[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Christopher Patton <cpatton@cloudflare.com> Thu, 25 June 2026 13:21 UTC

Return-Path: <cpatton@cloudflare.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 2C12810741176 for <tls@mail2.ietf.org>; Thu, 25 Jun 2026 06:21:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782393687; bh=b4IYbya6QUC8KpL57coQWbRiCdi1VsywFug+e+0e9yk=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=QHyyA9RA+y8mq4VcJz+VY0JRihMOSzoyuavSf8yGanuL2xlV0diCD8nC8O90J2Eq3 nkJ8W/2o2Ap1QhrNxmNX4zvyD4QZfKvDaoD1JHCfHDhBKPQxyYdXLjdZ1RBjn5XfC6 yJuTQPd5ELzSS6Isnpq48tcuNGi4t5wWveXPeuRM=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cloudflare.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1cUCnYEIYvNx for <tls@mail2.ietf.org>; Thu, 25 Jun 2026 06:21:26 -0700 (PDT)
Received: from mail-qt1-x830.google.com (mail-qt1-x830.google.com [IPv6:2607:f8b0:4864:20::830]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D5AF2107410AD for <tls@ietf.org>; Thu, 25 Jun 2026 06:20:21 -0700 (PDT)
Received: by mail-qt1-x830.google.com with SMTP id d75a77b69052e-517b1f2c6adso19126071cf.2 for <tls@ietf.org>; Thu, 25 Jun 2026 06:20:21 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1782393621; cv=none; d=google.com; s=arc-20260327; b=oFQu3cQ7NQbLbyWAcXZjDHkbgDY6Q6gnAkUylBPUSPViRqkyjtsg8tiuYAGTR8pMrm JCyQvzQ7Pi3q0wO3UR3rYcgASRGg7l9gMTzer7BU9SgIfYWVKUxjpu7IKJBhsw6xLLhm 6zoTVSXNdj6W20yorA2nP6yxd++GosVqc7zN9uhv5CL2YRMkCgt7q7DS+CbMQnzoILy+ PWT49n2JHl0iU+0FPXjd6u3BGYP7F8YA1iGsmM2x8PBaRQSB0+BLfx2ZN+euV3n+bkmb gjc5XZpiAc2sfc2kuSHqu3xUh5HNz/OtbOezFeVu3sbGgltUKDYSGEphhadfj3W1oJCi /Oyg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=L3GJu91bdAB4epLU6gGV252pAD/d+NdBkFG9ip8PHJk=; fh=9LbPrA1Va9L+iF7Ce8TROP9DIqYhRmp9zbV5VlxGOkM=; b=bsMkAe2JUEIkkfrjfp8PqB9hvlyhRW6/K38Mjxdo+imCCU6+SvYwHrM5T4kwRgGmqd Bazp3/jHHG9cVkfE0VFgUvqDU089/UQAQ/ZNsJI4De9S8xvijTdtfvhrkFw8i6k5qbzq nzrPtZ09UN7hI8pfNROBOtkpYn7nrxne5GC+N0VQIgJyW+ba1gauu6X02K5GUC3OOTuc qia7ci1ukDGMhkbgTKdgqaJKLkCUbb4mP0++LQZ7hdwnGNAv687YLzi8aG6S+Wci6z5y 74cqoNH+zjHZfRA3JjfQTJBAbu4+lIEZ16G/pNKXq+AkeIt08RTfi/RGZHPHtWIaLAb3 R4IQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1782393621; x=1782998421; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=L3GJu91bdAB4epLU6gGV252pAD/d+NdBkFG9ip8PHJk=; b=O8qeBMNroTSxciUVicH2D0iwOk9aw6XJ26gSmIrN593wJoyGTEJs23mhuAMjt4rY3u 6uEL4M6JSLTfD3c1oz6+9OwgFAN5qjWJ/GdHojbbJWGyBEKGTgNAbfl9vIwTCCI7xcA8 VtR/SdFMIR4mf2qQyarkZmZs3xIX0SNcayWheOz2QirNQhnqREisHQWNMy8xfF8iUmry BwXF5oYCxxw1zs4QUkLbsEurgRmazYZk4ZPFdovdR+8enM9D7adiTFQUs9MlE/nbAzGb N7RoRM4IgQU/rnNQDds63zwmiMPIVxBn7GK7vJnFqWRPIt97ZcheMJExyxcakyRvRRgn 9+jw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782393621; x=1782998421; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=L3GJu91bdAB4epLU6gGV252pAD/d+NdBkFG9ip8PHJk=; b=EFvgNjGsTL3LIm0aaMuN0m6gUhpPgHvJJmBen8H9t1Saq1qCpDf/xwvxtEUN9DfbT7 asrCy+sLqY9esK/H38xtyysPOiFZFMv47k5cire1g4NFAgLLh1tL0Vo3Wm7G+lr0Kfa/ hMlk8OM9e38DUrjR1/PtTK57WuDH0igGAS9BA3Sb+vG/nbkf4v8c202JrTQ+4ijV7/Ge MhazUqq29HvZ2nvyEiwI2N6qicUyq9SG5Gag67r62H3NFBRw6XhCyzhYFGANSek0e9g4 TTbxpcRXg2RC7ek9Wex9kfcSc0c+DJvxXp5NbzwU965qqYwqZGB95SzKuQNNvWzY8abJ ptvw==
X-Forwarded-Encrypted: i=1; AFNElJ+2qqYP2uQ5z9RbYBwtqRu6SV2r2R1wcpSDhz11wA903k4/VEYhmriuqlhTuLm3EyAdpK0=@ietf.org
X-Gm-Message-State: AOJu0Yy9eZD/TXEhLooDwJBC8qzTsddADJv+WQAaMyPuIepvy1HX4w1E xRF3hB/RdG5TzFyAIf4j0Pf1AT+YXhTjdZwnI0XiZ5rlOxtWpFnXYQ909iiTpHOEKb8UIejRpqR LYJn53j6ldGVZNR9uPRBjb4vNuRqbCLFBN/uVZWRBVg==
X-Gm-Gg: AfdE7cnzXJuF+48xzVgDmqi/4W/89HOsLqbWo4UQvcmT59PpDSAC3JDEkxj2yaYdSK6 yeDnICt86Zd8IIxuWbxcJ+c75tO3Lf5laxaOYtpSg6AU6jnwHEjvC/yK/6p4s7Y5tBWYXuIoI2s STz1bHq9yasQOVEnD35rUCgBfvQD45Kd/14eUkRR1R9xZKnfik4ZGnBn7qVmKYhPQh7f+2hCSgp JQTlst3znU+VjNg7VUf7ODwf8SrMA0UrrwjW//y5P3sR/SnfL145QCG8/pC/QHpFwL0HaDted76 elpEvp3QDdoec/aYA3gsxNhX4Hh/ZjOnxr2xiddMPbqeRirRGWTXMMMel/zMvhlz4kwxQaFe03L 4
X-Received: by 2002:a05:622a:1802:b0:517:917d:e3d7 with SMTP id d75a77b69052e-51a727a6aedmr29646811cf.28.1782393619831; Thu, 25 Jun 2026 06:20:19 -0700 (PDT)
MIME-Version: 1.0
References: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg>
In-Reply-To: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg>
From: Christopher Patton <cpatton@cloudflare.com>
Date: Thu, 25 Jun 2026 09:20:08 -0400
X-Gm-Features: AVVi8Cd8jTjZqRdYJpC2tcNNrMhWXrKc60B747_X5G6g1m-MiaapSLUzYAQfh6c
Message-ID: <CAG2Zi21jFAC5Yqyi-vSY_JXHnm6pzQD3JbF6+sifSLoRpMvRBA@mail.gmail.com>
To: Joseph Salowey <joe@salowey.net>
Content-Type: multipart/alternative; boundary="00000000000090aac2065513daac"
Message-ID-Hash: 234CSGYUPLXSGKSTYYZKLLGNZ5H6EZAT
X-Message-ID-Hash: 234CSGYUPLXSGKSTYYZKLLGNZ5H6EZAT
X-MailFrom: cpatton@cloudflare.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-tls-mlkem@ietf.org, tls-chairs@ietf.org, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/lxCmk5SfxnRx33XT_GMbtSriGwM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Thanks for the summary and thanks to the chairs for their leadership. I
support publication.

Best,
Chris P.

On Wed, Jun 24, 2026 at 11:01 AM Joseph Salowey via Datatracker <
noreply@ietf.org> wrote:

> This message initiates a new Working Group Last Call for
> draft-ietf-tls-mlkem[1], which defines standalone ML-KEM key establishment
> for TLS 1.3. The main question before the working group is: "Should the
> working group publish a document specifying stand alone ML-KEM?". If there
> is rough consensus then we will push to refine and publish the document;
> otherwise, we will stop discussing the draft and not progress it. Please
> respond to this call indicating whether you support publishing a document
> specifying a stand alone ML-KEM. Please refrain from further discussion on
> this topic as most arguments have been discussed multiple times.
>
> Why are we holding this consensus call now?
>
> Significant developments have occurred both within this document and in
> the broader TLS ecosystem to address the concerns raised in the last WGLC.
> Therefore, the third consensus call is warranted. We ask the working group
> to consider document publication in light of these recent changes:
>
> - Promotion of Hybrids in draft-ietf-tls-ecdhe-mlkem: Following a separate
> consensus call, the WG agreed to promote the X25519MLKEM768 hybrid group to
> Recommended: Y in the IANA registry. Consequently, the IANA registry will
> reflect a clear community preference for a hybrid because Recommended: Y
> clearly indicates this while the standalone ML-KEM groups defined in this
> draft remain Recommended: N. The updated security considerations in [1]
> reference the IANA registry to emphasize this preference.
>
> - Key Share Reuse Prohibited in draft-ietf-tls-rfc8446bis: The WG recently
> reached consensus to explicitly prohibit key share reuse across connections
> in TLS 1.3. The new text changes the guidance from SHOULD NOT to a strict
> MUST NOT. This resolves the concerns regarding static key reuse and its
> associated privacy and forward-secrecy risks for ML-KEM.
>
> - Nadim updated the ProVerif model of TLS 1.3 to evaluate KEM and hybrid
> KEM groups in TLS 1.3. This supports other results which show that KEMs are
> secure when used in TLS 1.3 and that hybrid groups are secure even if one
> of the components is compromised.
>
> - Liaisons: We received liaison statements from multiple SDOs including
> O-RAN[2], IEEE 802.11[4] and from 3GPP[3]  expressing support for the
> publication of draft-ietf-tls-mlkem as an RFC as they rely on the IETF to
> provide a stable normative reference.
>
> Please note that a third-party IPR disclosure exists [5] against this
> document regarding patents related to the underlying ML-KEM algorithm. This
> IPR declaration has not changed since the last WGLC. As a reminder, per BCP
> 79, the IETF takes no stance on the validity of patent claims, and the
> working group may decide to proceed with a technology despite IPR
> disclosures if it decides that such use is warranted.
>
> Conduct Reminder: Given the heated nature of previous discussions on this
> topic, participants are strongly reminded to adhere to the IETF Code of
> Conduct (BCP 54) and the TLS WG's Mail List Procedures. Keep feedback
> professional, technical, and focused on the document's text.
>
> This working group last call will end on 2026-07-08.
>
> Joe and Sean
>
> [1] https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/
> [2] https://datatracker.ietf.org/liaison/2198/
> [3] https://datatracker.ietf.org/liaison/2151/
> [4] https://datatracker.ietf.org/liaison/2148/
> [5]
> https://datatracker.ietf.org/ipr/search/?submit=draft&id=draft-ietf-tls-mlkem
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>