[TLS] Re: draft-connolly-tls-mlkem-key-agreement

Andrei Popov <Andrei.Popov@microsoft.com> Sat, 07 December 2024 18:51 UTC

Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9E850C15107A for <tls@ietfa.amsl.com>; Sat, 7 Dec 2024 10:51:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.25
X-Spam-Level:
X-Spam-Status: No, score=-2.25 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.148, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ig0UyM-zC_Ok for <tls@ietfa.amsl.com>; Sat, 7 Dec 2024 10:51:11 -0800 (PST)
Received: from DM5PR21CU001.outbound.protection.outlook.com (mail-centralusazon11021115.outbound.protection.outlook.com [52.101.62.115]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 98831C14F738 for <tls@ietf.org>; Sat, 7 Dec 2024 10:51:11 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ooAwywYE+NxLfE29YY8fF3LM55q50d4GxltULv/vG1eFQ3qoCh3hQu6d/TqgSSIZK+leHoVq3A+pD8RYv9Y08cuUhkM9/zuf8ysq+FWT/1+B6SKzMTaFLUufkC5WIqrf888724V56f3wBmOhkx8Z0ZXQQ8AVLHfWOqxRPZYlpG+PCucqZClC6S7B0apEoyhT2FeA5CLtLTnpm907JirhyTQ2uMw5oQK1PNdYa+Z2MIY039V9+z3UlFNx4DFKdXT8ns/tgqODK8HZ1Jdq+dX9kBGtMRF3HA8GkXoYM4m5EfGRNnvHoW1VkW1NgfGraKR5p2e6tI/m7IJzFVm8zy1oDg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=+tVkkwPO2tAGiaP+baLuxUSVDudp25K0kuFxOJqkQAc=; b=gFGsRgpWvU7g7DYwNm06f1+U2/izbypUUcYy3yzUlujnRdiaJ2iWYGbDOLzb2XqFtBoygu08rT5+KgZrUPRlwyS9TmffxFggUwNP55lxEpmS0WtDlgWXwIDdwUwdm/V+gNnvZjZVNgB8rJENjhHlIRDCzUU56aRUa/aD2+LUreHnf7B1V12xmlo6uF86v/y0FzUrO4bDPGKn2fD/RFrzW6jgg3WPDvmjhi/Imd7jQcGTDa9RhFb8xrUgopye3+FzJVba5HWwIlswLCQ7VXjwb9nrvYI3XjInLSs6TqUyTzGPBhIvOyP2Mwt2ER3iLneZ3kZX9Tldyh0AvwB40AiHPw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+tVkkwPO2tAGiaP+baLuxUSVDudp25K0kuFxOJqkQAc=; b=PdmNFum2KbkI5EbI4dgeNhbLd8yJMsKCmzDWl4dX45u1zYSJoNCNwRBw44WtesV3y2BscUdPc5MSDpwxHQKnX2aWMKBz63VQmzaDU4vk586bxwlY6jshoa4q0WC1SexzIvF34TfLwHJOYvmGIbbbwSCwXpzRNdLWDtLnApJqFMs=
Received: from DS1PR21MB4167.namprd21.prod.outlook.com (2603:10b6:8:1de::21) by DS7PR21MB3669.namprd21.prod.outlook.com (2603:10b6:8:92::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8251.12; Sat, 7 Dec 2024 18:51:09 +0000
Received: from DS1PR21MB4167.namprd21.prod.outlook.com ([fe80::6d81:206d:9ced:ecee]) by DS1PR21MB4167.namprd21.prod.outlook.com ([fe80::6d81:206d:9ced:ecee%5]) with mapi id 15.20.8251.011; Sat, 7 Dec 2024 18:51:09 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, Andrey Jivsov <crypto@brainhub.org>, "TLS@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] Re: draft-connolly-tls-mlkem-key-agreement
Thread-Index: AQHbSHgZsF1xBpmmn0SJ2Wd9WXh7G7LbH5Tg
Date: Sat, 07 Dec 2024 18:51:08 +0000
Message-ID: <DS1PR21MB41678FAF5FE55F467C5BEA288C322@DS1PR21MB4167.namprd21.prod.outlook.com>
References: <CH0PR11MB5444342A5C29C5C5BCCF9BA3C1302@CH0PR11MB5444.namprd11.prod.outlook.com> <20241206172906.124753.qmail@cr.yp.to> <CAAWw3RinB6WKCzLaFjds63Mgoykt-2haaD9rQEsFv2k_b8RJzw@mail.gmail.com> <GVXPR07MB9678B6F0BC3C1C815B9A7C2189322@GVXPR07MB9678.eurprd07.prod.outlook.com>
In-Reply-To: <GVXPR07MB9678B6F0BC3C1C815B9A7C2189322@GVXPR07MB9678.eurprd07.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=63c7f881-f9e5-4083-bbc4-7e9f100dcc34;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2024-12-07T18:46:00Z;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DS1PR21MB4167:EE_|DS7PR21MB3669:EE_
x-ms-office365-filtering-correlation-id: a4ced87c-49d7-42af-5519-08dd16f01cfe
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|376014|4022899009|366016|7053199007|8096899003|38070700018|13003099004;
x-microsoft-antispam-message-info: 6xfJPGqPrVnP2OsAOJhqlvZvtQVVChFDgK700prHn/BRf0AOlK7YdNNLLAFTFJB5S2xiaeNTxFmrQrFqirsyu1iMuLF0G+7oYvF2Redh+Rl5hlF9aqT9Vi2X5xlE2BvFC6Q+wQ7d+42Z8t0ipVo0+NZFXokSCQ4Y20GZUrYPywnONHliUh5WqAfITZLXUdONoXH8qipox1ydQMlBJmI2DA4oGpQ62s/ES7iT31WCtBWKLFYMmXfq8Y9Nj3onWiO5X+rt9aZIs4iUL8uDkha45OfT193JfpezIzDgGFPcoh5r/tVVcqobm0lTtvMBekXzEOrgGcC/X6rNzBcU0RkGNvNUtr5EoYCbez/3mWAwxXJrkThtK3iC2ccxfGNk+aDUeOJr1KYFe9LS8OZEE9wxeCuR9e8+c1lpKjrjqktZJghFndctYUC4FrTrE5Za5T+ui+a2J27AfhPc9rS6KOfNe394rMIBHp00nZQpeGM8L8oPPH4WAVlidquDx8ayUSqzozhAnHNOJh8T2xFR6E4L0rbj0DDLRLprXorrgmnGkWoAINU9QpA8PMFpcpPWJPj4uoGS9UxDK8Fc/WSIb1fNpFA2bVUn0TJZlHl2kYvo61xCK3jQHDhpLJFCVEk6xXvNin+2BJOwBemjmyssp1/7aIDafx3Xfq0C881X6K/S9H160DSwsnEoAT0/LdpkhiCbZCRNIuFuwoEK0uZp3wHB8oOBAj7N4YZsJFeqt9cXKaRUmwUmqwxu9uOF9RLMWG0Elo7Kkkt5o/9H1QYPbk7Lo4VG/4/h7X/e+66mR+gsR10lX+GTBeHAw4xtwvnh9lg1njffbYswQDdCnBNumCvJUDYS3Qp+zRo1Vb6POX4N95u9XiUBixj2suqAb5K9U/wOfOauNPnP975y+cckJwj+spYM1jbXhXgQcay9kOEgyQUu6bs7Rc5otVaA4glvBJaAtcI/26b0cVrqDejE7rXNoxygmDmdFPZWujfwqqlFCn/AzpMr3Hg06z386rYue0zyreknvDs25J1Hvwy6qfsRcCthvPSuImmo1I5CgVZl/yn7ASvndIE57ob4nhbVOgYQ4+EohpNoRPu6/kLmX/IAd4kTd9KiQBL/5fRFvWcwuISVjyTVp8QaM567hb8XcefikHw/JPfsy/fb7dAT+kWaW7PKChKvCSARrtohfn1dOy7zF62LcoCSAoyjvfAo4KnqAysiI+SPdu17y/Qhagi10OChyeS1kSyHWU5q9oDgdjBJB2SrOCe8w1QQGUy+q0jcDhhQdwSAblH5LxjqtuNVG50xKOW7r0WSc/vgzPIN7tM8cibZ80SwORo4fTRtMCWAe3nBEp2QW15ItNaEIgTXbs7PUvBFnVFPVBbSTRCMLb8=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DS1PR21MB4167.namprd21.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(4022899009)(366016)(7053199007)(8096899003)(38070700018)(13003099004);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: lG2XxKmKtObse9+p8Ne6VvuQlwj/PyOJ5F4tY6I6RiF36I24yA1pLpwZeYaBcRiwwwjkL8nvXPUc2jo24xtx3890y+MxUzTe5ehdua9aZ/bdzW69adNXX/G1ASbEfpPM+w44cXy2tVdbl4K0tpJ4y3x049amE2WIlFATgMfq0bFKwVjvJ36Y/JwGbABVvDIdV1cRsSsmExuD2BRXr4jfZ7yfdh+eT9Z7j7kIgv+UWOTzmiL0Hu0abucrjfMR0+fInF6dRDDn5ul1/AQ6temIDmpulaRLtzUAfxE75+/QWE0RG2/W9lUig9XfCycX7hDmqalZl8Q3orCTa6A6ssIKA5HAyoBpKj9Mb0FeQKNmZHzdmd0PSq3u8jvVCVWzBr1zsTy9yj32u5jdFC+0pV1kecpayNcagoLEPKL4THaoWE1/grHFO2ZlMYbl/NHCrsIuvR0HKKx4XLWVoWMG5czwaOZ4WKft22Q740hDwphBGDl7YPU9oXCKaMcl//ju4ZBSZo0OGItpmeFv9WUWoRBfgVsyPAQKTzws/BYuVqhMPmp9LyUv5DcCQsahDWx+yLM/1VlmCmvbzFOPL6ThYRmir3FW5IoPQhFyX8PWdRDbJUnEJn5fsjmuQWUYG25NpOJRE3W5R0rSqXl26mAlrdRWhYXyI6gFQFO50BDaF1AoAOJrF7jlWFraV25NgwXqH896aLJh9zQbYVicF6K24XYhlqwyKMY8d8LumwjeAoH5HpZiTHF8bRTWui8ygE6WWFp1rB8VSJwofFR8OHUj3uXKMv31KSHysfADs4AbZ9tFdHusXaANEiaZ9TX9y02Izvf0LlOzU6msnD1XnvfPHknCi0PqyVtbqzqVJw30qNSjpJY6Rfuo1Exm/hieTTM0Gh3kgHNzoJnycIq5FedpCOCdYhA2+79xCWDosE0+Q6LI3LKTjYtjkVCBEwUYZYSDXznHYILUZZpej7O8+IBHXE3Ph+el7sRja/cFuFVSVyNXVAIWbasC+4NrEq7RPgrlfkNj7TT/8CwXTUWwLe4HULWrIr6vlhyq9Ej0n5cNH4hmLCGvB7XOn8okZksFN/ejj4hDgIDcpf1rQzOfl1IlD+DjQOgseQRZe3n+Igf1uRe3QsxMhu5XEq6Q9ith7wgTZQ1n+ToM92ElINDnBIGlLflLtyGSjg8AAkwXLd2C1S60D0vS0NHLMed53Q1kJiPfJz7drn0limQN8u7IOmY+3Qzo3U5er8eWTIXEvYVG8DbahIbWrwvEQPzQpol564wtOWdFw2x1V5l46I5JoNJ9nF+JXdnpRZBi+kyWNvBKfRm5G1vBFf+nYWqlfY3pJhsVG2HWrRutUR68W7f83xV5szMmRIBUb82+ZkWkklqp2m9ELoXre6Cop5hl8HbnrTNIoGXuXmnUwlwW8cPnNHECOCsOWqvyz9gMhUM9M13eprThUWYo195/CcUvr3iWnEPmrnVVbsIMw6Hk1L+rIVtxKUk0C8FZNrqiwtD8GRoQsIBDafiB/MlVTErSBIXOLELIxbYtNw4+gupIkXoMUe0gOab3NGu+Kcf8Snb8quNTPjaGSbXDwiyuQpZVFqRm1Py9Z0rE
Content-Type: multipart/alternative; boundary="_000_DS1PR21MB41678FAF5FE55F467C5BEA288C322DS1PR21MB4167namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DS1PR21MB4167.namprd21.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: a4ced87c-49d7-42af-5519-08dd16f01cfe
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Dec 2024 18:51:09.0301 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: EUkYl8ArcGkd3iAHGPwEbdcBrrbpx+ny0t1LaNOGw22dspoXp81veVsjPEwiTaUoo0gbtIBiIewaC4foAZOh9A==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS7PR21MB3669
Message-ID-Hash: 4M57CZCG25ZBLW74U4JR7X77UZZMPF5R
X-Message-ID-Hash: 4M57CZCG25ZBLW74U4JR7X77UZZMPF5R
X-MailFrom: Andrei.Popov@microsoft.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: draft-connolly-tls-mlkem-key-agreement
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/kMKseUZgsUVGnYZbU8yz2Et9CmM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

  *   We don’t see any need for SecP256r1MLKEM768 at all, I think that should stay RECOMMENDED=N.
What would be the reason for dis-recommending SecP256r1MLKEM768?

A large number of Microsoft’s online properties are subject to regulatory regimes that prevent the use of X25519; these will need P256+MLKEM and P384+MLKEM.

Cheers,

Andrei

From: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>
Sent: Friday, December 6, 2024 11:17 PM
To: Andrey Jivsov <crypto@brainhub.org>; TLS@ietf.org
Subject: [EXTERNAL] [TLS] Re: draft-connolly-tls-mlkem-key-agreement

For Ericsson, we are planning to use X25519MLKEM768 as soon as possible and make that the default choice. We would like X25519MLKEM768 published as an RFC, be RECOMMENDED=Y, and MTI asap. This is already the de facto standard. All standalone ECC (secp256r1, secp384r1, x25519, x448) should soon be made RECOMMENDED=N and secp256r1 and x25519 should soon be removed from MTI.
We want standalone MLKEM1024 for customers wanting compliance with CNSA 2.0. We are fine with RECOMMENDED=N, but we would like it published as an RFC.

We don’t see any need for SecP256r1MLKEM768 at all, I think that should stay RECOMMENDED=N.

In the future we would like to see one or more backup algorithms (BIKE, Classic McEliece, FrodoKEM, HQC, etc…) to MLKEM standardized and some of them hybridized with X25519 be made RECOMMENDED=Y.

Cheers,
Another

From: Andrey Jivsov <crypto@brainhub.org<mailto:crypto@brainhub.org>>
Date: Friday, 6 December 2024 at 21:45
To: TLS@ietf.org<mailto:TLS@ietf.org> <tls@ietf.org<mailto:tls@ietf.org>>
Subject: [TLS] Re: draft-connolly-tls-mlkem-key-agreement
I second D.J. Bernstein's concerns, but my other issue with giving options like this is that they will creep up into MTI sets or default sets, with higher priority than hybrids.

I find it less ideal that the document on pure ML-KEM (or signature) and hybrids are disassociated, causing the progress of standardization of the pure version to bring these other concerns.

So, as long as everyone is on the same page that pure is just one option, perhaps for strict compliance with CNSA 2.0, then there is no issue from my perspective, but that's a (mildly) controversial part.

On Fri, Dec 6, 2024 at 9:29 AM D. J. Bernstein <djb@cr.yp.to<mailto:djb@cr.yp.to>> wrote:
Scott Fluhrer (sfluhrer) writes:
> I understand that people want to discuss the hybrid KEM draft more
> (because there are more options there) - can we at least get the less
> controversial part done?

See https://blog.cr.yp.to/20240102-hybrid.html. Using just PQ, rather
than ECC+PQ, would incur security risks without improving deployment.
Regarding "less controversial", you might have missed previous TLS WG
messages such as

    https://mailarchive.ietf.org/arch/msg/tls/j1qkfNmk33OZ7hgCR53TiLmYOiA/
    https://mailarchive.ietf.org/arch/msg/tls/I1GPuKLCBJ3jA-ovNcuIsLlNGkM/
    https://mailarchive.ietf.org/arch/msg/tls/gB55YMMdfFLqaCE9ughNXX8qjtA/

where various people (including me, obviously) already objected. Also,
you might have missed BSI writing in

    https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TG02102/BSI-TR-02102-1.pdf?__blob=publicationFile

that its post-quantum KEM recommendations are only "in combination with
a classical key derivation mechanism"; commentator Matt Green writing in

    https://x.com/matthew_d_green/status/1742521204026622011

that NSA's "stance against hybrid encryption makes absolutely zero
sense"; and NSA itself in

    https://web.archive.org/web/20220524232250/https://www.nsa.gov/Portals/75/documents/resources/everyone/csfc/threat-prevention.pdf

asking for two cryptographic layers "to mitigate the ability of an
adversary to exploit a single cryptographic implementation".

---D. J. Bernstein

_______________________________________________
TLS mailing list -- tls@ietf.org<mailto:tls@ietf.org>
To unsubscribe send an email to tls-leave@ietf.org<mailto:tls-leave@ietf.org>