[TLS] Re: [EXT] Re: ML-DSA in TLS
Andrey Jivsov <crypto@brainhub.org> Sat, 16 November 2024 04:52 UTC
Return-Path: <brainhubr@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 609E6C151088 for <tls@ietfa.amsl.com>; Fri, 15 Nov 2024 20:52:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.655
X-Spam-Level:
X-Spam-Status: No, score=-1.655 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id okovG13PfpEi for <tls@ietfa.amsl.com>; Fri, 15 Nov 2024 20:52:48 -0800 (PST)
Received: from mail-qv1-f52.google.com (mail-qv1-f52.google.com [209.85.219.52]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E1562C151083 for <tls@ietf.org>; Fri, 15 Nov 2024 20:52:48 -0800 (PST)
Received: by mail-qv1-f52.google.com with SMTP id 6a1803df08f44-6d3e9e854b8so22276816d6.1 for <tls@ietf.org>; Fri, 15 Nov 2024 20:52:48 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1731732768; x=1732337568; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=11qdK/K4voOQwXpirKuWZZO5EHV5CXkd2jOXbO8m/fE=; b=s6Qx/dbWUNYdyegqoF7qH7tC1U8VArg+TxjQXe16gsPz9r6jqjvoUQzjiS3FyFRDM/ fHPSMjdWKTGpMMndqiF/CckKAcNhX/q0lrthwmtd8kbRPfi7dxz7YTtAhpU3S1rOQduL jfNmhmhhQyvx9O7iBJsO7FdBUZLhuFtaHh91HxJnHCapiIljTDTExN82/wLdlR4jluLE /epqISZJp+RWUNYlD8qeH7l99jwcOhB71ZHdbGbRe6H3zLZsThvAELIDg5AdHcLKCAGr Si5i5joyUETSSp67VgCYiRifJX/UudjKd9D3d0mI0dfiubRUSSsu4lkj4fSUpo1n77/c yv+Q==
X-Forwarded-Encrypted: i=1; AJvYcCVoA5LKJEb7MqPh/FnzPo+jYDZmp8NW3Y1PHJZQzIOCpuMWrR3w6cxGcFh/w7eKpFWGP8Q=@ietf.org
X-Gm-Message-State: AOJu0YwELph3sUOxklWOB+DgKOmdLGMtcMvIsBPCsgdb9StDCWoQu9yH BkTzxf/V4zFNLMT+0WkOyxDkE2InxcOdn+2D2PTGtoifOGqWuEAZ1wKnZg==
X-Google-Smtp-Source: AGHT+IE2nbMnaEWfJTiHd+9B8kOBVb+E1FgZpFQYMzrjsHI/zFSAYH/kKursXf1V40CMFpterj7FkA==
X-Received: by 2002:a05:6214:4890:b0:6d1:7455:9b0d with SMTP id 6a1803df08f44-6d3fac7ab52mr88882096d6.16.1731732767861; Fri, 15 Nov 2024 20:52:47 -0800 (PST)
Received: from mail-qk1-f176.google.com (mail-qk1-f176.google.com. [209.85.222.176]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-6d40dc48b9asm4671496d6.65.2024.11.15.20.52.47 for <tls@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 15 Nov 2024 20:52:47 -0800 (PST)
Received: by mail-qk1-f176.google.com with SMTP id af79cd13be357-7b35b1ca0c2so257314385a.0 for <tls@ietf.org>; Fri, 15 Nov 2024 20:52:47 -0800 (PST)
X-Forwarded-Encrypted: i=1; AJvYcCWs+pnMUMZlNU/prkZQcmUGyhFuS+1/LhoQs3l1lRzc8TveTOjl4WDU28KWqMjn/VbCLPI=@ietf.org
X-Received: by 2002:a05:620a:284a:b0:7b1:44ee:644d with SMTP id af79cd13be357-7b35a4930c2mr1507095685a.10.1731732767347; Fri, 15 Nov 2024 20:52:47 -0800 (PST)
MIME-Version: 1.0
References: <CAMjbhoUFkL=UT0Pt2xjPLm998=j1ef+wdm0WO14_W7OJDJ-hOg@mail.gmail.com> <CAMjbhoWY+1Km_=+PbXfEjab02AfWpbd4WwKwuBN_5KZZpCkXZg@mail.gmail.com> <bd714bdc-5bf9-47a6-8e66-b2e4624c9df0@cs.tcd.ie> <GVXPR07MB9678722E47C82B14B0F296F389242@GVXPR07MB9678.eurprd07.prod.outlook.com> <CAAWw3Rh-2A1zuEWOLuoaQ5DMcDGb_oQXRc8ZNYNVoO8KDsqzTA@mail.gmail.com> <e855562b-2bce-4bd4-ab58-074550c34475@redhat.com> <CAAWw3Rj7L8v9OOJtGHMvCXRtcHYAMU3TLPJ_etf8EP8MSiSHGQ@mail.gmail.com> <BN0P110MB141974314450179F48B424D99024A@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM> <CAAWw3Rgy7qonCMqKmYiCQZi3RCq=t4J94NA817ONYGOTwP3FDw@mail.gmail.com> <CACsn0c=8J4S00mzOWpHgKSudnpp=zzRjGmVQ5tRNTOnN5ekWfw@mail.gmail.com> <CAAWw3RjCk1hhjapG5r6F0NEo83G=XzyNuscSrzJMeefuZm_cJA@mail.gmail.com> <CACsn0ckf57w-6xg+-d2WrvoY-RGM+BQbZFP-fo=OTC11kNdRYQ@mail.gmail.com>
In-Reply-To: <CACsn0ckf57w-6xg+-d2WrvoY-RGM+BQbZFP-fo=OTC11kNdRYQ@mail.gmail.com>
From: Andrey Jivsov <crypto@brainhub.org>
Date: Fri, 15 Nov 2024 20:52:36 -0800
X-Gmail-Original-Message-ID: <CAAWw3Rg9YW5=Gd3E-XvthsU6-N=zx_N0Ss2uZsaVcB5c8HoQFA@mail.gmail.com>
Message-ID: <CAAWw3Rg9YW5=Gd3E-XvthsU6-N=zx_N0Ss2uZsaVcB5c8HoQFA@mail.gmail.com>
To: Watson Ladd <watsonbladd@gmail.com>
Content-Type: multipart/alternative; boundary="00000000000071a1fa06270074c0"
Message-ID-Hash: WNZXC542FXYFE2W4IXKKFOV65CPXTI4M
X-Message-ID-Hash: WNZXC542FXYFE2W4IXKKFOV65CPXTI4M
X-MailFrom: brainhubr@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>, TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [EXT] Re: ML-DSA in TLS
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/rsvfZclVhBNxZZNmuSpaCQ9PCko>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Fri, Nov 15, 2024 at 3:56 PM Watson Ladd <watsonbladd@gmail.com> wrote: > ... > Why not hash based signatures? > I think that the stateful ones are perfectly suited for certifications in X.509 certs, but in the TLS handshake this has to be Sphincs+, at 16.2KB per signature at the AES-192 security level. In addition to size concerns, it's not allowed in CNSA 2.0. Are vendors considering SPHINCS+ for this purpose?
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Kris Kwiatkowski
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Eric Rescorla
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: ML-DSA in TLS Ilari Liusvaara
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Ilari Liusvaara
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: ML-DSA in TLS Eric Rescorla
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS Eric Rescorla
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: ML-DSA in TLS Russ Housley
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: [EXT] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: ML-DSA in TLS Santosh Chokhani
- [TLS] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: [EXT] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Stephen Farrell
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Eric Rescorla
- [TLS] Re: ML-DSA in TLS aebecke@uwe.nsa.gov
- [TLS] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Salz, Rich
- [TLS] Re: ML-DSA in TLS Salz, Rich
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS aebecke@uwe.nsa.gov
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] ML-DSA in TLS Bas Westerbaan
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS aebecke@uwe.nsa.gov
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Tim Hollebeek
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXTERNAL] Re: ML-DSA in TLS Andrei Popov
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Ilari Liusvaara
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS Rebecca Guthrie
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: ML-DSA in TLS Salz, Rich
- [TLS] Re: ML-DSA in TLS Bas Westerbaan
- [TLS] Re: [EXT] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: [EXT] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: [EXT] Re: ML-DSA in TLS Watson Ladd
- [TLS] Re: [EXT] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Deirdre Connolly
- [TLS] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS Ilari Liusvaara
- [TLS] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: [EXT] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein
- [TLS] Re: ML-DSA in TLS Alicja Kario
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS Andrey Jivsov
- [TLS] Re: [EXT] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: [EXT] Re: ML-DSA in TLS tirumal reddy
- [TLS] Re: [EXT] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: [EXT] Re: ML-DSA in TLS Scott Fluhrer (sfluhrer)
- [TLS] Re: [EXT] Re: ML-DSA in TLS John Mattsson
- [TLS] Re: [EXT] Re: ML-DSA in TLS Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: [EXT] Re: ML-DSA in TLS D. J. Bernstein