[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2026-02-27)

Stephen Farrell <stephen.farrell@cs.tcd.ie> Fri, 20 February 2026 15:06 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1A761BA78AFB for <tls@mail2.ietf.org>; Fri, 20 Feb 2026 07:06:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RhMkNJh11Xht for <tls@mail2.ietf.org>; Fri, 20 Feb 2026 07:06:39 -0800 (PST)
Received: from PA4PR04CU001.outbound.protection.outlook.com (mail-francecentralazon11023114.outbound.protection.outlook.com [40.107.162.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CA400BA78AE7 for <tls@ietf.org>; Fri, 20 Feb 2026 07:06:38 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Yu3zcEgBXkUkhBwHuNtZPec7LBWNxqngE5RlLI0vgcbUjFYLSQgaM5lMQljVfsGaCWRKiIBwzhceXP/K/MF3IDMqOFwM74MSA0SvOKsXgysrP3WQJMcW78tqAQzm7uhgo1Ijy7rf8Zbwxm1iOVHB/ZEXzn6rc5peEPNVNudZWp93EA9U1F9MgF/uXonPOE54pvLY42kAvj9UIsU3aD3XXm/AkpUW3k7laMeA0HkcxoHA7uE5R3ZHwK0yF4+TxLZa7Es9q8efjWZ7ujoA6kVqPJUkCu1uyPfXzAe4DpaKnqSi+XdXy7qe122tmIdQ4GCUFu0jrv8D5fUhgrinW4cgjA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=ZHXZOqCvdmvBNr0yXkoJ0JrlBhtIH51e2me2qOz+Al0=; b=iAnlR9JGjVJgTp+CO/LgRynq/Nve4lnrqKE9lpJeAbCtEi1vTDRUE61P6lZsBQ/wiANBVvDSjfjPzIzYFybEiN537S7prqt/JBjDibTX3VLtqMF7ReX37ZG/1FByggevnSOgFn7LVFNzcUXhtr7juydXpKwxwOhUAq/ZECSO9M7//ct5zVSXCzrY3VK4V6nyKzZVHKGPvQOsRLKcC4WT5Jw/JU7H735c9cEUYjrPUUba1uZw94+ielxTnA+Z0kzEja1nuQ9+wr+M9Dc9/W372uinzQKa812nLiKHG42+h8skT0ssRFdbSZ2Nn56X7pmn5EOrVhLhj17z12BU6J4Arg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ZHXZOqCvdmvBNr0yXkoJ0JrlBhtIH51e2me2qOz+Al0=; b=FxK/ImNdQM/iZQe0mSRl4Jspjqc4zSSjlJ+6zIEN/AyNfqBLs7mQtk7ccYAT+WnoxjMRR1WPgxbsDLESgi/vocpEqMQA6OYuat14NYo9iaG8FSkXHIG5cnloCcHxL+LZc4ns7CE4t27h3cWC0lDNZ3LWXSSiWALukh0IO2xxr0HO15zu60H5gPT/U4jUU8nSp1GnUmMS8DiSbaqgcnzbu9/23LZd4PeB9EMEznkhJmuiB7oo6Y8eEVogt+YhCpT+KeGLN9b19YRuBPdVgxkyWoD1fM58S/yHn32noFrHMIzMkMeAM4NvIoqSaxhudeKaCw7dsDGlfCNmrKRQCAafIg==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from PA3PR02MB11163.eurprd02.prod.outlook.com (2603:10a6:102:4b4::19) by GV2PPF71E9EE678.eurprd02.prod.outlook.com (2603:10a6:158:401::5d7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9611.15; Fri, 20 Feb 2026 15:06:26 +0000
Received: from PA3PR02MB11163.eurprd02.prod.outlook.com ([fe80::71cc:8d7f:5cb5:3772]) by PA3PR02MB11163.eurprd02.prod.outlook.com ([fe80::71cc:8d7f:5cb5:3772%4]) with mapi id 15.20.9632.015; Fri, 20 Feb 2026 15:06:26 +0000
Message-ID: <ee1be3a5-0e03-4976-8398-45c014c9dfcd@cs.tcd.ie>
Date: Fri, 20 Feb 2026 15:06:24 +0000
User-Agent: Mozilla Thunderbird
To: Paul Wouters <paul=40nohats.ca@dmarc.ietf.org>, tls@ietf.org
References: <20260218194044.1135896.qmail@cr.yp.to> <7C9C99AA-42B0-4BC7-8F41-39F35754F1C4@vigilsec.com> <MN2PR17MB40310F0A2891942D76C43E60CD6BA@MN2PR17MB4031.namprd17.prod.outlook.com> <2caab265-00ba-4078-b6d0-3a178dabaa61@tu-dresden.de> <CAEEbLAbkV4YxN7cgggckpEp24MLtRZpzs6M4KemBatpzCCcs0A@mail.gmail.com> <MEAPR01MB3654415F735DE96CEE239C78EE68A@MEAPR01MB3654.ausprd01.prod.outlook.com> <aZfbhrFDBp7a0xHL@chardros.imrryr.org> <EB48AB24-A1A2-47C8-9C2C-47C93B9320E7@thomwiggers.nl> <93af0689-4bd3-4f6b-afaf-41869d27fa4d@app.fastmail.com> <CAMtubr3QcHbiP5guhBoiFbFh8tKSD6WNHBJkxxb_AM4Wy5i0=g@mail.gmail.com> <9b71e709-69a3-f3d9-4cbd-d4d521556c55@nohats.ca>
Content-Language: en-US
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Autocrypt: addr=stephen.farrell@cs.tcd.ie; keydata= xjMEY9GzphYJKwYBBAHaRw8BAQdAo6JvjmSbxHdQWPZdvciQYsHhM1NxQBU398Mmimoy4p7N M1N0ZXBoZW4gRmFycmVsbCAoMjU1MTkpIDxzdGVwaGVuLmZhcnJlbGxAY3MudGNkLmllPsKQ BBMWCAA4FiEEMG54R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwMFCwkIBwIGFQoJCAsCBBYC AwECHgECF4AACgkQ5Njp+ZeoM93bogEA25ElRyX0wwg+kGEN1AoL60MoZfvQZ/VtmXY6IC5j +csBAIBpkL5ySuzJK2zLNZn9qQGht8IaUcA7cvDcLvS2uHUEzjgEY9GzphIKKwYBBAGXVQEF AQEHQILCPWOwW36e8D3pY8GmvvtItIT+A5uV80ist+WokVsQAwEIB8J4BBgWCAAgFiEEMG54 R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwwACgkQ5Njp+ZeoM92bcAEA8R+8cpqRUIS+SoAN iO05xE6O/wEx8/e88BqzAYki3SoBAOQdwiPX+MQrAxkWD8xxOsdMOAtxYKpkD1n8aPJUw6QJ
In-Reply-To: <9b71e709-69a3-f3d9-4cbd-d4d521556c55@nohats.ca>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------9wS4Ry8KVTo6ck282DUFxyTC"
X-ClientProxiedBy: DUZP191CA0022.EURP191.PROD.OUTLOOK.COM (2603:10a6:10:4f9::26) To PA3PR02MB11163.eurprd02.prod.outlook.com (2603:10a6:102:4b4::19)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: PA3PR02MB11163:EE_|GV2PPF71E9EE678:EE_
X-MS-Office365-Filtering-Correlation-Id: a748376c-706d-4847-73ee-08de70919e29
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;ARA:13230040|366016|376014|786006|19092799006|4022899009|10070799003|1800799024;
X-Microsoft-Antispam-Message-Info: fFz7WpFFiX910wuxJOQZDYjLl7Ppugh6pDeTMTQVth3DRjvAl9xcF9PpD4zHn6d5IMCDQetrgdVPdQ9FJjncqUXwU03VAW5I1nRE7YpqCAo0Hz2SZaxNugK4hCEJSl71nRiW2cvz7ucrsZ1DWkD+sJD/lI15+DVG+M6PTzG+JfvT4LLuhMWcp5ho8ykIKYQSWUf/W8tU3yfT+/7Pqtrdxfl4j2Cod4X3oH0PEy81HziFekh7Jibn/SR4mxW6MweQgl57unubfFwxGSYzz45Qm9rUSip378nMQFU3uOatqqUjsB23i/0qrb9559VcnToCh5uW/m3ei4HJZVvJH6e2XLIU0QCXDoyKttaZqORlGwQWxpo69eXBEXhxWVAJDti9wlLczaY43hWfjaRWUYFIQTyh/lG82hEDaClzEs0QEKnQPkax5sLXCuvsk0WR7vPWiBzwDR/+vw+GangIGRJJc8bIGwrjTP5ufLK1FypKJsx6LHowcUQnpgVvzQVgfKpOzb52BXNlgkg21DC03I/On4ujGSUEh0APT/xVodj7Vr2dVwoKAxeZkdylgTtlUKi6UGgK7pYTbkbZon4qnXCfvOHx2yolxPXvADaxiCMDRVWSw0t5w73UzWXI8k3lQjUpabD4Uw7Zd0x+H53oO5gfcZFilu8zChu1MoQaahKFC3c82TsocDiWxxS+XQuuCNmKniloJEpTzh7g0y+hOsxKYIKqOS2P+p2bIgFgvtRhU+qFDuhH8bke2yf9OyK+02p4hXiVHHEONaY9W2g4atv/I6CaLi1vzBifu2NyNcmgm2m0w/Gy7brHoCbIbLpLK0gSsEhhT712r7MfhxXu3CP79IDGVf08sl0eT8JCpWYFs5pmLRtLDJfiesRmZSaVetBet44d0+9Lg53dnkuqZRRh4zjl/p9tybNy3oH9wYTlFQNoOhqptNSNWxNjt3cikKr4TAaAXkuyTQgMYq7V2dYYjIZ/EfqeNmb5Q4FhxaX2MIp8YpdT3pkwBTNKP9YwqgApdW35JMWTmGy2MX2ePeRnFXJpNuYjIy4SavN1JBchLCPPqH3lvd8cAGho+EFVcpYRis71X6Hc1YqNmCnVwA22v/xPn+91sXAbwBdb4B3mRAKORqpicdI9VweVVLq5K3Kpd0E6tChlwwpa5UrnoJPCqt+3rMadDLYcTJg/ylkBuM4e+59YmByVRwhw7Udl5q4PuCgWobIm2atDkNo8BZPYemTY+TsfRlDewjPeNwYpFyNDRIU+aLJ3kHSBTgTrLBoy79J9qPbeesMv6tkncB0RbTf+c4LR/n4fDDfhHCpce3l9/5xcx6kGnT8uA2A5XSwwGNYSj1CG0CFpKVKa8TkNVKfJATs1l+3uNMxU4O59NwDU+8JZfu6OsgL6gBB3Xs9XAvyeE6l4zrEjC4E88iynDk/HIB/RCzauF6CMkSsxxmbi820uu8dkHG/p29QUu5OT6rvGbtUkN4ugAEVJ2zHFhP9Xh/NdLvWedMIDf6EtL15bkKJPoid8BDx584P87DZxJzYKEhDioYC9PugUF5Oy2T5VJ3wWAU1/XT6mr4mnhl0=
X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PA3PR02MB11163.eurprd02.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(376014)(786006)(19092799006)(4022899009)(10070799003)(1800799024);DIR:OUT;SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 2
X-MS-Exchange-AntiSpam-MessageData-0: J6X86qMKlDsbk1nWcZ/5TFRJETdHggo8eL6sYhxUfWIl/B3m2feEtuY05i/+mSF9lEarH6w6xs8j0RPkB/nU684qnQ4R7x5iy6oRpflYfX7cwUKgxq9WhpGP8e/BJzdFKvJSgh1fem2Nm0dn672lAGa23V/NJPk4/M/hZofEpyn9raNuB/WQCMe2gI6XsOQNbzBZFa2/eohdfwvycZwB7hIMRj322DlUwi5v3WrzBwjjJFC+XrfnVkIHKD4GoRIrwcFVc4FEJrgGvCEpxvQ+USirGR6SK/sjtONGV3T7RPgtMFX254qWIr1UmHaoNADxVR3nZuLH1vUK9WBGyK10oIAbXb7+Sb54Y46Ldf5EIpEBCfotQOQut7CzDDPst5Y1spQieEBawy83MQAT8O6Fa4gvp53eC+ErXGsZmNd7VybNoDmY3qEsYCAy/F71kev0FC3IlnQtTEcPVlOzvzzm330Xb0tITk8hNCYxzVIj2XY5RqRFw6Fh/oZyPfRDetSFhSGjK+CUFsWTBsjUH8z9k9R5/ijYyKkUjllYnkQd16w/2SdWbfhLLUL+0AG48Lhfq1/zU+ttE6zYzrcaw0fE8JVzWhv37tJkX/VXDlMzRnG2B+yKXx1E5HE32v7FnobKAXXMUgCPf4unBihcDMc/6q/9g3WXiPr0OagNZZKKjqVc0QL49+6fsBgSS0DRsaz8fZvIPV4kNm0JfrJ1yeYAAXePwf/h5SN99RbcTvdaVIJfqjzlt1cIyubVONpAQUY7h+0RY/LPfGnQvRxvKG41myxZSVB4cKpMd5uJPkJrMsYQ0K/CKaxT/WltHD/Pp5XKMjYdaJUSelKfD7Qrnd3syGO+eS+1OqsX+TlZaQqsI4fkOcE0Le55GZ0fpt8Vh2oN2pDx6f/u1xNUifrFxRQsyuKJ/DPbgq7j7YLI6Z9cbSqVM4fnvqwF8a3yMeNWUVWYcgcYKanQqUd9Yo5eFBQILHxyIJyV+rPMhm13YazRE7d2I9LVuElQ4chqxKxaU28jcreJ7JVXlObS/PgaLigyIH5iH1X6htLEU8gef6JqmnHlM9ZDtQWXs/0aDdHr9BDRz4QUK6OBQb2E0Zihd4ro1gZ2UdsTdSc+nOSOdFMrVWC9txuVwcpdmltLWrqN0jYc9SFAxgBycff6Bd3nFbYNMBYDXoDqBeODxnISZWUMDnjbiv61cXx4NI/Eakmd/VLXzVP+N2c5m31CqGustq3KNUd3kssPf6A8QavCla82NcIinDAjuIQcJ8Cs1squ5iDmBaSPJpI5/oSWQOI+AB/ax3l9doMKU+snFPu0cMar0Csng30cOiW5QJCh4NV62sKVlFHPUQfzBflq6nw+J3qSSVXWuBtZORsiYCNdenKDO21Vkw2/PEdigR1S07GH9W/7/hmF3y1iXJ2c1eX+A41zOf9KTCRgCy8iAgqjtNGOuo0fJsdPx4PkG2tRoAJwuJvdD2sS/DmFifPaSjSFehfI4cnasRQVQpaANyN9FdgQv5cG39diay4voqZ/oYVSwgPtdeF4ie6HwszKQ2/xbDxn5d6Gz4II7WSPhM5+MTvP+/6FSG+F3F2n//AodRe3fLBYzQmWTZ0+8hKf/o7G1oVx25ZgfHEBzpGslYSd+dX/1EOGfc+u8XOnJHZ/hB6aZb3M76APQxAq45uXPdIRxvh2rVMAV6SUM2Q1Bs7UYkGJlYGs5H58+PSiEbrza7SjPu9mvCPmh9cGKNbkaF+pkkQFfYNdc+Uxr13kLi0EaMTVxR1VExhz5aCIg4P52Fs3n2NSQhYkVWoG
X-MS-Exchange-AntiSpam-MessageData-1: xVnOYFG9Kf2etw==
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: a748376c-706d-4847-73ee-08de70919e29
X-MS-Exchange-CrossTenant-AuthSource: PA3PR02MB11163.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Feb 2026 15:06:26.2959 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: 0oow9ATFLzgkHa/aoHrN8mpvzO8vg4tllth46vi82V2TvAlc+FHmhOG4LGf/Qe/6
X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV2PPF71E9EE678
Message-ID-Hash: XWFIILBLRXNGBURGDYPP6RII6BY5DLPR
X-Message-ID-Hash: XWFIILBLRXNGBURGDYPP6RII6BY5DLPR
X-MailFrom: stephen.farrell@cs.tcd.ie
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2026-02-27)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/V6mkczU1sDTRpGQlOiLhCpffMog>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hi Paul,

Quoting from [2] below:

"The chairs will then redo a working group
last call to see if there is rough consensus for publishing this document."

FWIW, I read that as meaning a fresh WGLC not one limited to the
diff. And I think it'd be unwise to process this as if it weren't
as controversial as it clearly is.

Cheers,
S.

On 20/02/2026 15:00, Paul Wouters wrote:
> 
> [ AD hat on ]
> 
> All,
> 
> I want to remind people that the goal of this 2nd WGLC is to focus on
> the new text changed in responds to the conclusion of the 1st WGLC.
> 
> We already had a WGLC on this document [1] and the conclusion [2] was
> that it passed WGLC provided some clarifying text would be added that
> stated that for the general use case, hybrids were preferred. This
> 2nd WGLC is about that topic.
> 
> There is an appeal chain that got muddled by the inappropriate use of
> derivative clauses that is still in progress, but so far yielded the AD
> statement [3] that confirmed the WG Chairs view that the consensus call
> passed. There is an appeal with the IESG [4] on that decision, and this
> document will not be placed in the RFC Editor queue until that appeal has
> concluded, but will also not stop all processing while the appeal runs.
> 
> This 2nd WGLC is meant to get those people who provisionally said "yes"
> to publication of this document pending some extra text, to review this
> text and let us know if that resolves the conditional part of their
> "yes" statement. The text changes to discuss can be seen at:
> 
> https://author-tools.ietf.org/iddiff?url1=draft-ietf-tls- 
> mlkem-05&url2=draft-ietf-tls-mlkem-07&difftype=--html
> 
> 
> I understand this is a heated topic. I am also not hearing from people
> that they have changed their opinion on whether or not to publish this
> document at all. Confirming your views are fine, but again, that is not
> the goal of this 2nd WGLC. It would be helpful if, especially those
> people who wanted additional clarifying text, to give us feedback on
> this. And ideally, offer up suggestions that would address any still
> outstanding issues.
> 
> Thanks,
> 
> Paul
> 
> [1] https://mailarchive.ietf.org/arch/msg/tls/Pzdox1sDDG36q19PWDVPghsiyXA/
> [2] https://mailarchive.ietf.org/arch/msg/tls/Gc6KVPrVHn-QCkeEcvJ_qtRcFxY/
> [3] https://mailarchive.ietf.org/arch/msg/tls/dzPT8KQe4S-_pZROLUJMvS9pM0M/
> [4] https://datatracker.ietf.org/group/iesg/appeals/artifact/230
> 
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org