[TLS] Re: [External] WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Ryan Appel <ryan.appel.333@gmail.com> Thu, 25 June 2026 20:36 UTC

Return-Path: <ryan.appel.333@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C602810785415 for <tls@mail2.ietf.org>; Thu, 25 Jun 2026 13:36:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782419814; bh=mkqtxW0VWKFWTHbGg5DbEDpTuh70RqhJqOWU7xArjG4=; h=From:Subject:Date:References:Cc:In-Reply-To:To; b=AGpl2M3VZ4q5ACk51HE5pLGAhYLqbdeAzN40fSbanmysWXlgsXoeWkP0soAyV7VMB 0rzhiINstnHqL4pc6YyChbVVOm7vDhA6tRg/V35HPzjqn4FlPOZAKSzFuvySKGj9h+ dI7Vi8CajSdTBK0e0n4Y67uQcS71eVEriwetj7/0=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.956
X-Spam-Level:
X-Spam-Status: No, score=-0.956 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.1, MIME_HTML_ONLY_MULTI=0.001, MIME_QP_LONG_LINE=0.001, MPART_ALT_DIFF=0.79, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id S731fQntJGE2 for <tls@mail2.ietf.org>; Thu, 25 Jun 2026 13:36:53 -0700 (PDT)
Received: from mail-oi1-x230.google.com (mail-oi1-x230.google.com [IPv6:2607:f8b0:4864:20::230]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id C597E1078540D for <tls@ietf.org>; Thu, 25 Jun 2026 13:36:53 -0700 (PDT)
Received: by mail-oi1-x230.google.com with SMTP id 5614622812f47-491618c81fdso86181b6e.2 for <tls@ietf.org>; Thu, 25 Jun 2026 13:36:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782419807; x=1783024607; darn=ietf.org; h=to:in-reply-to:cc:references:message-id:date:subject:mime-version :from:content-transfer-encoding:from:to:cc:subject:date:message-id :reply-to; bh=D6iF8Lc982m4gmzBuFXvgdpy89g5Srqa7fSUL+ly36Y=; b=YgeGlndXvIbHm0AmwgraGlQg68iBGg/A94CZ1fk0k/HJo51e4LmUzJm+PezIqovsZe cMsCbRU182T3rSX6lXqVgj3eB512Cc7/2fBihQtjStgsYuYK6KI1aMI72FgmosTWE66V 4slb0iXmEMFi4szOeYviV6fHw9Kbq5ODTbIIerpSNk5Tcy4+MiGefu80Ld5tu9nbF+5W T0UVwxwm7+2Wsf8PoRdUflMWGN9Hg7uY/LsJWzlMCIoU5JSBlYOqljaTOTat1T3rOK6t 7EYY2rguMhBYcfyk/dmoFufhCFL2IAH4cclRVq7mGHDIq2TM7SPbV8I26jYOaOYLwAhT BvIw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782419807; x=1783024607; h=to:in-reply-to:cc:references:message-id:date:subject:mime-version :from:content-transfer-encoding:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=D6iF8Lc982m4gmzBuFXvgdpy89g5Srqa7fSUL+ly36Y=; b=I+cRKfj9Z7n40bssh4MPZ9EPsPF1TxEzgm7dzp/I+n/G9XiROoTAcwlEYhf05b2OR1 ORIgqUc69ERTJSmCLyiskzJJW6Sf2SJLjRZVX+CcdC+7JI4NlqAsQGzHfDO9OqkjO1Zb 8WeIhMTDfCFgwRT6mC/sl1Zo4KBwtE/JpUUqfmkAvKYTXNCgPG+lTVTfp37OTiCgzhnn snUnmPPYTms6iF+8Qv6u1LY1RcPJbSx9THqK92akWLIa7Kkd1wq2EBqyX7UXcS+IbrPv JlNNHCL02KkBPuxzPCgSvIrmg5perdWzDRkEMUdZiQYlsc/bP1IYBbqwIFLIajxzrh/w cfTw==
X-Forwarded-Encrypted: i=1; AFNElJ+q3BBDXtcDnSzdP9V+PkzUdYEqnLJ1h5ENauIP2wvMNS++yd+ieicHGod1udlRApyOjL0=@ietf.org
X-Gm-Message-State: AOJu0Yyq26nt0c+q9AVWtYyjnm2cHoxuAT4g1qXPy3iKBVB7FS4Bvn3m MOe7b0QYN5qEIcXVbWKhq95+BT/8FJGoNTax/RMyVc5vWbS2KiKKfLS9kZtZXnn+
X-Gm-Gg: AfdE7cmA0vvPVZ3LIVeDkAdycujWOSQGBR/KyGRujJkFVZG3s7NXZV7u7tNFvtDEb1L VegoJgtmJJWwRpYCmeYyNa6SRi1tSUEgCm5Xi7KQdbPYZOpQEjB3SK/yJH+u5Yruob99mMdjROc ktukTSkNoWC5TWmNrBYVipNYKJ7VTaXfHGUvcyYHs4xiy7zRlrDI/0EQrm1Tt2+DO3+Qmw7T2HQ vDIVMvzaIL5As73RjzQIlOhS+FIlFelzGpOwNrS7BoM95RhVlSlGHQfeJP/4JMs1fMBUw+VS9xC iSJCdX/psEcDbJOb1+/KvMbFBpVKome6k86fhXoTVvNbf343QhwL8EZ5TZ7mVNh359W0pAGmD5I fx1JVQswEIrk0JFSICCSqS1/GCKo2vXueh5/5dHfpdv6WcD78Q24xpVo5AMzi94aqYAG+acauIP mJ02JBXiyANfRtiE4psJEqMwauNN297LWlsJ6D1dkEVBwHczhBzUp6O5NSQQThZA==
X-Received: by 2002:a05:6808:5185:b0:485:41fc:71dd with SMTP id 5614622812f47-492173355fdmr3298204b6e.13.1782419807077; Thu, 25 Jun 2026 13:36:47 -0700 (PDT)
Received: from smtpclient.apple ([2600:1702:5238:9080:794f:721a:307e:bfa0]) by smtp.gmail.com with ESMTPSA id 5614622812f47-4935545dad9sm48098b6e.16.2026.06.25.13.36.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 25 Jun 2026 13:36:45 -0700 (PDT)
Content-Type: multipart/alternative; boundary="Apple-Mail-0817AAC5-C8F7-4E8A-A625-5AB54CFD2090"
Content-Transfer-Encoding: 7bit
From: Ryan Appel <ryan.appel.333@gmail.com>
Mime-Version: 1.0 (1.0)
Date: Thu, 25 Jun 2026 15:36:34 -0500
Message-Id: <B37D9D97-9C26-46FB-9416-E7C22A26488E@gmail.com>
References: <CAFR824yGd7OHa_Dz8sMOyJ7q5cnyzP+t1yVrf9zawrBKGYifCg@mail.gmail.com>
In-Reply-To: <CAFR824yGd7OHa_Dz8sMOyJ7q5cnyzP+t1yVrf9zawrBKGYifCg@mail.gmail.com>
To: Deirdre Connolly <durumcrustulum@gmail.com>
X-Mailer: iPhone Mail (23F81)
Message-ID-Hash: OMWUDD2MPBML2BZAYSNIYU5J5XJSOMC3
X-Message-ID-Hash: OMWUDD2MPBML2BZAYSNIYU5J5XJSOMC3
X-MailFrom: ryan.appel.333@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-tls-mlkem@ietf.org, tls-chairs@ietf.org, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [External] WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/np6pi6VzgHBPd0iffK5Fc3KabrQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I support publication. 
Thank you,
    Ryan Appel, MS, BCS

On Jun 24, 2026, at 12:28 PM, Deirdre Connolly <durumcrustulum@gmail.com> wrote:


On Wed, Jun 24, 2026 at 12:04 PM Schäfer, Pascal <pascal.schaefer@accenture.com> wrote:
I support the publication of this document.

Only one editorial comment beside of the other mentioned editorial comments:
In the abstract I saw an "and and", which should probably just an "and".


-----Original Message-----
From: Joseph Salowey via Datatracker <noreply@ietf.org>
Sent: Mittwoch, 24. Juni 2026 17:00
To: draft-ietf-tls-mlkem@ietf.org; tls-chairs@ietf.org; tls@ietf.org
Subject: [External] [TLS] WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

WARNING: External email. Be vigilant with links, attachments, and requests.

This message initiates a new Working Group Last Call for draft-ietf-tls-mlkem[1], which defines standalone ML-KEM key establishment for TLS 1.3. The main question before the working group is: "Should the working group publish a document specifying stand alone ML-KEM?". If there is rough consensus then we will push to refine and publish the document; otherwise, we will stop discussing the draft and not progress it. Please respond to this call indicating whether you support publishing a document specifying a stand alone ML-KEM. Please refrain from further discussion on this topic as most arguments have been discussed multiple times.

Why are we holding this consensus call now?

Significant developments have occurred both within this document and in the broader TLS ecosystem to address the concerns raised in the last WGLC. Therefore, the third consensus call is warranted. We ask the working group to consider document publication in light of these recent changes:

- Promotion of Hybrids in draft-ietf-tls-ecdhe-mlkem: Following a separate consensus call, the WG agreed to promote the X25519MLKEM768 hybrid group to Recommended: Y in the IANA registry. Consequently, the IANA registry will reflect a clear community preference for a hybrid because Recommended: Y clearly indicates this while the standalone ML-KEM groups defined in this draft remain Recommended: N. The updated security considerations in [1] reference the IANA registry to emphasize this preference.

- Key Share Reuse Prohibited in draft-ietf-tls-rfc8446bis: The WG recently reached consensus to explicitly prohibit key share reuse across connections in TLS 1.3. The new text changes the guidance from SHOULD NOT to a strict MUST NOT. This resolves the concerns regarding static key reuse and its associated privacy and forward-secrecy risks for ML-KEM.

- Nadim updated the ProVerif model of TLS 1.3 to evaluate KEM and hybrid KEM groups in TLS 1.3. This supports other results which show that KEMs are secure when used in TLS 1.3 and that hybrid groups are secure even if one of the components is compromised.

- Liaisons: We received liaison statements from multiple SDOs including  O-RAN[2], IEEE 802.11[4] and from 3GPP[3]  expressing support for the publication of draft-ietf-tls-mlkem as an RFC as they rely on the IETF to provide a stable normative reference.

Please note that a third-party IPR disclosure exists [5] against this document regarding patents related to the underlying ML-KEM algorithm. This IPR declaration has not changed since the last WGLC. As a reminder, per BCP 79, the IETF takes no stance on the validity of patent claims, and the working group may decide to proceed with a technology despite IPR disclosures if it decides that such use is warranted.

Conduct Reminder: Given the heated nature of previous discussions on this topic, participants are strongly reminded to adhere to the IETF Code of Conduct (BCP 54) and the TLS WG's Mail List Procedures. Keep feedback professional, technical, and focused on the document's text.

This working group last call will end on 2026-07-08.

Joe and Sean

[1] https://urldefense.com/v3/__https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7Xp19ojzQ$" rel="noreferrer nofollow" target="_blank">https://urldefense.com/v3/__https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7Xp19ojzQ$
[2] https://urldefense.com/v3/__https://datatracker.ietf.org/liaison/2198/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7UVzVFYJQ$" rel="noreferrer nofollow" target="_blank">https://urldefense.com/v3/__https://datatracker.ietf.org/liaison/2198/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7UVzVFYJQ$
[3] https://urldefense.com/v3/__https://datatracker.ietf.org/liaison/2151/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7V-27j4vg$" rel="noreferrer nofollow" target="_blank">https://urldefense.com/v3/__https://datatracker.ietf.org/liaison/2151/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7V-27j4vg$
[4] https://urldefense.com/v3/__https://datatracker.ietf.org/liaison/2148/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7VaUHPDRw$" rel="noreferrer nofollow" target="_blank">https://urldefense.com/v3/__https://datatracker.ietf.org/liaison/2148/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7VaUHPDRw$
[5] https://urldefense.com/v3/__https://datatracker.ietf.org/ipr/search/?submit=draft&id=draft-ietf-tls-mlkem__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7XeMmnQZw$" rel="noreferrer nofollow" target="_blank">https://urldefense.com/v3/__https://datatracker.ietf.org/ipr/search/?submit=draft&id=draft-ietf-tls-mlkem__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7XeMmnQZw$

_______________________________________________
TLS mailing list -- tls@ietf.org
To unsubscribe send an email to tls-leave@ietf.org

________________________________

This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security, AI-powered support capabilities, and assessment of internal compliance with Accenture policy. Your privacy is important to us. Accenture uses your personal data only in compliance with data protection laws. For further information on how Accenture processes your personal data, please see our privacy statement at https://www.accenture.com/us-en/privacy-policy" rel="noreferrer nofollow" target="_blank">https://www.accenture.com/us-en/privacy-policy.
______________________________________________________________________________________

http://www.accenture.com" rel="noreferrer nofollow" target="_blank">www.accenture.com
_______________________________________________
TLS mailing list -- tls@ietf.org
To unsubscribe send an email to tls-leave@ietf.org