org; q=dns/txt; s=f8320d6e; t=1788403597; h=date : from : to : subject : message-id : reply-to : references : mime-version : content-type : in-reply-to : content-transfer-encoding : from; bh=R98tI1975IqExNKCZQMASBEdFkM1KdbVhVNZL+PhuLY=; b=qmw+FP6wP0LyjoFgWJ5ORatwBsG8d1rFeTeWKk9braQbRbIlXwY8G5XAd6NNRDgGTV34Y 8whmXAXTdtZSK2DNGNriOEF/kr00t0TZCLDloLqKR51fq76WQb5XuDEHyzBAqwcsviRUPPr 5r/YP14vZ/Te8fxUwrKQbvpzvqA1dvI=
Received: by chardros.imrryr.org (Postfix, from userid 1000) id 22ABE93559C; Thu, 03 Sep 2026 12:46:37 +1000 (AEST)
Date: Thu, 03 Sep 2026 12:46:37 +1000
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
To: tls@ietf.org
Message-ID: <apjfjd22WOm5dUvx@chardros.imrryr.org>
References: <aphmn2ZdoGs3tiNv@chardros.imrryr.org> <MN2PR17MB403141BCB04F7863DFF70838CDB72@MN2PR17MB4031.namprd17.prod.outlook.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
In-Reply-To: <MN2PR17MB403141BCB04F7863DFF70838CDB72@MN2PR17MB4031.namprd17.prod.outlook.com>
Mail-Followup-To: <tls@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: TU5HIL2EPHVC5BHERAIBDIKACLLSA7LO
X-Message-ID-Hash: TU5HIL2EPHVC5BHERAIBDIKACLLSA7LO
X-MailFrom: ietf-dane@dukhovni.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Reply-To: tls@ietf.org
Subject: [TLS] Re: FYI: Ubuntu 26.04.01 GnuTLS ML-DSA sigalg friction
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/jMKpJCMZvZe9338FX-1CoYtTF6o>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Wed, Sep 02, 2026 at 06:17:29PM +0000, Salz, Rich wrote:
> > GnuTLS library advertises ML-DSA-{44,65,87} sigalgs even though the
> > implementation of the corresponding verification algorithms in
> > libnettle is stubbed out and always fails.
>
> Seems like a simple bug to fix. Did you report it to the GnuTLS
> folks? (That’s probably more useful than reporting implementation
> bugs here :)
I should perhaps have mentioned that essentially the same library stack
(GnuTLS + nettle) is correctly built in Fedora43. This looks more like
a question of consistent build configuration than intrinstic features.
Reasons to mention it here in addition to notifying the Ubuntu and
GnuTLS maintainers include the observation that similar failures can
happen any time the TLS stack and underlying cryptographic library are
maintained and delivered separately, and the TLS library assumes a
set of available signature algorithms without an explicit indication
of the availability of each in the underlying layers.
A similar mishap is not entirely unlikely in other implementations,
and I'd like to recommend designs in which there is greater confidence
that the offered signature algorithms are actually available.
A second reason is that this sort of friction can adversely affect
pilot PQ deployments, and mentioning it is not particularly less
relevant than say mentioning that 3GPP is phasing out TLS 1.2, ...
neither is directly about a document under WG consideration.
I don't expect to need to say more on this topic.
--
Viktor. 🇺🇦 Слава Україні!
- [TLS] FYI: Ubuntu 26.04.01 GnuTLS ML-DSA sigalg f… Viktor Dukhovni
- [TLS] Re: FYI: Ubuntu 26.04.01 GnuTLS ML-DSA siga… Salz, Rich
- [TLS] Re: FYI: Ubuntu 26.04.01 GnuTLS ML-DSA siga… Viktor Dukhovni
- [TLS] Re: FYI: Ubuntu 26.04.01 GnuTLS ML-DSA siga… Dmitry Belyavsky