[TLS] Re: [EXT] Re: ML-DSA in TLS
Watson Ladd <watsonbladd@gmail.com> Sat, 16 November 2024 06:12 UTC
Return-Path: <watsonbladd@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B7C00C15152C for <tls@ietfa.amsl.com>; Fri, 15 Nov 2024 22:12:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QQhTltL5Ly-a for <tls@ietfa.amsl.com>; Fri, 15 Nov 2024 22:12:54 -0800 (PST)
Received: from mail-wr1-x42b.google.com (mail-wr1-x42b.google.com [IPv6:2a00:1450:4864:20::42b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A27C0C151531 for <tls@ietf.org>; Fri, 15 Nov 2024 22:12:54 -0800 (PST)
Received: by mail-wr1-x42b.google.com with SMTP id ffacd0b85a97d-37ed7eb07a4so928496f8f.2 for <tls@ietf.org>; Fri, 15 Nov 2024 22:12:54 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1731737572; x=1732342372; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=8TEKuPERVbzgXQYNrTTRZ9dPcMeinlvYGUr5vb3iGOw=; b=UdDm1B4DtsgIHsCnYUEE5qiMcYL9jt6NosPXp1cN1FyskXk2X5FsEe7+95e1aFAnZV BUxbk18z59XgEXMBGij8cEKjpMdq3E69v4O2EJryy460sX3GVzWDhG7L44KDC/cKu7GJ O9SyMQC8x/EjJiZDOrw4wUpGCi3qUY0DKSSMxIOmS46N417KE0H0OlefQ931tMUfgPP+ Fd3nlIBRKuBoYoeLdXlxKUxx2NQp4477yeGBvxWdyIFNamiI7urhvD8Vgwv3NkhpsmeR hBWxrTjDFRKxq39ZzOfbjnhNK8sQOX6YI3WBN19A/CbN1YQVHq2+JvHsufry/5Yik0ff VPpw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1731737572; x=1732342372; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=8TEKuPERVbzgXQYNrTTRZ9dPcMeinlvYGUr5vb3iGOw=; b=Rbcxfl81Lg/NU7G8ZeAqtGLYZzNCWSLBoGBbL7DoeUam/y5ZdyJMUPxfPeZP9/M+m3 7JquUfIxfMe/n5Ezw8RFzzJuoO6TVgbgKKfcCgt3j5mOb6sJI4iO7UKbwjAGQo64QYj8 vf0H4ZBnbSXFuwWst88FWfrB7EvgsFpa1rfVJHqC0AP1s/ex7A9mJFxx5Ma/J7mkJKhN pVGPDXTYre0qi7CgHBr7ibJYM5nzvih2Jf2G9nApLxx0XqhithYfadfQo4B3igZUlwrH D8ruaYWHKvC6NK3AFopuG5h7u6A6ggb+9CIoMQeBQHFmPpb+8rbr1PmRQM4lVpWCweGz ogQA==
X-Forwarded-Encrypted: i=1; AJvYcCW3aVrdImb7zQMu+M8uD5eA/UnFhT4hYxZxlLVY+jaX70752C8HVS0F9mN2uSKr7TNWhbY=@ietf.org
X-Gm-Message-State: AOJu0Yw1vU16U73Rm+Z8+7coPlb/hOkD6CWe9nbx9aDOL5mzzzuafc2A Z8Jq5Y9UcKWlJtmZamnSWiNUfVcCRQRoeHxVNxsUxMnxLmTUqIaax+G/qyEWA2v/rYa0pJecz+r ptA2mXcX5tvXkC0y4bTxx3bP5jZQ=
X-Google-Smtp-Source: AGHT+IHWAvZh2Dxovf69OwFM3gkAD8ssEwLZXLRk0djf4u0cVeHww7MDS9pex1dZZzhm4CNtMg57Jru9qhfsBs0bO4A=
X-Received: by 2002:a05:6000:1849:b0:37c:d23f:e465 with SMTP id ffacd0b85a97d-38225aafa8bmr4271845f8f.55.1731737572395; Fri, 15 Nov 2024 22:12:52 -0800 (PST)
MIME-Version: 1.0
References: <CAMjbhoUFkL=UT0Pt2xjPLm998=j1ef+wdm0WO14_W7OJDJ-hOg@mail.gmail.com> <CAMjbhoWY+1Km_=+PbXfEjab02AfWpbd4WwKwuBN_5KZZpCkXZg@mail.gmail.com> <bd714bdc-5bf9-47a6-8e66-b2e4624c9df0@cs.tcd.ie> <GVXPR07MB9678722E47C82B14B0F296F389242@GVXPR07MB9678.eurprd07.prod.outlook.com> <CAAWw3Rh-2A1zuEWOLuoaQ5DMcDGb_oQXRc8ZNYNVoO8KDsqzTA@mail.gmail.com> <e855562b-2bce-4bd4-ab58-074550c34475@redhat.com> <CAAWw3Rj7L8v9OOJtGHMvCXRtcHYAMU3TLPJ_etf8EP8MSiSHGQ@mail.gmail.com> <BN0P110MB141974314450179F48B424D99024A@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM> <CAAWw3Rgy7qonCMqKmYiCQZi3RCq=t4J94NA817ONYGOTwP3FDw@mail.gmail.com> <CACsn0c=8J4S00mzOWpHgKSudnpp=zzRjGmVQ5tRNTOnN5ekWfw@mail.gmail.com> <CAAWw3RjCk1hhjapG5r6F0NEo83G=XzyNuscSrzJMeefuZm_cJA@mail.gmail.com> <CACsn0ckf57w-6xg+-d2WrvoY-RGM+BQbZFP-fo=OTC11kNdRYQ@mail.gmail.com> <CAAWw3Rg9YW5=Gd3E-XvthsU6-N=zx_N0Ss2uZsaVcB5c8HoQFA@mail.gmail.com>
In-Reply-To: <CAAWw3Rg9YW5=Gd3E-XvthsU6-N=zx_N0Ss2uZsaVcB5c8HoQFA@mail.gmail.com>
From: Watson Ladd <watsonbladd@gmail.com>
Date: Fri, 15 Nov 2024 22:12:44 -0800
Message-ID: <CACsn0c=ubuOzJbvRegg+J5=Rs9oQRwoZN35_CCqoVsynPQbTew@mail.gmail.com>
To: Andrey Jivsov <crypto@brainhub.org>
Content-Type: multipart/alternative; boundary="000000000000d8d4d606270192fc"
Message-ID-Hash: 3TDSV523B5WQHLOE4ZVRW2U6YQEHZFUB
X-Message-ID-Hash: 3TDSV523B5WQHLOE4ZVRW2U6YQEHZFUB
X-MailFrom: watsonbladd@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>, TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [EXT] Re: ML-DSA in TLS
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/m4jktvygiK425aQX2IZ8mkQzz0o>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Fri, Nov 15, 2024, 8:52 PM Andrey Jivsov <crypto@brainhub.org> wrote: > On Fri, Nov 15, 2024 at 3:56 PM Watson Ladd <watsonbladd@gmail.com> wrote: > >> ... >> Why not hash based signatures? >> > > I think that the stateful ones are perfectly suited for certifications in > X.509 certs, but in the TLS handshake this has to be Sphincs+, at 16.2KB > per signature at the AES-192 security level. In addition to size concerns, > it's not allowed in CNSA 2.0. Are vendors considering SPHINCS+ for this > purpose? > If CNSA 2.0 is the guide why consider hybrids? >
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Kris Kwiatkowski
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Eric Rescorla
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: ML-DSA in TLS Ilari Liusvaara
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Ilari Liusvaara
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: ML-DSA in TLS Eric Rescorla
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS Eric Rescorla
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: ML-DSA in TLS Russ Housley
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: [EXT] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: ML-DSA in TLS Santosh Chokhani
- [TLS] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: [EXT] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Eric Rescorla
- [TLS] Re: ML-DSA in TLS aebecke@uwe.nsa.gov
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Salz, Rich
- [TLS] Re: ML-DSA in TLS Salz, Rich
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS aebecke@uwe.nsa.gov
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS aebecke@uwe.nsa.gov
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXTERNAL] Re: ML-DSA in TLS Andrei Popov
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Ilari Liusvaara
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Rebecca Guthrie
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: ML-DSA in TLS Salz, Rich
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: [EXT] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: [EXT] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: [EXT] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: [EXT] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS Ilari Liusvaara
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: [EXT] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: [EXT] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: [EXT] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: [EXT] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: [EXT] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: [EXT] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein