[TLS] Re: Fwd: New Version Notification for draft-reddy-tls-composite-mldsa-11.txt
tirumal reddy <kondtir@gmail.com> Fri, 28 August 2026 05:50 UTC
Return-Path: <kondtir@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 895EA130CD4BE for <tls@mail2.ietf.org>; Thu, 27 Aug 2026 22:50:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787896240; bh=hKBlZGB0cO75sCGi0RT9Yp+pGEY6wQhySjO0fGeVBz8=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=TIEdM1JVC3lxY6kNd27HqtB56U1A8T/isTuZXqv2xu308PYoREIslMfdL1iWoCkNL cWfTPVn3iDhdDx4ru/Jn4WCxKI08nh/45RfVk6h29XqrKxyhOHXX53cB69Wku5kN/o HQPJlA4amRtO89XLt1i4QzVXWw6IWpI1OzI7Ag/8=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1tqGkRYG-vO2 for <tls@mail2.ietf.org>; Thu, 27 Aug 2026 22:50:39 -0700 (PDT)
Received: from mail-ot1-x329.google.com (mail-ot1-x329.google.com [IPv6:2607:f8b0:4864:20::329]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id B9FE4130CD4B7 for <tls@ietf.org>; Thu, 27 Aug 2026 22:50:39 -0700 (PDT)
Received: by mail-ot1-x329.google.com with SMTP id 46e09a7af769-7f3ece23165so772274a34.0 for <tls@ietf.org>; Thu, 27 Aug 2026 22:50:39 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787896239; cv=none; d=google.com; s=arc-20260327; b=CIubOzTwGAWQEMnn+NVNgv3s/2BQMjgja/mKktI7SL3sqxIcUlHdMSWpbQN+v7YmHT 9FWQlh1uc7BNV98QyO4+ey8wn/e6z9tBI5AAlcdEdQJHcfyqU2NQ25G9e6f0b/hVnMIW AzAbjuV+e9FCWjKgc6eIXQRhhAEBH6JWW2PNlAPToPzRgRCV9+f9UnDTn1R8yLc9AOzg FMEW8J4Pc5NWIIZnHyYMnv2GaUQXJJX8+KIXRhrHCXYvuipp3qBlKzTbY+EnZvEt0EZC Vfknn3uYIOuST5BhFLlc0SbaHGprZn488csXs1xTz18f9K6mC1vrilK88AgGfWJxemfc IHgg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=KXujujbMDx9vmyh0R7XxbmLafglzmhTzFv41N1IgxWU=; fh=pVsAYx7+jVkYM1JEF8nANSYcVP/PXC1gsK+v4KBdrmM=; b=gcb8RbPPPhru4wNbcd8csZN8H/xK2vRbZkXyxbkRpZptQMXr4Yp4HYmFCPlLAhaUmK VteyHuby00kLZxSYqxw78KsUs7JjIFdnQWF6gAWn+wCA/DoE5HHe8hpfcZgxqJDiZnsi vr6pTKcZa4PbTNv+ybQdrSaqWI1tQuAdE5T496tGPVrREhFqptFtWQIkF0IcOwTUapFg WW5Gw5NRCpx3rjTT9f9xRu5A9zdYqqbmnmQUJMYFRVeZLcrRIE8izdXNzIai4ihkdHdA T35J2chXfuE5UuAcSmSALpSp/oZoDiSmOTkot7Fh6ecYGH/aJbBL3svyMf5QkD1gQn83 0GdA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787896239; x=1788501039; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=KXujujbMDx9vmyh0R7XxbmLafglzmhTzFv41N1IgxWU=; b=Faop0By5z0YE3yUnPIG3Hs2enFC6QpzgBl5oA+0ifYO6efRp24lSnhTU7Zf4IUThp7 iXE7IU7TEU+prEKfisHOK7E0CUVWlMMk43HPRibPn6GcRxaMtdiiJmzw4YlpQETIjNzV hDCo/yFkq4dfWxG+Mg6jfRf2oErChkaQla9+Zcj2QmxiJJEHo2hvWu90v2sQV8u9X+ME nhdalx2HKkQG6ON5GCDRaRxGUHAaf2En8gNQ5d8BHsJyY+i41Jnp/eROcxocHXnAaOca RIY1td5ZVFHdSDbXLIHXiUNPD/ogaNTkOcT0Y9ljG1ugMmCFWy3nQA2W2CkBMK6qDptT nnkQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787896239; x=1788501039; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=KXujujbMDx9vmyh0R7XxbmLafglzmhTzFv41N1IgxWU=; b=oUJen4h1wduUsBRzgSBMMHZCHHQG2mb/vwguMjacP/uz+GqTYxutICNzHDAr+pPnPs qrAjK0YdYR/ZV8qgHTAWQVc9T63CMcKWqQ85yT8f3+ya2kGHLzwAWaRW4et7K2RgaLnc QrwlHuFa1CCEkW6AyPRc1w21omkYrlflNgxOPi8pbad9QUaMd3dv/OeNuIiovi0V1tLI zo6y5hiasol9DV/sU6uzhkAzIW/yJIot+CtoKyE19BSa9qMbFMDBxwX0icgIQmGU+o2c WNn1DkXkn4GecGlccG2K2UDbVG75JFrxxz3GG6G+1BWja+4KwOePbmb1NDIAfaAD9TGW NpaQ==
X-Gm-Message-State: AFuF++lMZOXLbyVGYe+25UIwIcW/gP+VrGHaotd79QSjAkccGLyW+WiE pN124YnyHDtveEUaJu5BMKMPO+qzGqZ/3AxruI55O1aSfZX3VdBsKfBx29WwdhjOmy2qLy2FZa/ Hj5aUmDd6ouRF9wXJ3vdnG5n6ZXv6lSEzpg==
X-Gm-Gg: AR+sD10EXtN/Tnbdn8zU0H5XdSDP85BL+ig9bZomF9kQlLQgsenl77WhRGeidOIlPcc Gofk9B8CynjAt2R0fY1Y5JHjK/MXVX/2jmn6QZvKRcS1Muo1FOj29qt3WRN04vNaX5c8HxX5tmo 9YZbEZoyPHTyrAURaDSWzrqhA7g7IjfliOD7nvruGONz9flw2h3rqTpTt4ubpp56qgkZ7l70jW6 Fdfz8Cmp4ddnYnwUFHKcCFxwSoSlxXcUadPJfUKmxrE+TXqmjISrpYxIA+BZGEUY3rZJ4TScy5K JnD6PP40DJIdqABVjZ9cuEOPwwpMcWO1r7RAr/kMJ9kHLdMaJvcupdxLHMZ6BD8fkJbKUPqpKNu M
X-Received: by 2002:a05:6820:7049:b0:6b1:a11a:eeaf with SMTP id 006d021491bc7-6b1c66c3a86mr3359632eaf.13.1787896238880; Thu, 27 Aug 2026 22:50:38 -0700 (PDT)
MIME-Version: 1.0
References: <178705738239.532236.9732380350992727627@dt-datatracker-7c6ddbc678-lb5nk> <CAFpG3gdxmCKQkf42R=iLSKR12tafk1hFYw25N=ae5DrKtXY6dg@mail.gmail.com> <0a0f5a93229a4266ab4c46bad9131fd9@huawei.com>
In-Reply-To: <0a0f5a93229a4266ab4c46bad9131fd9@huawei.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Fri, 28 Aug 2026 11:20:01 +0530
X-Gm-Features: AcwNN1VURXcPtX76yNinH0bsm_3Y40ab9GuWTKjxDKA1kbQxU-XqKZJI2-s5-aY
Message-ID: <CAFpG3gej2Ji5VHq8KEudpp0aWU2OXZcP2Wwdv6C=L17C_wx-jQ@mail.gmail.com>
To: Wang Guilin <Wang.Guilin@huawei.com>
Content-Type: multipart/alternative; boundary="00000000000036bc52065a150816"
Message-ID-Hash: WC6LLQXFZ3UVQK27FMF67ZQJ7BDD2H4B
X-Message-ID-Hash: WC6LLQXFZ3UVQK27FMF67ZQJ7BDD2H4B
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "<tls@ietf.org>" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Fwd: New Version Notification for draft-reddy-tls-composite-mldsa-11.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/puGUvWRkjTSqxd30jK1kid4GyIM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Hi Guilin, Thanks, I agree with both comments; they are now fixed in PR https://github.com/tireddy2/composite-mldsa/pull/17. On SUF-CMA: it isn't about the traditional component being broken. A composite is SUF-CMA only if every component is, and for instance, ECDSA isn't, so some of those composites already fail SUF-CMA today. On the second point: the text now has the attacker deriving the private key from the traditional public key in the server's existing certificate and becoming an on-path attacker. No certificate forgery or CA compromise is required. I also added another threat vector: an attacker that derives a CA's private key can issue certificates for any name, which also affects a server that has already moved to a composite certificate if a traditional CA is still trusted by the client. -Tiru On Tue, 25 Aug 2026 at 12:09, Wang Guilin <Wang.Guilin@huawei.com> wrote: > Thanks for the update. > > > > Read Section 5 (Security Considerations). The following two parts could be > improved, I think. > > > > "However, composite signature schemes do not in general preserve strong > unforgeability (SUF-CMA) once the traditional component algorithm is > broken, for example due to the availability of CRQCs. " > > > > This description seems not really accurate, as composite signature schemes > [I-D.ietf-lamps-pq-composite-sigs] do not preserve strong unforgeability > (SUF-CMA) as long as either of the component signature algorithm is not > SUF-CMA, not just in the case of "once the traditional component algorithm > is broken". > > > > But I do agree on "This loss of SUF is inherent to the composite > construction and does not impact TLS". > > > > Also, the following is just an attacking scenario for an adversary CRQC. > > > > "TLS clients that support both post-quantum and traditional-only signature > algorithms are vulnerable to downgrade attacks. In such scenarios, an > attacker with access to a CRQC could forge a traditional server certificate > and impersonate the server. If the client continues to accept > traditional-only certificates for backward compatibility, it remains > exposed to this risk." > > > > In my understanding, a more natural and better hidden attack is to either > compromise the server's private key or forge a valid signature w.r.t. the > server's existing traditional public key certificate. > > > > Cheers, > > > > Guilin > > > > *From:* tirumal reddy <kondtir@gmail.com> > *Sent:* Tuesday, 18 August 2026 9:18 pm > *To:* <tls@ietf.org> <tls@ietf.org> > *Subject:* [TLS] Fwd: New Version Notification for > draft-reddy-tls-composite-mldsa-11.txt > > > > Hi all, > > We have published a revised version of the draft: > https://datatracker.ietf.org/doc/html/draft-reddy-tls-composite-mldsa. > This revision incorporates the feedback received from the WG. The main > changes include adding the missing composite algorithm based on the > selection criteria in the draft, clarifying why the loss of SUF-CMA > security does not impact TLS authentication, and adding downgrade security > considerations. > > Please take a look and let us know if there are any further comments or > issues. > > Thanks, > -Tiru > > ---------- Forwarded message --------- > From: <internet-drafts@ietf.org> > Date: Tue, 18 Aug 2026 at 18:19 > Subject: New Version Notification for > draft-reddy-tls-composite-mldsa-11.txt > To: Tirumaleswar Reddy.K <kondtir@gmail.com>, Daniel Van Geest < > daniel.vangeest@cryptonext-security.com>, John Gray <john.gray@entrust.com>, > Scott Fluhrer <sfluhrer@cisco.com>, Timothy Hollebeek < > tim.hollebeek@digicert.com> > > > > A new version of Internet-Draft draft-reddy-tls-composite-mldsa-11.txt has > been successfully submitted by Tirumaleswar Reddy and posted to the > IETF repository. > > Name: draft-reddy-tls-composite-mldsa > Revision: 11 > Title: Use of Composite ML-DSA in TLS 1.3 > Date: 2026-08-18 > Group: Individual Submission > Pages: 16 > URL: > https://www.ietf.org/archive/id/draft-reddy-tls-composite-mldsa-11.txt > Status: > https://datatracker.ietf.org/doc/draft-reddy-tls-composite-mldsa/ > HTML: > https://www.ietf.org/archive/id/draft-reddy-tls-composite-mldsa-11.html > HTMLized: > https://datatracker.ietf.org/doc/html/draft-reddy-tls-composite-mldsa > Diff: > https://author-tools.ietf.org/iddiff?url2=draft-reddy-tls-composite-mldsa-11 > > Abstract: > > Compositing the post-quantum ML-DSA signature with traditional > signature algorithms provides protection against potential breaks or > critical bugs in ML-DSA or the ML-DSA implementation. This document > specifies how such a composite signature can be formed using ML-DSA > with RSA-PKCS#1 v1.5, RSA-PSS, ECDSA, Ed25519, and Ed448 to provide > authentication in TLS 1.3, including use in certificates. > > > > The IETF Secretariat > >
- [TLS] Fwd: New Version Notification for draft-red… tirumal reddy
- [TLS] Re: Fwd: New Version Notification for draft… Wang Guilin
- [TLS] Re: Fwd: New Version Notification for draft… tirumal reddy
- [TLS] Fwd: New Version Notification for draft-red… Wang Guilin