[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2026-02-27)

Yaroslav Rosomakho <yrosomakho@zscaler.com> Fri, 20 February 2026 00:33 UTC

Return-Path: <yrosomakho@zscaler.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 03069BA2D306 for <tls@mail2.ietf.org>; Thu, 19 Feb 2026 16:33:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=zscaler.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7QbR2bJQchwO for <tls@mail2.ietf.org>; Thu, 19 Feb 2026 16:33:09 -0800 (PST)
Received: from mail-dl1-x1232.google.com (mail-dl1-x1232.google.com [IPv6:2607:f8b0:4864:20::1232]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 786EFBA2D2FF for <tls@ietf.org>; Thu, 19 Feb 2026 16:33:09 -0800 (PST)
Received: by mail-dl1-x1232.google.com with SMTP id a92af1059eb24-12758ce1e8dso3884256c88.0 for <tls@ietf.org>; Thu, 19 Feb 2026 16:33:09 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1771547588; cv=none; d=google.com; s=arc-20240605; b=Mx0N+yPNtaZvmWcSHH9pfBDauoNspufBhNDzCXA0wF8l5J5QDFlJ9cWe93s0H7DYri KjVxdMX3KTUXQ2wzQZVd63scH0qz6+V87BBJVBSnIkkDjaz31S/ZA5RiUVGTwxhEPBdq JUpowEuPUrqBaLoP/OYcMXuJeFnVxyY9YsRtWIz8LZ5XFKAAIuxUZKyWuKSe3jLI+f3T 5DlpeufLKiinZ/wzvJXVB0mJzXQzho9TQ3T5xLBgYeSKSOTvsjK6oLi/6piYzj7KCO0Q p1DnrRIHnewTIfE3U7kE5DMp2le22frxf6I/jN/keGkfQQmnfAl8mVflLFLaB7Jd2vzZ N5wg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=rKUaxEbrq4dJq8kHQQ1Rx/6Scep9HmPhWES/RHELDT0=; fh=evwO7pRt6bQBsfOroTJBkxVkB8FYUo4hfmaqyo8ND58=; b=QLDgXiKWXprJaxZ18+olmbQUvvfgQbMNOvqkhHHh8s+DS/XRRCMYD48sUHq/hbwURd vp7gTNlEWn/0bpM8lb1pNVj6f9lZ+o9srsaDVkelOstFJnGhXBoNa2qUyJ58br2Mr85p y3HPZTO/Vnxx+XVdoHsVtU6myNj/34BytdUtxs1C9RyLkYp3lK3So0rDxkLWj4+XEFs4 NiwSZ8J1i9qiUXCJlyRkkYqKP4t5fBOpVHo7BfoLMxCwRseN2cc4mM1Pmt1e6dCx/MiM 8kLCivEgtH9RKEcU5+E76B464H6v9juix6bih+PlRnagAqnODpKYRESzqTdAQucInHw0 V4Bg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zscaler.com; s=google; t=1771547588; x=1772152388; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=rKUaxEbrq4dJq8kHQQ1Rx/6Scep9HmPhWES/RHELDT0=; b=Va+Bl0pTlIfG3e4uvB+vzHgLvJo4IiYxPwi9gFTBsuJ0jrPgpkSJtafd5cUNFAxMZ9 ESPdC3smPqI4W/cjfUbxX/R+znr9Fcear6OkWNVKMbGAytL+G2lQtvwmhcQLeROalp4c 3Gr25n9iNBi/uV+1v5dmPAqyVOxtqcfgrgz6o=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1771547588; x=1772152388; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=rKUaxEbrq4dJq8kHQQ1Rx/6Scep9HmPhWES/RHELDT0=; b=WXVi6fuskRygCHQDIREOCuTm51Jw3M2gu3KaKC7KnECpOsLYZ+3Tg+MAFjLeGNWzG+ Pra2ceby1pUhNs1bj+IctJG/xFN/R21JmIDgdzzD0RQGMX4/vtpkSK4LTRNjEb0TdjVa CMQ+3anpd2wnjubc1QCp2Skb4JUeFIuODWRrzGYrTstFquknL8/FcZF/79VQTXEcL1uE qtEGH3nz0RNIqWlp9B6TQHolvPEjfdPsHbGp5VDJYrF3f/oIZx10rFzwseuz+Cd51yij ayX9/jJLn63YROec8W30DRHpMHn25+Jm75HOlrB0FAFeoZWwVY9ytLlQ4rLbLAxScF90 Autg==
X-Gm-Message-State: AOJu0YzyNonyG++gdxfe6Khs4Wq2D08YGbywixYwHz3xIhD7wkKMT3vG vCLmqF/muUZQC2E248UzVXiwuHWEhCgrm6qMPqXlh9IkZM2MWNmhXdXS/y+PjlGmroq5XXCcZJl jw/FjhJazwIksznCAlJA0HekRFhRK18OyXbxolwi4uRU1kzDK+s8NsH7x+MWEu8nZMvyfiq3Hcm yAmyIcNk2PkWI2a/AAtQKDQg==
X-Gm-Gg: AZuq6aJE1L5pbqSlrF14S0XtNYmCDzbB5SDL2ReUhAlc4i3TJuiGYwUcyJu7jbRmFUo cRINNFXQb/M7eKuG7tb+EjcLnRS8nHCfAe+DunADRCNLjzD7sRq1xDksqx1LYHzGMSFkjhjmdc+ NUv39VNVEg7pBADckQ64o2BJxiyeWLlT/vNC985v57S8O1WQhLpiQeo2a44JSbgONjZcOx5hDRN mA5wWJ6/W9PM/gVKCs+oBlrHDmxS3tr2fkN2NtbDMXDPlrp+G9RtCCybGSnRsvqJpk2X87KNyRR hWbhr+0Ap+ZucxXZ9lExNJFb1J1zdVP4c2j2fiX+1x2XqsVEaYvn
X-Received: by 2002:a05:7300:3b20:b0:2ba:6b88:d636 with SMTP id 5a478bee46e88-2bd5b3ee2c1mr2643625eec.31.1771547588047; Thu, 19 Feb 2026 16:33:08 -0800 (PST)
MIME-Version: 1.0
References: <CAOgPGoDLVqAVesWjrrD9ZR8HMkqQVLMp69vOkXPkk87MzcsOSw@mail.gmail.com>
In-Reply-To: <CAOgPGoDLVqAVesWjrrD9ZR8HMkqQVLMp69vOkXPkk87MzcsOSw@mail.gmail.com>
From: Yaroslav Rosomakho <yrosomakho@zscaler.com>
Date: Fri, 20 Feb 2026 00:32:57 +0000
X-Gm-Features: AaiRm509oXBDhbWjPejZKUDfXHtSGV_atYPLNfzECcweKnRmeo1QohwkYjnyhqo
Message-ID: <CAMtubr160cFW_X2iNAnh02xHfPsRASsNJXy-DPewj1qDmzt5Yg@mail.gmail.com>
To: "<tls@ietf.org>" <tls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000b04d87064b369073"
Message-ID-Hash: 7BDCWEGIW2DWSQJGRGPM7PGW4DN5DYNP
X-Message-ID-Hash: 7BDCWEGIW2DWSQJGRGPM7PGW4DN5DYNP
X-MailFrom: yrosomakho@zscaler.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2026-02-27)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/FugOOQg6mPpWFUU-cTi4JpCkaGk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I support publication of this document.

The current Security Considerations, together with the "N" value in the
Recommended column of the IANA registry, provide sufficient guidance.

Hybrid PQ/T is clearly a transitional mechanism. While we cannot predict
the exact duration of that transition, its purpose is to enable safe
migration rather than to become a permanent steady-state configuration.

Publishing the pure ML-KEM specification will give the ecosystem a stable
target and allow future work to focus on deployment experience and
subsequent evolution rather than prolonging uncertainty around the base
mechanism.

-yaroslav


On Thu, Feb 12, 2026 at 7:06 PM Joseph Salowey <joe@salowey.net> wrote:

> This message starts the second Working Group Last Call for the pure ML-KEM
> document (draft-ietf-tls-mlkem-07).
>
>
> The file can be retrieved from:
>
> https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/
>
> The diff with the previous WGLC draft (-05) is here:
>
>
>
> https://author-tools.ietf.org/iddiff?url1=draft-ietf-tls-mlkem-05&url2=draft-ietf-tls-mlkem-07&difftype=--html
> <https://author-tools.ietf.org/iddiff?url1=draft-ietf-tls-mlkem-05&url2=draft-ietf-tls-mlkem-06&difftype=--html>
>
>
> The main focus of this WGLC is to review new text providing more context
> around the use of pure ML-KEM.  For those who indicated they wanted this
> text, please let us know if the new text satisfies you and if you support
> publication. This working group last call will end on February 27, 2026.
>
>
> Thank You.
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>

-- 


This communication (including any attachments) is intended for the sole 
use of the intended recipient and may contain confidential, non-public, 
and/or privileged material. Use, distribution, or reproduction of this 
communication by unintended recipients is not authorized. If you received 
this communication in error, please immediately notify the sender and then 
delete all copies of this communication from your system.