[TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3

Richard Barnes <rlb@ipv.sx> Wed, 06 May 2026 19:45 UTC

Return-Path: <rlb@ipv.sx>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 182E5EA20ECA for <tls@mail2.ietf.org>; Wed, 6 May 2026 12:45:10 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1778096710; bh=efTEdaAvK3UQxAZXeF6vV+6hCDVG64a9XwjT5VF8aww=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=YjATdrgSN52+8IXYGvs/HPIgwDrGaheTHzkLaD69y0EFA18hSNlm4tNKuZGTNQ40h QszRbb49A5Dk3Dbzm2D9oHybVAFpz4tF4rDZRHuZPunnjg0zGAQ93R2bVz9MGS3RN5 LgR+VKbGVxxNfptEl/brSJTr4DRwTQfAwXAdVFHI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.797
X-Spam-Level:
X-Spam-Status: No, score=-1.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20251104.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EH_65-ZLU-ge for <tls@mail2.ietf.org>; Wed, 6 May 2026 12:45:07 -0700 (PDT)
Received: from mail-oa1-x2e.google.com (mail-oa1-x2e.google.com [IPv6:2001:4860:4864:20::2e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id E46AAEA20E02 for <tls@ietf.org>; Wed, 6 May 2026 12:45:06 -0700 (PDT)
Received: by mail-oa1-x2e.google.com with SMTP id 586e51a60fabf-4043b27ddeaso3608594fac.1 for <tls@ietf.org>; Wed, 06 May 2026 12:45:06 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1778096706; cv=none; d=google.com; s=arc-20240605; b=h/dn1rYJyciUnc/yrCvUuxNOz+umdz3jZzfTHWGivuxZhCuG/1cGcDRviML5MOPYIU RAz34L8CyufSgCYvISkqWIqYo5fcDdj1T5MA0tkhygvrleQ1e3k8y+x+tIevgk1jsmYV 7W6eARcpGtmun0Q2A5+RYWwqRzylfZ7Z+ThVz8OaEsoZlle+WJMMDWEj/2BAev9vRogE mOWKXplHSiOCMK6YtvjThSMFDmr0b3OVv4iWJYxsv8qOYt03AzIzRlXj/cbg4INF8IyC lLzb5JOqKKb0D7Kh+e6yueA9/dVdO9hmtpoFCp4nDB17hiIyLZ4Un8PwNRefSlA3aqGW fGAw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=lzc/QcbtaGuhDw8O2uvrCgy8K1tBZSjW/JiCUq9VMuE=; fh=deECjFncdhJHWktrVvdR2G6YKa4BG1hifWzNxMupsSo=; b=Ni55lIigQbLfGKjePxTHY820FW8KPT89qTuZKQyKWDMswddJewxBOknaVZWhDmoFfM vWBrGJpT0666whMlsMzGKAlZ4Zx5LGW0IXmBc1XCbFCXGQqMS1wt+HTfdYcAt24062NJ 7GvBRLnuJGwMrV0B5jT4k37uOhyOPC6Pmj7YZsm1nkxpSSrqjdNwiBmQ+Xmy+2jlRsjW obDi6NlbkV/O3aGhgd3vlEkenJ2mg3tOAJh7w1ltpyImF9k6LE7ppOeAh4s7VEMLPnVB BoIVXdKnyf1SzV0tq86u/FaNmDm9PRAq+Vub0SEUWuIudokLbmnXGidOFuKHqz0TJIhm bvBQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20251104.gappssmtp.com; s=20251104; t=1778096706; x=1778701506; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=lzc/QcbtaGuhDw8O2uvrCgy8K1tBZSjW/JiCUq9VMuE=; b=OKdz0PrY39QZWOysOHKHWKC6eg/BdtTqpDTvnb59fNC5G39jWLNrTm6bQrxr75yGa5 bLysRLvpiAVLzTgPl7I8x2Et2HjHh916ej+1vxfSpeWNd2Yas5gpIpyrF5AAVo1oBDqw w3E+h8Z1mM2c113G3ZMGt4V386qdTUHQ7uJu5feL3ArlFp6OyWhuToHQk8Hy2xBHPfYZ P08ul8BxxgpD8S5fmF8rgqPpiLFiWTVv8WqZSIbm58tn9FbqNnulNTz/0RcGk8aIF6LK lptRJrckYFIu8k0VWJDIJ+IgnymXYkOh/nHM4jBDMgsnNWhPReXVmK4IdGlGQRFL0c1+ K5sQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1778096706; x=1778701506; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=lzc/QcbtaGuhDw8O2uvrCgy8K1tBZSjW/JiCUq9VMuE=; b=rGtA0CeaTvtTx0nRyxyuc0fneBoaNeuA1YnYKHIY2fbq1Yi8Ncc0t87iUqLEA36+4A tpD0n5qxqJtW4GvI408Riuc6CPBn2nKALThZybdyY0+2h/6MkkJQnD7hWqRpp8BG38Yx M02hOezV+Bqj2kpRDr+nHq0pZ4IVoKadiXtgPGn5g4/3wYjPqVFNHe4n8Po1Jk8cPxKC Bel6YLUyw0a7auaKtWL2P/aRj5Y6OtAIwBolZvo934nlzpxsVDF3nu1ayuZUQxq8Vdcl 5u1pjQHnvHeoQrlSCxwZv2CIgk8GsmT7WqoXaQgMhLFU5eQjnHYNU9syNdyKg94UAz2O UNbA==
X-Forwarded-Encrypted: i=1; AFNElJ+sBTpTYh8aihSMvhcsvLTtY6Emgw0RCiDoTVkCBI3oOw7cTs7KamosaMIi9aTOBE1nCHo=@ietf.org
X-Gm-Message-State: AOJu0YyJog5GIi+803+1eLoEWDyv3uNPShj6T5Ut1XRVYijwhp6gL2zz GRBi+8EHEz33nIX4rIi27gXUMrvbwlePe0tBnex3T9F690hlkH8+Haz+53RDny+v9FBYtVIi4XG 8p6gi89cyemlgr1i9HnLnGWJhvXXT0i77F1KqEZrUMw==
X-Gm-Gg: AeBDiesyChV7vQbqFYJ9G7RBRgoBL7YIn9cDTtbNxsDntl6za3XpicHy9t+ikptrGH3 uPKqQNvVnDIJzwwo2RplzLmY7RIYRwu0rdeQut1H0I91JesmFze4vFW/mZY1epDpzJh7W6kDMiF xoLOtrs+7mPZehtX1P0wuR4deDn6GNa0VitFp8ZZ8SYgYNv8Em+jZMb3ZAKw/QPhB8zE/MkfRKd ah3VKHcBTtDaY8A9gKyX+m0FB2GjFiwUvPoMF4eKpiGw+TWQQT8u0i6NQK5aa2oU/QIrBL3A8ev dme0U4BKaCn4dZzWx/KuWiGSsFnOZznoICMd/4Pi/ldImiCugA8=
X-Received: by 2002:a05:6871:c968:b0:409:bd2b:91a3 with SMTP id 586e51a60fabf-434f66cfe66mr3209460fac.32.1778096705537; Wed, 06 May 2026 12:45:05 -0700 (PDT)
MIME-Version: 1.0
References: <16CF0FDA-7263-461A-9F2B-D37DBEAF5DD9@sn3rd.com> <038E2DBD-EE06-4091-8401-9818FB692459@sn3rd.com> <3E4481D4-A20E-4B3B-B5BE-B71BBDA42176@sn3rd.com> <CAF8qwaBU3-VvY2TregAg7VezK6b4dmOUTsEFNmq=zj1eMoPgHQ@mail.gmail.com> <CABcZeBNzQ3-qQgQCpEigo9cVRZNQScO3cB+QEvjuNJ-xP_fQGw@mail.gmail.com> <BYAPR14MB288524DF36A25332DC1FA6E6D73F2@BYAPR14MB2885.namprd14.prod.outlook.com>
In-Reply-To: <BYAPR14MB288524DF36A25332DC1FA6E6D73F2@BYAPR14MB2885.namprd14.prod.outlook.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Wed, 06 May 2026 15:44:52 -0400
X-Gm-Features: AVHnY4JeJlPRq-PUeQ0I3bg_OQ0qg_Bak2CARdJL8tUl_TC6uhGfCYyIg3yaeJ0
Message-ID: <CAL02cgS8pfnQW+P1Cm9b2mijX5mLa6Gmez2EOBupX5_gX_NcOQ@mail.gmail.com>
To: "Ackermann, Michael" <MAckermann=40bcbsm.com@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="00000000000082973006512b6666"
Message-ID-Hash: UYANJHU5T3K722KO6IIGGF4NVKEHW5EA
X-Message-ID-Hash: UYANJHU5T3K722KO6IIGGF4NVKEHW5EA
X-MailFrom: rlb@ipv.sx
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/m_JFXlE-9k6NR27CkoOQy-Bs-uw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hi Michael - This does not seem like an appropriate tone or contribution
for this list.

(Chairs please take note.)

On Wed, May 6, 2026 at 3:37 PM Ackermann, Michael <MAckermann=
40bcbsm.com@dmarc.ietf.org> wrote:

> HOSTILE TAKEOVER???????????
>
>
>
> *From:* Eric Rescorla <ekr@rtfm.com>
> *Sent:* Wednesday, May 6, 2026 12:51 PM
> *To:* David Benjamin <davidben@chromium.org>
> *Cc:* TLS List <tls@ietf.org>
> *Subject:* [TLS] Re: Working Group Last Call for Use of ML-DSA in TLS 1.3
>
>
>
> [External email]
>
> +100 to this.
>
>
>
> With any luck, we can take a pause on the discussion of this topic
> on-list. I am aware that there may be pending appeals, but we have a
> process for addressing those that does not require on-list debate.
>
>
>
> -Ekr
>
>
>
>
>
> On Wed, May 6, 2026 at 6:23 AM David Benjamin <davidben@chromium.org>
> wrote:
>
> Thanks, Deirdre, Joe, and Sean, for all your hard work in navigating these
> WG discussions!
>
>
>
> On Wed, May 6, 2026 at 9:09 AM Sean Turner <sean@sn3rd.com> wrote:
>
> Replying to the original consensus call message.
>
>
>
> RFC 2418 Section 3.3 lays out the criteria for “rough consensus”:
>
>
>
>    Working groups make decisions through a "rough consensus" process.
>
>    IETF consensus does not require that all participants agree although
>
>    this is, of course, preferred.  In general, the dominant view of the
>
>    working group shall prevail.  (However, it must be noted that
>
>    "dominance" is not to be determined on the basis of volume or
>
>    persistence, but rather a more general sense of agreement.) Consensus
>
>    can be determined by a show of hands, humming, or any other means on
>
>    which the WG agrees (by rough consensus, of course).  Note that 51%
>
>    of the working group does not qualify as "rough consensus" and 99% is
>
>    better than rough.  It is up to the Chair to determine if rough
>
>    consensus has been reached.
>
>
>
> In this case, during WGLC there was an almost 4:1 ratio for progressing
> this draft, which we judge fits within the numeric “more than 51% and less
> than 99%” range suggested by this text for “rough consensus” and represents
> the “dominant view of the working group”.
>
>
>
> In assessing rough consensus, we also considered the nature of the
> objections. In reviewing the list traffic, the majority of objections
> related to the status of pure MLDSA versus composite MLDSA-ECC, including
> (1) we should not publish a pure MLDSA specification at all; (2) we should
> recommend composites over pure MLDSA; (3) we should publish the composite
> and pure MLDSA specifications concurrently. While there was substantial
> disagreement on these points, we believe that the discussion on-list
> sufficiently aired the respective points of view and that the right
> approach is fundamentally a judgement call based on weighing various
> technical factors, which each WG participant needs to make for themselves.
> We see no reason to believe that participants were not able to make
> informed judgements.
>
>
>
> Conclusion: The chairs believe there is consensus to proceed with
> publication of this draft as an RFC with Recommended=N for those people
> that want to use this algorithm, and a future Standards Action will be
> needed to make a change to Recommended=Y, if anyone has the willingness to
> undergo this heated discussion again.
>
>
> For transparency purposes, the chairs note that we received a
> complaint/appeal about the consensus call. The message was moderated due to
> a previous notice of moderation; see [1], and the complaint/appeal contains
> a derivative work notice. As a result, the message was not sent to the mail
> list and we will not process the complaint/appeal as-is. If the message is
> resubmitted without the notice, the message can be posted to the mail list
> and we will process the complaint/appeal.
>
>
>
> The Chairs,
>
> Deirdre, Joe, and Sean
>
> [1] https://mailarchive.ietf.org/arch/msg/tls/no0lW8r_wIPGF1ZXWB3EaGywh9Q/
> <https://urldefense.com/v3/__https:/mailarchive.ietf.org/arch/msg/tls/no0lW8r_wIPGF1ZXWB3EaGywh9Q/__;!!DVqnNCPqsA!H9Py_Rt__O8pjzUI4OMX2OusR6HFRbXek-Wm9dHUdjLkLaTuW7-CKZAvUaDoN8M1vUJ4yLIQHQ$>
>
>
>
> On Apr 28, 2026, at 16:24, Sean Turner <sean@sn3rd.com> wrote:
>
>
>
> Hi! The chairs have judged that there is consensus to progress this I-D.
> We will work with the authors to get a new version submitted and we will
> get to work on the Shepherd Write-Up.
>
>
>
> The Chairs,
>
> Deirdre, Joe, and Sean
>
>
>
> On Apr 9, 2026, at 15:30, Sean Turner <sean@sn3rd.com> wrote:
>
>
>
> This is the working group last call for Use of ML-DSA in TLS 1.3. Please
> review draft-ietf-tls-mldsa [1] and reply to this thread indicating if you
> think it is ready for publication or not. If you do not think it is ready
> please indicate why. This call will end on April 23, 2026.
>
> REMINDER: If you have not done so recently, review the TLS WG's Mail List
> Procedures; see [2].
>
> The Chairs,
> Deirdre, Joe, and Sean
>
> [1] https://datatracker.ietf.org/doc/draft-ietf-tls-mldsa/
> <https://urldefense.com/v3/__https:/datatracker.ietf.org/doc/draft-ietf-tls-mldsa/__;!!DVqnNCPqsA!H9Py_Rt__O8pjzUI4OMX2OusR6HFRbXek-Wm9dHUdjLkLaTuW7-CKZAvUaDoN8M1vUKcrqJCBA$>
> [2] https://mailarchive.ietf.org/arch/msg/tls/ucdImHExlbOf4Q3BCG81gjzi2xE/
> <https://urldefense.com/v3/__https:/mailarchive.ietf.org/arch/msg/tls/ucdImHExlbOf4Q3BCG81gjzi2xE/__;!!DVqnNCPqsA!H9Py_Rt__O8pjzUI4OMX2OusR6HFRbXek-Wm9dHUdjLkLaTuW7-CKZAvUaDoN8M1vUJmOlAILQ$>
>
>
>
>
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>
> The information contained in this communication is highly confidential and
> is intended solely for the use of the individual(s) to whom this
> communication is directed. If you are not the intended recipient, you are
> hereby notified that any viewing, copying, disclosure or distribution of
> this information is prohibited. Please notify the sender, by electronic
> mail or telephone, of any unintended receipt and delete the original
> message without making any copies.
>
> Blue Cross Blue Shield of Michigan and Blue Care Network of Michigan are
> nonprofit corporations and independent licensees of the Blue Cross and Blue
> Shield Association.
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>