[TLS] Re: WG Adoption Call for Use of SLH-DSA in TLS 1.3
tirumal reddy <kondtir@gmail.com> Fri, 06 June 2025 11:29 UTC
Return-Path: <kondtir@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id ABA3C31BAD0C for <tls@mail2.ietf.org>; Fri, 6 Jun 2025 04:29:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.098
X-Spam-Level:
X-Spam-Status: No, score=-1.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bNsmyiP7x1_Z for <tls@mail2.ietf.org>; Fri, 6 Jun 2025 04:29:52 -0700 (PDT)
Received: from mail-ej1-x634.google.com (mail-ej1-x634.google.com [IPv6:2a00:1450:4864:20::634]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 3372331BAD03 for <tls@ietf.org>; Fri, 6 Jun 2025 04:29:52 -0700 (PDT)
Received: by mail-ej1-x634.google.com with SMTP id a640c23a62f3a-ad89f9bb725so370300966b.2 for <tls@ietf.org>; Fri, 06 Jun 2025 04:29:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1749209391; x=1749814191; darn=ietf.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=NyPoxDJKB/hIV/b5pJje9+R3629RbRuJ8ul+QO4AoRs=; b=e2UC8fYpxBQLbhTSSYWLEAWpcyiDENkV18l2Qc8vb8mDhfeWqLGZs5HpRgZsJOQ5Nk qKPLFsqfXSfyHC63DCAhRlyUVuIkCtBlHgVFzcDPw+Aqty1fhPBBC+nRqVSyUI/isdEN B3QW2sWlv+tQ9o9x2694EcNEEY4c/f7lpode7PyH/ezcJagYX3aLHmpR4xoHqwjdxw1D eiSN7EeLvIAM3nel4FyT1slz+30e/fiqGkP2sqGCmX9yQB16taRdvTFAy2mqfODHJVzC SLYZ/LnuVJMvDtoipNY/I9pFRpCfn1hj34/DrrsG6cg/2yfwJujVRnkn1dFiIJsodwB8 KTuA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1749209391; x=1749814191; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=NyPoxDJKB/hIV/b5pJje9+R3629RbRuJ8ul+QO4AoRs=; b=IYw+UdHnErq5LbvN7dFsnu/emZciILIVm7DITxhKrh4mdPiRwfuetvw/R1AaZoFyVf RngQb2rnMXA0BQQoGO/9/Me1jQICTGZ5ffMWIKEhHMehsDWOAwMxOIyTaGzJnRQPf85/ K8anvhuEFEaaCMv/3yARkqslCKTmXnyjbgSIS2vKUl10/oXyfst6z/wYllV8NRwC3r5K B0VU6qXo6lUh8ATFrPFVUHGPO3WdF1hD6CImWaQPyqhS1yaGXH5vypxCMPPU5icOZbRW dhEoBgFUP7SziMA3uFL/izIwytMPpnWyzFXuJ+QJ2WeQqd0Gn4tHs78AmrSriqPDc83Z Xpuw==
X-Forwarded-Encrypted: i=1; AJvYcCWNYxVBb8jPYZ8oK3cZ4lpHQkd2v57Ep4rSWPvrx3S3GaKFHTufFmkfvRjuX/bG418ExiI=@ietf.org
X-Gm-Message-State: AOJu0YxtoxG++T1hkImJoVynnvivm1sCxj/y3h7cM57yGDj6sFlZ4zqY 6hS16FFhRdQgzUA+XilJ0LzWDdM4ZiByJClCPdRnztiDszlXv5/NRAr+isgrLpOvIjFcKQqedgg FyyYeRhOhIEWhxsX3bm7OiAuSmlDJrbE=
X-Gm-Gg: ASbGnctPdl2CE2/0o9nENv6bYzfJqXej+w+0Vu4j4OnCBlBVR2ngJEwmiVaxT95jNGH NVsrNmwtJh0Ch2/FC9QI3ScVK7/aJv6A1IL2rI4c7sxKNzgpUyIpEvQdQibEEgQy54utdMX60Ju wqtLdLj9dautYtjei3hv12M/zi8VZDVaVhpRKhF9WMg9Y4Aw==
X-Google-Smtp-Source: AGHT+IEPXLP85b63v/e7/x7Mo09O4fzMZoFtSXmOazK9kVigGjLXYJInMHsz80fRmH0hZi4zX609HXLgiou6h4oN010=
X-Received: by 2002:a17:907:962a:b0:ad8:99e6:80bb with SMTP id a640c23a62f3a-ade1a8d9affmr269021266b.1.1749209390685; Fri, 06 Jun 2025 04:29:50 -0700 (PDT)
MIME-Version: 1.0
References: <FAA80303-6B8C-43C8-A4F3-7CBFE708EE6E@sn3rd.com> <b6b8ab20-ef35-4c26-8f9b-bf6dba388de5@betaapp.fastmail.com> <IA1PR17MB64213D1467BDB3A829BE347CCD92A@IA1PR17MB6421.namprd17.prod.outlook.com> <CAKZgXHrjQzwTCM7t7AFL4KVPkFCVN6hgDtti6ZgCR-w6yn6JHg@mail.gmail.com> <CAFpG3gcbaQ9qACC8ih7cnS146F9oShc9J2JVPixAPTrRbEVFLQ@mail.gmail.com>
In-Reply-To: <CAFpG3gcbaQ9qACC8ih7cnS146F9oShc9J2JVPixAPTrRbEVFLQ@mail.gmail.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Fri, 06 Jun 2025 16:59:12 +0530
X-Gm-Features: AX0GCFtdJCCy0HrtWA-oMKIuWc0u_Am_FDNekB17owx8NVBpeTXKr56-SjzcUMA
Message-ID: <CAFpG3gerd=eNzgqAncq+jXc_y0OfnxnXJGQxhssGMmX3wUEwcg@mail.gmail.com>
To: Mike Ounsworth <ounsworth+ietf@gmail.com>, "<tls@ietf.org>" <tls@ietf.org>, Martin Thomson <mt@lowentropy.net>
Content-Type: multipart/alternative; boundary="0000000000005ea4d10636e58c59"
Message-ID-Hash: Q6YJB6WFGYJ2CE4UTN6O6TW2SNBKMQOY
X-Message-ID-Hash: Q6YJB6WFGYJ2CE4UTN6O6TW2SNBKMQOY
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Adoption Call for Use of SLH-DSA in TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/yyHNyOWrjvZTIHVYQeqPzYMZWhI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Hi Mike, Please review the revised security considerations section https://github.com/tireddy2/slhdsa-tls1.3/blob/main/draft-reddy-tls-slhdsa.md to address your comment. Best Regards, -Tiru On Mon, 19 May 2025 at 11:58, tirumal reddy <kondtir@gmail.com> wrote: > Including TLS WG mailing list. > > Thanks Mike for the feedback. The long-lived TLS connections will undergo periodic > re-authentication to check the certificate validity. In a typical 3GPP > deployment, the certificate will expire and be replaced with a new > certificate with a new key pair well before the SLH-DSA signature limit is > approached. For example, if a server certificate is valid for 1 year and each > connection re-authenticates every 12 hours, this results in approximately 730 > signatures per client connection. Even when scaled to many clients, the total > number of signatures generated over the lifetime of a single key remains vastly > below the SLH-DSA signature limit > > It is an important security aspect to be discussed in the draft. I will > raise PR to address it. > > Cheers, > -Tiru > > On Sat, 17 May 2025 at 19:30, Mike Ounsworth <ounsworth+ietf@gmail.com> > wrote: > >> (my messages are not making it to the list; hoping someone will reply-all >> to get it on the record) >> >> @Martin, would you object to adoption less if there were fewer algorithms >> being registered ... like 1 or 2? >> >> @Tiru, @JohnMattsson -- My objection to this draft in its current form is >> that there is a lack of discussion about that 2^64 signature limit. I am >> aware of the size of the number "2^64", and that this simply won't be >> reached in a long-lived TLS connections, but once we allow SLH-DSA in TLS, >> it's allowed, and Moore's Law scaling over the coming decades could make it >> conceivable to see 2^64 handshakes on a single key, especially with massive >> horizontal scaling and CSR key reuse across cert renewals. How do you solve >> that? Do we require operators to roughly track the number of signatures >> performed? How? So IMO this draft NEEDS a well-worded Security >> Consideration about this limit and I want to see at least roughly what that >> text looks like as part of adoption because to me SLH-DSA is appropriate >> for TLS if and only if we can find something reasonable to say about this. >> >> On Sat, 17 May 2025 at 07:23, Salz, Rich <rsalz= >> 40akamai.com@dmarc.ietf.org> wrote: >> >>> So far we’ve heard that 3GPP is considering using this (presumably for >>> thinks like station-to-station, as it were), but they need a stable >>> reference like an RFC. I’d say that “stable reference” is their problem. Do >>> they consider the TLS registries a stable reference? >>> _______________________________________________ >>> TLS mailing list -- tls@ietf.org >>> To unsubscribe send an email to tls-leave@ietf.org >>> >>
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Watson Ladd
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Loganaden Velvindron
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … John Mattsson
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Quynh Dang
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Kampanakis, Panos
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … David Adrian
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Eric Rescorla
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Salz, Rich
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … David Adrian
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Salz, Rich
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Stephen Farrell
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Eric Rescorla
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Simon Josefsson
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Eric Rescorla
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Eric Rescorla
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Richard Barnes
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Simon Josefsson
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Eric Rescorla
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … David Benjamin
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … D. J. Bernstein
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Viktor Dukhovni
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Thom Wiggers
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … John Mattsson
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … John Mattsson
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Salz, Rich
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Simon Josefsson
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Viktor Dukhovni
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Martin Thomson
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Simon Josefsson
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Peter C
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Alicja Kario
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Viktor Dukhovni
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … David Benjamin
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Watson Ladd
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Tschofenig, Hannes
- [TLS] WG Adoption Call for Use of SLH-DSA in TLS … Sean Turner
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Alicja Kario
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Salz, Rich
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Filippo Valsorda
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Aritra Banerjee (Nokia)
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Filippo Valsorda
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Viktor Dukhovni
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Filippo Valsorda
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Alicja Kario
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Alicja Kario
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Joseph Birr-Pixton
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Valery Smyslov
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Watson Ladd
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … tirumal reddy
- [TLS] Re: WG Adoption Call for Use of SLH-DSA in … Sean Turner