[TLS] FYI: Ubuntu 26.04.01 GnuTLS ML-DSA sigalg friction

Viktor Dukhovni <ietf-dane@dukhovni.org> Wed, 02 September 2026 18:10 UTC

Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 735B01340EF2D for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 11:10:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788372652; bh=sOY3Y2EJfczgq38GTxI/iWkx3dw39BNYpGMtddC/JCs=; h=Date:From:To:Subject:Reply-To; b=MiWP2I8ZrpBUeeCZiyFCVVqVqQiw9rxctCoOyqkaEoc4C/IBAbOOHuYJscrGXqc7Z EF3iKnDbj49fkIIJebhsV/AKjIQX/R/RX9u7GO46RFRva0J89k1rqjdf/D7GdRS+q1 5P8AGkqfbExdhHJeIE9Zh4ImvNBmCnLBNfH78g5Y=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.398
X-Spam-Level:
X-Spam-Status: No, score=-4.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=dukhovni.org
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aVXsb8YiccHJ for <tls@mail2.ietf.org>; Wed, 2 Sep 2026 11:10:52 -0700 (PDT)
Received: from chardros.imrryr.org (chardros.imrryr.org [144.6.86.210]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id C9BB71340EF12 for <tls@ietf.org>; Wed, 2 Sep 2026 11:10:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=dukhovni.org; i=@dukhovni.org; q=dns/txt; s=f8320d6e; t=1788372640; h=date : from : to : subject : message-id : reply-to : mime-version : content-type : content-transfer-encoding : from; bh=sOY3Y2EJfczgq38GTxI/iWkx3dw39BNYpGMtddC/JCs=; b=HBb1+y7UjSk0B/YNiUIgKnrf/ctGjZR91sO4zRVf1UlwpgzKRDY6yJg4FeTkK1dxygrGR vrlVW8ZE9CHq+cdzF7eOW/9VXyOjJgMmMdEN5LJDGlFzFfpbVb1LsFgpv2O1Of8dC9RD6iO d+dhjwM9VUk6yb2TCNnSOC1N3/rAtvc=
Received: by chardros.imrryr.org (Postfix, from userid 1000) id 1783D93559C; Thu, 03 Sep 2026 04:10:40 +1000 (AEST)
Date: Thu, 03 Sep 2026 04:10:39 +1000
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
To: tls@ietf.org
Message-ID: <aphmn2ZdoGs3tiNv@chardros.imrryr.org>
Mail-Followup-To: tls@ietf.org
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: 4Y7Q6VBCBVGGRO5MKSG7OOD3IMDLUVRK
X-Message-ID-Hash: 4Y7Q6VBCBVGGRO5MKSG7OOD3IMDLUVRK
X-MailFrom: ietf-dane@dukhovni.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Reply-To: tls@ietf.org
Subject: [TLS] FYI: Ubuntu 26.04.01 GnuTLS ML-DSA sigalg friction
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/pMukNXS7-0aeqyC9DeCgcCWm9j8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

An Exim MTA SMTP client on Ubuntu 26.04.01 with default settings is
unable to negotiate a TLS connection to my SMTP server because its
GnuTLS library advertises ML-DSA-{44,65,87} sigalgs even though the
implementation of the corresponding verification algorithms in
libnettle is stubbed out and always fails.

My server has both RSA and ML-DSA keys and selects the latter when
both are offered by the client.

For the specific case reported, Exim falls back to cleartext (the sending
system has not enabled client-side DANE) so I am still able to receive
email from that system.  Other Ubuntu 26.04.01 configurations may in
fact be unable to send me mail without explicitly overriding the sigalg
list. :-(

I hope this combination will not become entrenched.

-- 
    Viktor.  🇺🇦 Слава Україні!

    (gdb) fr 0
    #0  ml_dsa_verify (algo=GNUTLS_PK_MLDSA65, signature=0x7fff41dbfab0, message=0x7fff41dbfac0, raw_pub=0x55c364b1a430)
        at nettle/../../../lib/nettle/pk.c:1849
    1849            return gnutls_assert_val(GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
    (gdb) l -
    1844    static int ml_dsa_verify(gnutls_pk_algorithm_t algo MAYBE_UNUSED,
    1845                             const gnutls_datum_t *signature MAYBE_UNUSED,
    1846                             const gnutls_datum_t *message MAYBE_UNUSED,
    1847                             const gnutls_datum_t *raw_pub MAYBE_UNUSED)
    1848    {
    1849            return gnutls_assert_val(GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
    1850    }

The full backtrace is:

    (gdb) bt
    #0  ml_dsa_verify (algo=GNUTLS_PK_MLDSA65, signature=0x7fff41dbfab0, message=0x7fff41dbfac0, raw_pub=0x55c364b1a430)
        at nettle/../../../lib/nettle/pk.c:1849
    #1  _wrap_nettle_pk_verify (algo=GNUTLS_PK_MLDSA65, vdata=0x7fff41dbfac0, signature=0x7fff41dbfab0, pk_params=0x55c364b1a398,
        sign_params=0x7fff41dbfa00) at nettle/../../../lib/nettle/pk.c:2719
    #2  0x00007fb19bbb0639 in pubkey_verify_data (se=se@entry=0x7fb19bd2d830 <sign_algorithms.lto_priv+2800>,
        me=me@entry=0x7fb19bd2cbf0 <hash_algorithms.lto_priv+1456>, data=data@entry=0x7fff41dbfac0,
        signature=signature@entry=0x7fff41dbfab0, params=params@entry=0x55c364b1a398, sign_params=sign_params@entry=0x7fff41dbfa00,
        flags=33619968) at ../../lib/pubkey.c:2695
    #3  0x00007fb19bbb32af in gnutls_pubkey_verify_data2 (pubkey=0x55c364b1a390, algo=<optimized out>, flags=33619968,
        data=0x7fff41dbfac0, signature=0x7fff41dbfab0) at ../../lib/pubkey.c:2209
    #4  0x00007fb19bbc7e42 in _gnutls13_handshake_verify_data (session=0x55c364b20b90, verify_flags=33619968, cert=0x7fff41dbfad0,
        context=0x7fb19bd277c0 <srv_ctx>, signature=0x7fff41dbfab0, se=<optimized out>) at ../../lib/tls13-sig.c:132
    #5  _gnutls13_recv_certificate_verify (session=0x55c364b20b90) at ../../lib/tls13/certificate_verify.c:128
    #6  0x00007fb19bb5f0f8 in _gnutls13_handshake_client (session=0x55c364b20b90) at ../../lib/handshake-tls13.c:131
    #7  0x00007fb19bb77bcb in handshake_client (session=0x55c364b20b90) at ../../lib/handshake.c:3094
    #8  gnutls_handshake (session=0x55c364b20b90) at ../../lib/handshake.c:2914
    #9  0x000055c35a22ea0c in do_handshake (socket=socket@entry=0x7fff41dc5200) at ../../src/cli.c:1856
    #10 0x000055c35a22f97c in socket_open_int (hd=hd@entry=0x7fff41dc5200, hostname=0x7fff41dc7826 "mx1.imrryr.org",
        service=service@entry=0x55c35a2b6ea0 <service> "25", app_proto=0x7fff41dc77ef "smtp", app_hostname=0x0,
        flags=flags@entry=68, rdata=0x0, edata=0x0, server_trace=0x0, client_trace=0x0, msg=0x55c35a238750 "Connecting to")
        at ../../src/socket.c:627
    #11 0x000055c35a228e4e in main (argc=<optimized out>, argv=<optimized out>) at ../../src/cli.c:1366