[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-07 (Ends 2026-02-27)

Nico Williams <nico@cryptonector.com> Tue, 24 February 2026 04:10 UTC

Return-Path: <nico@cryptonector.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id CDDE7BCC54F2 for <tls@mail2.ietf.org>; Mon, 23 Feb 2026 20:10:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cryptonector.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g9vvSQy-EPwS for <tls@mail2.ietf.org>; Mon, 23 Feb 2026 20:10:13 -0800 (PST)
Received: from aye.elm.relay.mailchannels.net (aye.elm.relay.mailchannels.net [23.83.212.6]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4922EBCC54ED for <tls@ietf.org>; Mon, 23 Feb 2026 20:10:13 -0800 (PST)
X-Sender-Id: dreamhost|x-authsender|nico@cryptonector.com
Received: from relay.mailchannels.net (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTP id 57208820CD8; Tue, 24 Feb 2026 04:10:06 +0000 (UTC)
Received: from pdx1-sub0-mail-a240.dreamhost.com (100-99-99-94.trex-nlb.outbound.svc.cluster.local [100.99.99.94]) (Authenticated sender: dreamhost) by relay.mailchannels.net (Postfix) with ESMTPA id E9FCF822CED; Tue, 24 Feb 2026 04:10:05 +0000 (UTC)
ARC-Seal: i=1; a=rsa-sha256; d=mailchannels.net; s=arc-2022; cv=none; t=1771906205; b=XiE09yhRL4vBNKSMLTl8ANTdeT3UjyE4zjPVEf6KqqhtX7/BQbeDbcJ4OA1RTrsQsikDXg VevDRauy6I9cN9fFlw/49Co21NL+mPdNnWYLizbFgeFzQBd+nqm13syx50+nxmr/C8UfIH utZd4T2OSgLJx6JgRIryh66kufiBQFUSBx2RRumkPwthXhlQRfGu39LNbchXip91/LjQXs 1aTLmZLTsmVOXMmAD9ufnlyEOpxVQ0dPn5Dp7pclGDOkyFx2doKTuaSu/SWtTmpkwOv38a /UspTuzysnANZltulgK+of0ywFDhJ4uNpb7q7B9y1hBBf62npCbTFOmqfHouwg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=mailchannels.net; s=arc-2022; t=1771906205; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references:dkim-signature; bh=M+8jZcFNDXjm2ZGKgKgSQ844QAi0KnjFIDcdyqE5Gkw=; b=R/CPJfrnQpgUWqxJD6GFDpITpGiizC7mOLPaPnc7M/cNGJPR/GcMfYA8ddCa1mg9ouLhUE NERV3MMK4yXxb1drftJltyvlLKDB5ULNIQuDLpr1RjsXy0ipQxVn6q9uVpCw9Hiu3tLzze 6h4wc82EQy5rvf+4aeRk5sjxj+7MI20RKRw+1E5bPSRVkzy8VjQzxjvTZvGm/kXVkKE2v9 OVzMAbwKzxvXczB+lehso6H9bENuRBFwsLYhRoAUv9SrrJuxCV4JxJeANIWSqMUvCeWm16 G2GYaNTE9ymMEi/iZup5387eBbzBEPo6Ff9eNIDz2vrfpWvxSyreU9gmCYmQWw==
ARC-Authentication-Results: i=1; rspamd-7f65b64645-gdw9b; auth=pass smtp.auth=dreamhost smtp.mailfrom=nico@cryptonector.com
X-Sender-Id: dreamhost|x-authsender|nico@cryptonector.com
X-MC-Relay: Neutral
X-MailChannels-SenderId: dreamhost|x-authsender|nico@cryptonector.com
X-MailChannels-Auth-Id: dreamhost
X-Eight-Irritate: 6f39827a0b025ed0_1771906206180_1768672883
X-MC-Loop-Signature: 1771906206180:3381202262
X-MC-Ingress-Time: 1771906206180
Received: from pdx1-sub0-mail-a240.dreamhost.com (pop.dreamhost.com [64.90.62.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384) by 100.99.99.94 (trex/7.1.3); Tue, 24 Feb 2026 04:10:06 +0000
Received: from ubby (unknown [75.81.95.64]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by pdx1-sub0-mail-a240.dreamhost.com (Postfix) with ESMTPSA id 4fKklK3XH7zyrD; Mon, 23 Feb 2026 20:10:05 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cryptonector.com; s=dreamhost; t=1771906205; bh=M+8jZcFNDXjm2ZGKgKgSQ844QAi0KnjFIDcdyqE5Gkw=; h=Date:From:To:Subject:Content-Type; b=VmbU+YguPukKf50zo8F2yStFmKxDe9BbXks8bbQSVKBlFyf/ZMfbNPaOYGMx0SOFh bgc0asQ2EsrBlhPtm8WLCQhd9ejb+RECkAqoeryzRO69YNtbkIqHycDMKYWnGccsyr guHEHvpraXf1iL4yo2EFXO5bdwn3JdS+ztXLKEffB6MnPaeTe1KEYuM4yuTRJOLc5S jZ+ALnrSw11dlrF0YRnd+PdqLz2fJENH46C6RZKpgTFOPF7T3Sy6M034BDAhkj55an C6dIruK+onpUrA7DEwxQyG9HSOcKgV2QJTF/+c+kjZqI6cRotpWnwVYWIAjhVAimtF Tc/9ZMwT6JmrQ==
Date: Mon, 23 Feb 2026 22:10:03 -0600
From: Nico Williams <nico@cryptonector.com>
To: tls@ietf.org
Message-ID: <aZ0km2rrk62J4Ow+@ubby>
References: <aZfbhrFDBp7a0xHL@chardros.imrryr.org> <EB48AB24-A1A2-47C8-9C2C-47C93B9320E7@thomwiggers.nl> <93af0689-4bd3-4f6b-afaf-41869d27fa4d@app.fastmail.com> <7e6727a1-c994-43df-a16b-078bd8995717@tu-dresden.de> <AS5PR07MB1059610AC3701494F1B0BE7A28968A@AS5PR07MB10596.eurprd07.prod.outlook.com> <CAFR824z7endo8REtKvxQp-0dbVuQvg532BFtT1UebPLOSKbS6g@mail.gmail.com> <aZkMpTWxJGsmx--C@chardros.imrryr.org> <850d1216-8b24-45e3-95ef-3a6899deaf73@redhat.com> <CACsn0cmJbv99eE=s2jNUDrD5g34ZbJWdiwAxhK_0rYDybgu=ZQ@mail.gmail.com> <aZ0PqgnaIRkdK5Bj@chardros.imrryr.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <aZ0PqgnaIRkdK5Bj@chardros.imrryr.org>
Message-ID-Hash: DNZ5NNL7DFYHQNFSMLLAVYFOK7HZ5EJS
X-Message-ID-Hash: DNZ5NNL7DFYHQNFSMLLAVYFOK7HZ5EJS
X-MailFrom: nico@cryptonector.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-07 (Ends 2026-02-27)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/detyGtXDVNeQDfZ1-V3O1cxznNE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On Tue, Feb 24, 2026 at 01:40:42PM +1100, Viktor Dukhovni wrote:
> On Mon, Feb 23, 2026 at 05:36:32PM -0800, Watson Ladd wrote:
> > > Publishing the draft simple means "If you must do this, this is how".
> > 
> > The codepoint registration is all you need for that.
> 
> Sure, but a published RFC signals that the specification is finally
> stable enough to publish the final versioned I-D as an RFC.

Eh, the codepoint comes from a part of the namespace that is
Specification Required.  The current specification is listed as
draft-connolly-tls-mlkem-key-agreement-05.  If the I-D is never
published and the authors do not change the registration, then whatever
the last registered specification is is the stable one, and presumably
that ought to be good enough to produce interoperable implementations.

That said, I also support publication on the grounds that 'the ship has
sailed' and it targeting Informational is 'good enough', and given that
I'd rather have a document that received WG, IETF, and IESG review than
one that didn't.  Though I would prefer this be published as
Experimental.

Nico
--