[TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3

Kris Kwiatkowski <kris@amongbytes.com> Fri, 10 October 2025 09:50 UTC

Return-Path: <kris@amongbytes.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 024647091347 for <tls@mail2.ietf.org>; Fri, 10 Oct 2025 02:50:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=amongbytes.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ohho0uGXUyxE for <tls@mail2.ietf.org>; Fri, 10 Oct 2025 02:50:23 -0700 (PDT)
Received: from 2.mo580.mail-out.ovh.net (2.mo580.mail-out.ovh.net [178.33.255.145]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 41D927091335 for <tls@ietf.org>; Fri, 10 Oct 2025 02:50:22 -0700 (PDT)
Received: from mxplan8.mail.ovh.net (unknown [10.110.37.210]) by mo580.mail-out.ovh.net (Postfix) with ESMTPS id 4cjhn311Kfz5wj8; Fri, 10 Oct 2025 09:50:15 +0000 (UTC)
Received: from amongbytes.com (37.59.142.108) by mxplan8.mail.ovh.net (172.16.2.82) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.1.2507.59; Fri, 10 Oct 2025 11:50:14 +0200
Authentication-Results: garm.ovh; auth=pass (GARM-108S0021af04454-05da-4a00-93b8-160247c5475d, 74D9401547C7F04CD6AEBC49B119D12EDAA5279F) smtp.auth=kris@amongbytes.com
X-OVh-ClientIp: 88.97.253.244
Content-Type: multipart/alternative; boundary="------------Oc1I8RtZAKNTuSmgMMsaTD8D"
Message-ID: <e00950bf-1ce3-494b-a3be-f2ca2ac0d481@amongbytes.com>
Date: Fri, 10 Oct 2025 10:50:13 +0100
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>
References: <CAOgPGoA+c8kXDizwsvFG5tLz9+Kxk0HqiN1skKp5jMvvpxeu0Q@mail.gmail.com> <CABcZeBO+3u=1=ueNscq+O74Qv=7PC5NedsGsugp=GZjVqtODoQ@mail.gmail.com> <1040fcc9-46e3-197e-1fa7-353c978486fb@nohats.ca> <CABcZeBMZ=0ByGpDzHsfq2m3wO9NhpEoFX+2k0_8NhTiAYekqBw@mail.gmail.com> <aOimWoGkK3_dGOSF@chardros.imrryr.org> <1d14a4f9-ab5c-471f-88cf-e3ca963d7f9e@amongbytes.com> <CAMjbhoVG=Rvm2tMHmXCfmrn4=hj2aiKb_w7VYAbG5THcvs++eQ@mail.gmail.com>
Content-Language: en-GB
From: Kris Kwiatkowski <kris@amongbytes.com>
In-Reply-To: <CAMjbhoVG=Rvm2tMHmXCfmrn4=hj2aiKb_w7VYAbG5THcvs++eQ@mail.gmail.com>
X-Ovh-Tracer-GUID: 6583917d-ac5e-44a3-bb88-dcdd60a3bb83
X-Ovh-Tracer-Id: 15480842246466224026
X-VR-SPAMSTATE: OK
X-VR-SPAMSCORE: 0
X-VR-SPAMCAUSE: dmFkZTFujKvWdg2+MBcJtdckJR9mDqXtRSfEX4i8BFK7yy/bIYRSR31h+4GPh5JrzL5QihC6LhLAtvmak/DxUCVWxdsgxsM7Q+1zIRwSuu+9HMaLiXBLYWVRUsMlkLOPbLHcF41FIG8WYaqr/8AnqB8biGda9+qvVqST2taeu5HXgGs0nR0Q8RS/JjWhLahUqBUugAQ0sc/OmUBOQkb3DqtyOYokWx7UZuBSXqwoaYRstgvkjoirr3eucK6gCPMOrtfN0x6WRGerJiuFdRkP62FJMfXK+DzSHUET6NieeiMpggblpWqbSFHc28v63hoGJcH74AAdAlXEX2PLqQmkE4zeGXr+kwflLiXL6eHUHjCnAsJKhEcVjkO2ptesAIzFok1wzFpvNa+aafVSJze42wK+ZfLxvofBzrCCLSpmRuHz+mSdcUwvgTA0YaisAxsD4ppihQ6g04loWY+0c4lIDaGA7WA3R2G6uSIPp9JZqhu+NWnMau33sSkhdhCLxh1OuyDfQtQ+HGRWjzRIno6u6t239Y71TEOTn5J5y37o0cU4ZXtIL/UHxVQ3unXPKVXJxq7xxxuf8Blw7e9gJAMexAg6/ISCnOP55uR5uCTuxLccxF8Tk5aQ/SCB95rMLCt1HpdNsFdZOkwRdNPFLG9Zr8OHTDpxZ+kM04iHlT0m5se+PNFglg
DKIM-Signature: a=rsa-sha256; bh=fxEhsQVFjFpWAoPEDHtutucnLoRInYh/CP245Le2M0M=; c=relaxed/relaxed; d=amongbytes.com; h=From; s=ovhmo2671616-selector1; t=1760089815; v=1; b=IFY6vp8bLIV+wJqhS+iglnySwgEyPRg9P6ajCg5X1OujqI7YB94pszr0gomaA/D006mubib1 n6hRPB5qr0ni0q370PbmWa+zXy9euoA4w5pno4khYBuLKb+vfOwMEf4mGsUNkGwmwoMIhjVOfzk KodDyxJeszirHiZcVuR14rDYSqyPpIDJ+c3Qwo5OjOu4pVGvHdxX9p8vJs9b2bqj3PkENgFETFp PMSQvItDJSIC6JGS4fJqpG5cBpmhaKb2TRaLOZk0w6trrB/O0kj8FlfJZEoOYCp1z1c8Pa4moKy WgiKUJ4fyT+ipCIYB2JAKLv20CmeCEFHfKHhzrX+dUTHw==
Message-ID-Hash: NZY3S7RU4EYQLLD5KPFP2ZYT333KJHVF
X-Message-ID-Hash: NZY3S7RU4EYQLLD5KPFP2ZYT333KJHVF
X-MailFrom: kris@amongbytes.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/xb9-wMHxvHHWUZ3-hGLe5uVKhfE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I also see no reason to delay this document.

Additional code points can always be added later, either through an update or 
a separate draft. Discussion about those new code points may take several more 
months anyway. Meanwhile, the minimal set proposed here has already been 
discussed for some time and should serve well as a starting point.

On 10/10/2025 10:31, Bas Westerbaan wrote:
> Setting aside the question of use cases for a moment, let me note that no 
> one even bothered to ask IANA to assign codepoints for any hybrid not 
> already listed in this I-D. I see no reason to hold up this document now: we 
> can always publish a follow-up later on.