[TLS] Re: [External] WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Deirdre Connolly <durumcrustulum@gmail.com> Wed, 24 June 2026 17:28 UTC

Return-Path: <neried7@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7B690106A72B4 for <tls@mail2.ietf.org>; Wed, 24 Jun 2026 10:28:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782322106; bh=ZTmKrApCuA5sL8hv/Mwlc8wQ32vQejTdGwhF/sKb8eA=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=VBr6wEESWuwzI+/le6aGMy5PFwteLVIyNBqZ5ymEAM6ekvfgIPnfOCOor19jTobia WWg9x/k4g7PnTzokjN0CFG+GhyyuL5BNfze15Sy25gmSKvdD0LrMOA4eNgSL1Fov+4 rgWZye+ySzm3a8uXRhLWdUkBg6q4L0awYUwbCxq8=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.848
X-Spam-Level:
X-Spam-Status: No, score=-0.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KLjOS8xtQ2NV for <tls@mail2.ietf.org>; Wed, 24 Jun 2026 10:28:25 -0700 (PDT)
Received: from mail-lj1-x232.google.com (mail-lj1-x232.google.com [IPv6:2a00:1450:4864:20::232]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 22066106A724F for <tls@ietf.org>; Wed, 24 Jun 2026 10:28:16 -0700 (PDT)
Received: by mail-lj1-x232.google.com with SMTP id 38308e7fff4ca-396771119c4so12183461fa.0 for <tls@ietf.org>; Wed, 24 Jun 2026 10:28:16 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1782322095; cv=none; d=google.com; s=arc-20240605; b=Dt/Wd8egKKhNi1oB3v4eGv3irTGt21Cwb/y7XyF7l0TU5Fw9YYM00iwffS2ucXfYKq zCg9Vk7Qk38bcT4hyU58e6lUbjoRWWF1N9W4l+hlPFQZDmCGHidmg8Z5C++lqaKyr90N tFuH9tckMlAQefdlCMlQhk8JVU0AbjAtcIj1NgqRy6607JiqWzBtK93OF18X2jwjhh99 NqMmfnv4VjkwLlrFtca1o+vMnP9miBzX/yoEfwJ7Hc4F/rUOB8v4gGH8bRSbnILXyxJ3 eFPI0Wq9Tsc6XV3ZYA31Xq6UYc/ZhvHKrmRRophjM0FDAIOt7XTf2HXzBWQi0jyf0F9G CigQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=8s6QTeuEIc0O/5lf7X/yTEEcN1mQ/2A/1zQ6rLmjK/Q=; fh=R/xIhrK/GCzA/sohP+Vu4x9XANk7zG5SgmAqx03LeVw=; b=HC6K5I97SrYgAP0q+2QY4DRdbZV2CRZPFxrSx51mQVUIzNmsCgz39P9vhXNKz5GgkE 2bZWwDVm2/7fHeCt53QF6YlOCvZSeRO5uBIOcOCS7a7oAILRD3ncHuF/Y/fJXEJILHnO XxH2pwToPWKM85k/nFUjZOrE117MK1ZrEEN1V8ppC115AmdNKSzhfBgbH8mDAwIH/BiJ cSGAJEV6nL9j2rMooQTe8OT0VbalsGgsw+3of47Eult2eRFtVVYBXUj9+ab6LjaM0yHX TB4wJjNcel6Wjj/Q51JrsDeYD/pLV5MxpeS0wH/+EKsXlyQfqWzzERc1rQZYZbS2wzcO zhEA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782322095; x=1782926895; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=8s6QTeuEIc0O/5lf7X/yTEEcN1mQ/2A/1zQ6rLmjK/Q=; b=sF4ISP6kuZmWC8KN0Zwky94YdwA8fLRrm96X7ujTh9qPvkrm+cNplVLm5pqmlS6Rex v4sA4LvmN5USvjHd+JBfou0yTHP5v2H/Pu4nk3MAnM9VGDXF7rz5vdi7ZSFV5CjHXsSA UDF1ypFSB3kE2EKrBwe5KA3x+6ZGDDrkzIL/51tFKuwBNl/F3DRWHMvhA+s8T4WPnxRQ cgWb5UT4E9Wgs2TMW/aa5vSvyShE3dCc8uJ2dw+DQSI4/75Mwr11pSSG0wW8bpYm5e7f bXtO2bQVXdUXqxRN0KpgmoFabK/rBNARhvLLAhywyY2E5TjEBvN8cyc+g9tKBVwR+AD6 6Zcg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782322095; x=1782926895; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=8s6QTeuEIc0O/5lf7X/yTEEcN1mQ/2A/1zQ6rLmjK/Q=; b=XYY/O9+ZfjwdxMub5K1cxkgI09h2vAzPbjUeNYdX2fLsgArSkWJZwjxHWTT63YaRkB t2TNmIBQEKV7RCTo4o5pIuC7TgdWfiYR40Eifqo/12k1mhtwmvwg3l82fz5xmuFRleX5 ciP8oZqib21I7xWKLUYjTrfvPogOe28RVB0cBZFXtWpu20CPT/folpjCGVzSgkFT/8Ct I5XKp2kZmiRdxIy3xIDLcOvr+9utEHvYNCHjTMuJ7OtPQAWbZxA3OttbefpOOumCP/e0 9vtWLHASWa1EbeQg7S7nRbcpNxJxPF8jx1vVCJM0LvJgbiawv1TD42rxL/ogi813Xbcc pQ3A==
X-Forwarded-Encrypted: i=1; AHgh+RrYHDX8ttfZhtfQVcykN+eKaH0+VPnhhviuvQkWGUD+G9VHlq7dzxKNuv2IQcENnzM2CFc=@ietf.org
X-Gm-Message-State: AOJu0YzhUX7TlDiCUC+us2/KgeiIgbVFqGs+2Gg68IyVCl4VZNKDTNlH NgnlVN9xGUy/KsmOPFi7WnXisUWCij8CLdLD4mQnx68/MK2Jr6Y09cUeEyQYzHkhxPso8FdjRrS VBvrfnEygnhWoF0GHR+WJjULJVbGwc69fCLKx/3wc2w==
X-Gm-Gg: AfdE7cnkVyryyHktsEcRJHwAEdxVjjNqTJwRaeqUNI1i235Q6Nvycbb3BozG4KJvuOe GLWuvbHOVBEXkYffdTW1EXpvoy6lOSssRX+zLxMqcLkEYJLCcOyne39sphvaJ0uaWLl6BOhzTaT 5J9w9wfNKHLVc9Z++JaaT02/ZfFW9X0vC2VZAoofys0XH6FNYEKxc6cUiLfmKCa4oFIJg0Lqb5r 7SSfOMFtmwq1LYm2vISZf1NDjxu1wVPZNIWcaZkHQpvaneen3Qe9J7tcZj/nmikZA4klIYKDdVF S6az0wex22BuZfWWdNIOxw/jy1+c2Q==
X-Received: by 2002:a2e:be21:0:b0:396:6bd5:a9c6 with SMTP id 38308e7fff4ca-39a27e6ca31mr22697571fa.14.1782322093509; Wed, 24 Jun 2026 10:28:13 -0700 (PDT)
MIME-Version: 1.0
References: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg> <DS2P114MB2451A4F9F6025169C43D94BDE6ED2@DS2P114MB2451.NAMP114.PROD.OUTLOOK.COM>
In-Reply-To: <DS2P114MB2451A4F9F6025169C43D94BDE6ED2@DS2P114MB2451.NAMP114.PROD.OUTLOOK.COM>
From: Deirdre Connolly <durumcrustulum@gmail.com>
Date: Wed, 24 Jun 2026 13:27:37 -0400
X-Gm-Features: AVVi8CfMPgjbR2UnLaYbqWiXKrLWS3jcquvTZ_HjDbRd9O0LYuO_1j3PtREuOLs
Message-ID: <CAFR824yGd7OHa_Dz8sMOyJ7q5cnyzP+t1yVrf9zawrBKGYifCg@mail.gmail.com>
To: "Schäfer, Pascal" <pascal.schaefer@accenture.com>
Content-Type: multipart/alternative; boundary="00000000000042502a065503339e"
Message-ID-Hash: F7IMBNJE5LSGQX5OWI3NPONJUCB4724B
X-Message-ID-Hash: F7IMBNJE5LSGQX5OWI3NPONJUCB4724B
X-MailFrom: neried7@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "draft-ietf-tls-mlkem@ietf.org" <draft-ietf-tls-mlkem@ietf.org>, "tls-chairs@ietf.org" <tls-chairs@ietf.org>, "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [External] WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/sX-5gPh_d2UdDDZBSONSn8WrG3M>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

> I saw an "and and", which should probably just an "and".

Fixed:
https://github.com/tlswg/draft-ietf-tls-mlkem/commit/7d823d27ef341ee79af3a910e5327ef8ebcfad61

On Wed, Jun 24, 2026 at 12:04 PM Schäfer, Pascal <
pascal.schaefer@accenture.com> wrote:

> I support the publication of this document.
>
> Only one editorial comment beside of the other mentioned editorial
> comments:
> In the abstract I saw an "and and", which should probably just an "and".
>
>
> -----Original Message-----
> From: Joseph Salowey via Datatracker <noreply@ietf.org>
> Sent: Mittwoch, 24. Juni 2026 17:00
> To: draft-ietf-tls-mlkem@ietf.org; tls-chairs@ietf.org; tls@ietf.org
> Subject: [External] [TLS] WG Last Call: draft-ietf-tls-mlkem-08 (Ends
> 2026-07-08)
>
> WARNING: External email. Be vigilant with links, attachments, and requests.
>
> This message initiates a new Working Group Last Call for
> draft-ietf-tls-mlkem[1], which defines standalone ML-KEM key establishment
> for TLS 1.3. The main question before the working group is: "Should the
> working group publish a document specifying stand alone ML-KEM?". If there
> is rough consensus then we will push to refine and publish the document;
> otherwise, we will stop discussing the draft and not progress it. Please
> respond to this call indicating whether you support publishing a document
> specifying a stand alone ML-KEM. Please refrain from further discussion on
> this topic as most arguments have been discussed multiple times.
>
> Why are we holding this consensus call now?
>
> Significant developments have occurred both within this document and in
> the broader TLS ecosystem to address the concerns raised in the last WGLC.
> Therefore, the third consensus call is warranted. We ask the working group
> to consider document publication in light of these recent changes:
>
> - Promotion of Hybrids in draft-ietf-tls-ecdhe-mlkem: Following a separate
> consensus call, the WG agreed to promote the X25519MLKEM768 hybrid group to
> Recommended: Y in the IANA registry. Consequently, the IANA registry will
> reflect a clear community preference for a hybrid because Recommended: Y
> clearly indicates this while the standalone ML-KEM groups defined in this
> draft remain Recommended: N. The updated security considerations in [1]
> reference the IANA registry to emphasize this preference.
>
> - Key Share Reuse Prohibited in draft-ietf-tls-rfc8446bis: The WG recently
> reached consensus to explicitly prohibit key share reuse across connections
> in TLS 1.3. The new text changes the guidance from SHOULD NOT to a strict
> MUST NOT. This resolves the concerns regarding static key reuse and its
> associated privacy and forward-secrecy risks for ML-KEM.
>
> - Nadim updated the ProVerif model of TLS 1.3 to evaluate KEM and hybrid
> KEM groups in TLS 1.3. This supports other results which show that KEMs are
> secure when used in TLS 1.3 and that hybrid groups are secure even if one
> of the components is compromised.
>
> - Liaisons: We received liaison statements from multiple SDOs including
> O-RAN[2], IEEE 802.11[4] and from 3GPP[3]  expressing support for the
> publication of draft-ietf-tls-mlkem as an RFC as they rely on the IETF to
> provide a stable normative reference.
>
> Please note that a third-party IPR disclosure exists [5] against this
> document regarding patents related to the underlying ML-KEM algorithm. This
> IPR declaration has not changed since the last WGLC. As a reminder, per BCP
> 79, the IETF takes no stance on the validity of patent claims, and the
> working group may decide to proceed with a technology despite IPR
> disclosures if it decides that such use is warranted.
>
> Conduct Reminder: Given the heated nature of previous discussions on this
> topic, participants are strongly reminded to adhere to the IETF Code of
> Conduct (BCP 54) and the TLS WG's Mail List Procedures. Keep feedback
> professional, technical, and focused on the document's text.
>
> This working group last call will end on 2026-07-08.
>
> Joe and Sean
>
> [1]
> https://urldefense.com/v3/__https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7Xp19ojzQ$
> [2]
> https://urldefense.com/v3/__https://datatracker.ietf.org/liaison/2198/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7UVzVFYJQ$
> [3]
> https://urldefense.com/v3/__https://datatracker.ietf.org/liaison/2151/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7V-27j4vg$
> [4]
> https://urldefense.com/v3/__https://datatracker.ietf.org/liaison/2148/__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7VaUHPDRw$
> [5]
> https://urldefense.com/v3/__https://datatracker.ietf.org/ipr/search/?submit=draft&id=draft-ietf-tls-mlkem__;!!OrxsNty6D4my!6IJnS7RUmoEUptkioAYza6Ne1ruwc-jgBR1Opv9lUfXct3Vb7BGgc4NmlSdoEg7PhZRHWLPUQGPQD7XeMmnQZw$
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>
> ________________________________
>
> This message is for the designated recipient only and may contain
> privileged, proprietary, or otherwise confidential information. If you have
> received it in error, please notify the sender immediately and delete the
> original. Any other use of the e-mail by you is prohibited. Where allowed
> by local law, electronic communications with Accenture and its affiliates,
> including e-mail and instant messaging (including content), may be scanned
> by our systems for the purposes of information security, AI-powered support
> capabilities, and assessment of internal compliance with Accenture policy.
> Your privacy is important to us. Accenture uses your personal data only in
> compliance with data protection laws. For further information on how
> Accenture processes your personal data, please see our privacy statement at
> https://www.accenture.com/us-en/privacy-policy.
>
> ______________________________________________________________________________________
>
> www.accenture.com
>