[TLS] Re: WG Adoption Call for Post-Quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3

Arnaud Taddei <arnaud.taddei@broadcom.com> Thu, 27 February 2025 07:55 UTC

Return-Path: <arnaud.taddei@broadcom.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4E18829A388 for <tls@mail2.ietf.org>; Wed, 26 Feb 2025 23:55:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.539
X-Spam-Level:
X-Spam-Status: No, score=-2.539 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.442, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietfa.org (amavisd-new); dkim=pass (1024-bit key) header.d=broadcom.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietfa.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5bgfeirpzbHh for <tls@mail2.ietf.org>; Wed, 26 Feb 2025 23:55:18 -0800 (PST)
Received: from mail-yw1-x1134.google.com (mail-yw1-x1134.google.com [IPv6:2607:f8b0:4864:20::1134]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9D83029A36A for <tls@ietf.org>; Wed, 26 Feb 2025 23:55:16 -0800 (PST)
Received: by mail-yw1-x1134.google.com with SMTP id 00721157ae682-6fb2a6360efso5407807b3.0 for <tls@ietf.org>; Wed, 26 Feb 2025 23:55:16 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=broadcom.com; s=google; t=1740642916; x=1741247716; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=GU6SYwHIGUNjRXw3qxkkqtOXeKsUTlsfZTJ5KGp/mJM=; b=W6imiB+9+6kdJaSLFuzZbJNYDl4nFYCiPw8HPErIbjOF+cS6vBZFvlHzvdelYFnKPK /a9pxOKUIQcMAgYFzawLy66hUzYI0yzWSejFIGxjMviUPKBahdiPfwQOj3cMIkCDqIj/ yVtspmuUIWiL80qZq/BjjrO3bXk/Ej73zOdwo=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1740642916; x=1741247716; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=GU6SYwHIGUNjRXw3qxkkqtOXeKsUTlsfZTJ5KGp/mJM=; b=qPodnThdTFDPaWmBi1iJxoyio0ZikGf5C6J11Qgr9uEBsh9dxFVp+6TLXPZOBC9HxZ QeADw6rnoBkIv9OuuFoVpTgN0mosrj7VRBXXviwdwcECnuVc/RXKqJN5PKFyJMYC4mzn Ut6Cw6dOikh3n6FPH44M9T5pHFNDZAhEQE9QRo6azoKPVp+4lJ2Qwtfbn6u6ekmEWlLt b+tZYyAm1kRfCumBMz/npD7F2Yir4z8UB7C2CKHfJpPfxqlbl2Wg+bVYAmxnAMv3yRF7 +Esm+M3nYCz1rSCWr1x4E/FADcjxV5sYr6lRKnO3xZZT1UyEvi3n8dfrlcuj7CwQB6v7 TnHw==
X-Forwarded-Encrypted: i=1; AJvYcCWsDAn+0UeDkLzKHijj0BsCtDRxq80QGBT0kjG5rFOK4RkHF4YrXa6GOvU114qj7Csvvmc=@ietf.org
X-Gm-Message-State: AOJu0Yy5EkYtb3H31PuQQ2X4qXmUig/5Gxr540sL0Oyuci9UEGl1ATik fkiDTDD0/v9HigNlRbUnfO97bpEOecsnF//3CjgBnTYubAGRZ65NpRJ5QDeOtIDYosSvyeUThEf 6hy7IVpOOLzKWcoo8ZiYlaEsNGBp1HioBDp9taixcAorZ3deyYAdMDf+PIbrUIf5hgIqpLqWs2b 1QEvQune+uxuahFHafhQ==
X-Gm-Gg: ASbGncud3yonzKKtONFr2eOZfa1osXmBFwCZspag8bbMoDPXIlpjZ3idMCl6VnaZtwS GWfBzMTJJIh8YUbd7Gqvygsyi/3egGYKg3yPV0y3+dAqeoCnylYd1gMMJf3XCo43qaz1xQG4F+1 NqaJguytFWH6c6tNql3RSBSuT35iioNixdhUvGxvk=
X-Google-Smtp-Source: AGHT+IGNDwLPLmfVYQZiyoORegh3OI9aWa6OxWgTGLIXIsppGukD88XAtyKO+pWSxmA47FvN5xOWO23iVEeubGEo/e4=
X-Received: by 2002:a05:690c:6501:b0:6fb:ae6b:a340 with SMTP id 00721157ae682-6fbcc364aa6mr218911497b3.30.1740642915696; Wed, 26 Feb 2025 23:55:15 -0800 (PST)
MIME-Version: 1.0
References: <68EDF12D-1C97-4823-AFFE-19BF261D7034@sn3rd.com> <CAOp4FwTLD5LPFG+a=1K7d0mOb9iTpH4DA2JL0+-mGmyoAK4yzA@mail.gmail.com>
In-Reply-To: <CAOp4FwTLD5LPFG+a=1K7d0mOb9iTpH4DA2JL0+-mGmyoAK4yzA@mail.gmail.com>
From: Arnaud Taddei <arnaud.taddei@broadcom.com>
Date: Thu, 27 Feb 2025 08:55:03 +0100
X-Gm-Features: AQ5f1Jq1zoXTqDsHBoCKRLxe7mqlbsH2zY9rbSDzF_9hQcBULqpxRHQ_p_E6okQ
Message-ID: <CAMTNNNc_cqbuVqQOHoBstzFK5pap9xXJuCGF9TbBWt=r=wb76w@mail.gmail.com>
To: Loganaden Velvindron <loganaden@gmail.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-256"; boundary="000000000000b0c222062f1b0208"
Message-ID-Hash: L34Q3Z7NGKQ6A67YE4ZJZ66IXWHOZA4Q
X-Message-ID-Hash: L34Q3Z7NGKQ6A67YE4ZJZ66IXWHOZA4Q
X-MailFrom: arnaud.taddei@broadcom.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Adoption Call for Post-Quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/qG_6-PjW02S3q1FquvXu2KClHvc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I support adoption

On the good point opened by Chris Wood and to echo Peter, I see the same
syndrome from other SDOs. If not in a ratified text people won't move.

Trying to find an explanation for why this is the case, for nearly all the
customers I work with, teams have a lot of limits to what they can do
unless their business, legal and compliancy team says so.

In other words, if a standard with its text, number, etc. is not attached
to the *harmonisation* of a given Regulation that must be implemented, it
is very hard for the teams to make the business case for why things need to
be done to their decision makers.

I am under the impression it created a general culture of "if not in the
text, we don't need to do it"

But as Chris I don't want to make it a distraction to this thread.

Arnaud Taddei

Global Security Strategist | Enterprise Security Group | ITU-T SG17 chair

mobile: +41 79 506 1129

Geneva, Switzerland

arnaud.taddei@broadcom.com | broadcom.com


On Thu, Feb 27, 2025 at 8:01 AM Loganaden Velvindron <loganaden@gmail.com>
wrote:

> I support adoption.
>
> On Wed, 26 Feb 2025 at 22:32, Sean Turner <sean@sn3rd.com> wrote:
> >
> > At IETF 121, the WG discussed “Post-Quantum Hybrid ECDHE-MLKEM Key
> Agreement for TLSv1.3”; see [0] and [1]. We also had some discussion in an
> information gathering thread; see [2]. We would like to now determine
> whether there is support to adopt this I-D. If you support adoption and are
> willing to review and contribute text, please send a message to the list.
> If you do not support adoption of this I-D, please send a message to the
> list and indicate why. This WG adoption call will close at 2359 UTC on 12
> March 2025.
> >
> > One special note: this adoption call has nothing to do with picking the
> mandatory-to-implement cipher suites in TLS.
> >
> > Thanks,
> > Sean & Joe
> >
> > [0] Link to I-D:
> https://datatracker.ietf.org/doc/draft-kwiatkowski-tls-ecdhe-mlkem/
> > [1] Link to slides:
> https://datatracker.ietf.org/meeting/121/materials/slides-121-tls-post-quantum-hybrid-ecdhe-mlkem-key-agreement-for-tlsv13-00
> > [2] Link to information gather thread:
> https://mailarchive.ietf.org/arch/msg/tls/yGZV5dBTcxHJhG-JtfaP6beTd68/
> > _______________________________________________
> > TLS mailing list -- tls@ietf.org
> > To unsubscribe send an email to tls-leave@ietf.org
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>

-- 
This electronic communication and the information and any files transmitted 
with it, or attached to it, are confidential and are intended solely for 
the use of the individual or entity to whom it is addressed and may contain 
information that is confidential, legally privileged, protected by privacy 
laws, or otherwise restricted from disclosure to anyone else. If you are 
not the intended recipient or the person responsible for delivering the 
e-mail to the intended recipient, you are hereby notified that any use, 
copying, distributing, dissemination, forwarding, printing, or copying of 
this e-mail is strictly prohibited. If you received this e-mail in error, 
please return the e-mail to the sender, delete it from your computer, and 
destroy any printed copy of it.