[TLS] Re: PQ Cipher Suite I-Ds: adopt or not?

Rob Sayre <sayrer@gmail.com> Mon, 23 December 2024 21:26 UTC

Return-Path: <sayrer@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1FC0EC15153F for <tls@ietfa.amsl.com>; Mon, 23 Dec 2024 13:26:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, T_SPF_HELO_TEMPERROR=0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KPHhV97cn_-J for <tls@ietfa.amsl.com>; Mon, 23 Dec 2024 13:26:40 -0800 (PST)
Received: from mail-pj1-x1036.google.com (mail-pj1-x1036.google.com [IPv6:2607:f8b0:4864:20::1036]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CA5D2C14CE29 for <tls@ietf.org>; Mon, 23 Dec 2024 13:26:40 -0800 (PST)
Received: by mail-pj1-x1036.google.com with SMTP id 98e67ed59e1d1-2f43da61ba9so3783899a91.2 for <tls@ietf.org>; Mon, 23 Dec 2024 13:26:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1734989195; x=1735593995; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=m3GAFBafJG02Yq1/F/hjfp254fPU0GzU4DEDW4iOV14=; b=nAuPVbvc/zuLZkhX5eEkZxH/aw3WDTZhjwRdAW/eS4s17j2aqqgnLhPIPlwt+ylNj5 1TfxVqlHNgGyS/8OCIfJD9dlJn+Rs1vmmfSvwH7oD97aWyB1cw63Cr0ZPImGMs8qmAvk 4+8HGDd393hB6cBOsufF7yXSq0Jl5VzH9HmIHWQgCGgsCsDs/tKCxv3GvEdTLE5KT421 Did+jk0ifQ+meldgiA3KFqxKEhT2RN4/Oqz9Wj8nYxh8iPrciNP09DsHK/fsUn10aKEO 1JvXxGcUwYGAF9KLdYHvVFWTNmg57hU7MGpf3svxKxOzeLiCnmkxcubHx5zwv/rpB8An lwxA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1734989195; x=1735593995; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=m3GAFBafJG02Yq1/F/hjfp254fPU0GzU4DEDW4iOV14=; b=mfRMzGIllhmiz4PyhiDaH94XbXSfjeSVKDBRh0KByBfv1UPZ0I1o2H+IGAkQYmHf7d F3fnwb/xnRluQWIJPSqLb/B9pdFN5XfHNqqVFEJUt8hFl9KfERgRxBI6l9yR+bSwcJP1 5JzeoPUQdjioe20ahMyz2juIku8lZ3NHwQNfnA/YJmAqGKRouWxhctWCIuGlGdF4eoEC DAQo3N9Y6xXphXLxd7YbUV9BTWl0+PmRHQVH0xEgFM24dSGEgL0v9fbO20QZ/Urtttqx dLatcmVo2okmzzdZdJGC0uHGKQtYvGAZ8bQlpkLKP9oAWt3dUG5x8tdA7r+nU/ORo70S izVw==
X-Forwarded-Encrypted: i=1; AJvYcCUbIsIuzeie5WspYkvPytHeiQv/U2l63/reLRqAlX600ujzFzDqPW53cAjIlVegUFKv4jI=@ietf.org
X-Gm-Message-State: AOJu0Ywk2k9PSwAKPBivEzonQhmypKmMEAA07Vent7bNNQO9XSgD2GgR Htig76ZErtMh2B8V0IqB4dFxiwHNAKeOlaec5qwsrOLnJz2WU6ArPZX3Q9yOny+X0eUskKoCBCV PTkcPgJcc+oZuYN9mPyxF2+QbAHA=
X-Gm-Gg: ASbGncvJ1RjUT3I0FivQKvPWnW2GF9ey/giZCIL/fBS8zTFIwM85Etg6wMf7krw1h/V LUtIxXNpwR2R50KdkKM4S9yn9TVPx0ALB1wQjAehxSQp8YzKLKAuL
X-Google-Smtp-Source: AGHT+IEbBJvAtibFaCiGXVWdeiD2ziXH2moDxvIJm/7Rx/dEj7jZqm5IGJfJlWrim5519GtqHHg9Km2EwHtJ47uBpJQ=
X-Received: by 2002:a17:90b:544b:b0:2ee:c9d8:d01a with SMTP id 98e67ed59e1d1-2f452e1e54fmr20530458a91.11.1734989194905; Mon, 23 Dec 2024 13:26:34 -0800 (PST)
MIME-Version: 1.0
References: <10A06A24-8126-47B9-B187-55F4288DBBF2@sn3rd.com> <ea32ebd6-e57d-4da6-9250-a3e4d75d11a0@betaapp.fastmail.com> <CAChr6SzmGOpKws0L=BQAiNXvx3wv7OOoWTi6A30BQ0mXd+kjrg@mail.gmail.com> <CAOp4FwTdWxGkLLnYq8f6a6wzoa4_9F9_su=LTFYSpMXVKBdbuw@mail.gmail.com> <GVXPR07MB96781324AB7FBB6C7C5D4BB989022@GVXPR07MB9678.eurprd07.prod.outlook.com> <CH0PR11MB544478E32D038952CBDA98C9C1022@CH0PR11MB5444.namprd11.prod.outlook.com>
In-Reply-To: <CH0PR11MB544478E32D038952CBDA98C9C1022@CH0PR11MB5444.namprd11.prod.outlook.com>
From: Rob Sayre <sayrer@gmail.com>
Date: Mon, 23 Dec 2024 13:26:23 -0800
Message-ID: <CAChr6SxxDv-4Zoh5NVawrUt8eQ4mVmMUSWmZQJ_Mpj3wncsYqA@mail.gmail.com>
To: "Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com>
Content-Type: multipart/alternative; boundary="000000000000a6d2fc0629f6a665"
Message-ID-Hash: 5R6JQR3DXQY7BYSBQVLZIXCQE6IYT4CH
X-Message-ID-Hash: 5R6JQR3DXQY7BYSBQVLZIXCQE6IYT4CH
X-MailFrom: sayrer@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: PQ Cipher Suite I-Ds: adopt or not?
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/uj6U0AJaQ6rpiYah6LTNnB_HD7s>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hi all, since I am still on the CC list,

I took the question to be about how to organize the work. If everything is
a priority, there are no priorities.

That's why I want to do this one (and only this one), first:
https://datatracker.ietf.org/doc/draft-kwiatkowski-tls-ecdhe-mlkem/

Some of the other ones look like they could benefit from waiting, in the
sense that contentious points might resolve themselves over time.

thanks,
Rob

On Mon, Dec 23, 2024 at 11:00 AM Scott Fluhrer (sfluhrer) <
sfluhrer@cisco.com> wrote:

> TL;DR: Historical notes: not important for the current discussion.
>
>
>
> To be clear about whether Cisco (or actually, me – I don’t actually speak
> for Cisco, but I like to think they listen to my advice) preferred NTRU or
> NTRU Prime – I actually didn’t have a strong opinion.  I advocated NTRU
> because it made it to round 3 (rather than stopping at round 2 as NTRUPrime
> did), and so it appeared to be a bit more mature (that is, having more
> cryptanalysis).  If there was a general consensus towards NTRU Prime, we
> would have happily gone along.
>
>
>
> Other than that, John summarized the situation well – Cisco (or actually,
> Cisco’s lawyers) are happy with how the IPR issues around ML-KEM were
> resolved and are going forward with that (with both pure and hybrid).
>
>
>
> *From:* John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>
> *Sent:* Monday, December 23, 2024 9:02 AM
> *To:* Loganaden Velvindron <loganaden@gmail.com>; Rob Sayre <
> sayrer@gmail.com>
> *Cc:* TLS List <tls@ietf.org>
> *Subject:* [TLS] Re: PQ Cipher Suite I-Ds: adopt or not?
>
>
>
> The thread starts with “Due to this, Cisco has preliminarily considered
> Kyber unusable”
>
> This is obviously not true anymore as Scott very clearly stated that Cisco
> wants to see both hybrid and non-hybrid ML-KEM standardized, and that they
> want to implement and ship both. I agree with Scott. Also, I think Cisco
> was quite clear on that if the IPR uncertainties regarding ML-KEM was not
> addresses, which they were, they wanted NTRU, not NTRU Prime
> https://datatracker.ietf.org/doc/html/draft-fluhrer-cfrg-ntru-01
>
> Mozilla is obviously shipping ML-KEM in Firefox. I am an avid user of
> Firefox, and I am happy to see X25519MLKEM768 on more and more webpages.
>
> Cheers,
> John
>
>
>
> *From: *Loganaden Velvindron <loganaden@gmail.com>
> *Date: *Monday, 23 December 2024 at 02:56
> *To: *Rob Sayre <sayrer@gmail.com>
> *Cc: *TLS List <tls@ietf.org>
> *Subject: *[TLS] Re: PQ Cipher Suite I-Ds: adopt or not?
>
> If there are some patent concerns regarding ML-KEM going forward, Would
> considering NTRU-Prime as a less risky option for TLS Kex?
>
> (Please see this thread:
>
> https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdiscourse.mozilla.org%2Ft%2Fpatent-license-for-kyber%2F128114&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7Cb49fe1a69fb24e159b5808dd22f5004a%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C638705157893766686%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Fi1LM1Q49lgZfAwBOQf5HhvEXZccY%2Bjk9VXHg6yHEaU%3D&reserved=0)
> <https://discourse.mozilla.org/t/patent-license-for-kyber/128114>
>
> There is a section about patents here:
> https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fntruprime.cr.yp.to%2Fwarnings.html&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7Cb49fe1a69fb24e159b5808dd22f5004a%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C638705157893782148%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=T%2B2Ggx2ZxAV%2BCwqSvtrUlptlGHO9iYCFpCYf4Cq3xlA%3D&reserved=0
> <https://ntruprime.cr.yp.to/warnings.html>
>
>
> On Tue, 17 Dec 2024 at 02:53, Rob Sayre <sayrer@gmail.com> wrote:
> >
> > Hi,
> >
> > I only support an adoption call for this one:
> >
> >
> https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-kwiatkowski-tls-ecdhe-mlkem%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7Cb49fe1a69fb24e159b5808dd22f5004a%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C638705157893792936%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=D3lsZ10f5cHom9RHdadaPqHt0bSWb6Q6Cz53MBbq1PM%3D&reserved=0
> <https://datatracker.ietf.org/doc/draft-kwiatkowski-tls-ecdhe-mlkem/>
> >
> > The other ones seem like they could wait, carefully noting that
> postponement is not a "no" vote.
> >
> > thanks,
> > Rob
> >
> >
> >
> >
> > On Mon, Dec 16, 2024 at 2:21 PM Martin Thomson <mt@lowentropy.net>
> wrote:
> >>
> >> On Tue, Dec 17, 2024, at 08:59, Sean Turner wrote:
> >> > Is the WG consensus to run four separate adoption calls for the
> >> > individual I-Ds in question?
> >>
> >> I would like to see adoption calls for the key exchange modes and not
> the signature modes.  The key exchange documents are both more ready and
> more urgent.
> >>
> >> The question of whether to set Recommended = Y for any particular
> choice is separable and can wait.  Keep things as Recommended = N for now.
> >>
> >> _______________________________________________
> >> TLS mailing list -- tls@ietf.org
> >> To unsubscribe send an email to tls-leave@ietf.org
> >
> > _______________________________________________
> > TLS mailing list -- tls@ietf.org
> > To unsubscribe send an email to tls-leave@ietf.org
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>