[TLS] Re: New Liaison Statement, "Liaison communication to IETF regarding draft-ietf-tls-mlkem"

Nico Williams <nico@cryptonector.com> Mon, 06 April 2026 02:51 UTC

Return-Path: <nico@cryptonector.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 41D02D6D5DFD for <tls@mail2.ietf.org>; Sun, 5 Apr 2026 19:51:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775443906; bh=//KPK0G5HBAyy0XmxybQM+/aPrh73WIt6MgfPLePAj8=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=wu8S/np4tgFg2y1da/CHemzJPCwdkgHaBbkRv2sA13vqV96zSt+YviCQ9mNUlddl/ qnGB40NWtNvMdmEoNK1rUk9xMe/sr6QqM4CaQVmczKxV2IZHdTQuo20LjGfYevb28a aoDiB8FhpVjf2nROfSTFbQA1X5GlGcwmmG8assjU=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cryptonector.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o7XVaesX7smY for <tls@mail2.ietf.org>; Sun, 5 Apr 2026 19:51:45 -0700 (PDT)
Received: from slateblue.cherry.relay.mailchannels.net (slateblue.cherry.relay.mailchannels.net [23.83.223.168]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id ADC9DD6D5DF8 for <tls@ietf.org>; Sun, 5 Apr 2026 19:51:45 -0700 (PDT)
X-Sender-Id: dreamhost|x-authsender|nico@cryptonector.com
Received: from relay.mailchannels.net (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTP id 297A18A2886; Mon, 06 Apr 2026 02:51:39 +0000 (UTC)
Received: from pdx1-sub0-mail-a204.dreamhost.com (100-118-167-109.trex-nlb.outbound.svc.cluster.local [100.118.167.109]) (Authenticated sender: dreamhost) by relay.mailchannels.net (Postfix) with ESMTPA id C89428A2389; Mon, 06 Apr 2026 02:51:38 +0000 (UTC)
ARC-Seal: i=1; a=rsa-sha256; d=mailchannels.net; s=arc-2022; cv=none; t=1775443898; b=rXkTgLDLHVwD3Oh7lFk1sxjmec/HxrpE9c/zMPk3bM9pwFtnGqpWac/o82D7gVM+C9du2a iySiuLrzvVZi3V4ErjxRDK9Uem7MlqF3jL7E6PYgGCiIBTi6SwpTF4zZBLl8oRxHd5M4R2 xTSF0sd705F7tpLwjI7KY3rOsP6jRM8R0xISQo5oz+zZPch5tPZTqriwv9MMIZX51PcVKY GHVn6G9doJF8bemNbiAWz189U8KjfCy9eSjkASgIJFEDeJpDW1EZ0AecWEX6ZB4U5mj9eW Ef7NlqxWZ+otjX6UoVOxzcW9WcLZBmLwkrSjdYUpTq9Wc08zx9tytvAaGaM6yg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=mailchannels.net; s=arc-2022; t=1775443898; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references:dkim-signature; bh=lCHGLTnXNiKvQNeSVSXVdl+hofJsSQz1cZ9ejJbHcoo=; b=RkX2txL8JT0PTtERbpsS/RE19JVgIoX1xWYnfiGL/UjtLcsdk5h2HxRCDZv31QjXsq5a04 5M+E9GgY9Y6SuY85Lq5hiwqjQGcz7JRB06sbqJfmX/epzvIUa3rZBJQn/ym8uex59I0LSI +75Y4sSGlIfywDlMmmW5oFWFtslxIW+kB+bqe4p6bQZrlr5t9xlyGuTVzjhoFAjoXT5evT zeHnp8/1WGtk+myf1YK7rCVw/SHXWum2kjHYun19tRg5N7xUT9DrG+xrSKT4DMP3JX8yej EgH9GDa82E8Nq6PdzVX4/5ew9bevSI5mtFz+enc6OYhiZN8eNQryWxcHnRzQ+A==
ARC-Authentication-Results: i=1; rspamd-7d86dcc447-clmbp; auth=pass smtp.auth=dreamhost smtp.mailfrom=nico@cryptonector.com
X-Sender-Id: dreamhost|x-authsender|nico@cryptonector.com
X-MC-Relay: Neutral
X-MailChannels-SenderId: dreamhost|x-authsender|nico@cryptonector.com
X-MailChannels-Auth-Id: dreamhost
X-Exultant-Callous: 36be9ec3482c6785_1775443899055_804366417
X-MC-Loop-Signature: 1775443899055:2739812238
X-MC-Ingress-Time: 1775443899055
Received: from pdx1-sub0-mail-a204.dreamhost.com (pop.dreamhost.com [64.90.62.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384) by 100.118.167.109 (trex/7.1.5); Mon, 06 Apr 2026 02:51:39 +0000
Received: from ubby (unknown [75.81.95.64]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by pdx1-sub0-mail-a204.dreamhost.com (Postfix) with ESMTPSA id 4fpv3t0QJ4zPM; Sun, 5 Apr 2026 19:51:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cryptonector.com; s=dreamhost; t=1775443898; bh=lCHGLTnXNiKvQNeSVSXVdl+hofJsSQz1cZ9ejJbHcoo=; h=Date:From:To:Cc:Subject:Content-Type; b=cXcDCYWzlwKbCPbWESgDOT8rrXF1YVmZo2qYu+fwoeo0lPbqNcMfLkHi30DsaNghQ FL0VWIr/beeJF0yXT/hxA0r0UgC4BWFgndA+rv2JabgVpDxOy6CH4+EZLlqHqmnH9P PoJB93iiVp3cjp1/JS4oOPSgupFh/sTKjyekM7iA/AWz2SYC5bp88UCi5lHAocKbkZ eCcRrjIOJljB+lIqjvPNmEwH/OCFjANNtVEv8+Sg0DfwwPa9/rQOPY2Ngq8Py19z1o NYW9qMtC7eSJU6v+cqyc8UA7smsO5b3ujneO5L+0D/QMy03EYIFEbs+WURicG4hvdP iZ9gOCeXxGmUQ==
Date: Sun, 05 Apr 2026 21:51:35 -0500
From: Nico Williams <nico@cryptonector.com>
To: Eric Rescorla <ekr@rtfm.com>
Message-ID: <adMft3TMsDXWLxDp@ubby>
References: <5E23938A-6AAC-44A8-A515-C8B031203A16@vigilsec.com> <CAL02cgRS0VXm9ZyXZd=-ZOi-VCvTbvk05rjbTCm6_ksgu-RBKg@mail.gmail.com> <ac7oEfBv6zLisnIi@ubby> <CAL02cgRyekc5oz5FaGRcLvxcxNrUSYKH0pXxxxATke_SLZ1aLw@mail.gmail.com> <CAF8qwaBcotZqOnY2qJ6d0fRoa=5v0sZTOSWqeqkou+bLJcy9LA@mail.gmail.com> <CABcZeBPr+WeivTWpSCVC4f95fRuSiOytvvBPB_6r+af9Didhgw@mail.gmail.com> <CEB84168-5998-432A-9D62-36E28B9CDFA5@vigilsec.com> <CABcZeBM-eoqh+kJ7H6SiwC9p4tKAt+YiQhzetJZJmPNpXc+5OA@mail.gmail.com> <CAF8qwaALDXR6d=jLD46wXmKHDjyj=OdJ1X3a1AgxF+ByQceeMg@mail.gmail.com> <CABcZeBO0ysBjtbiPuSboP4fAATuVHQxq1TA5TbQ+_Oy-NrET0g@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CABcZeBO0ysBjtbiPuSboP4fAATuVHQxq1TA5TbQ+_Oy-NrET0g@mail.gmail.com>
Message-ID-Hash: ZCWDXIHHOQBNJIFHWZWCR7CZ54TYZSMC
X-Message-ID-Hash: ZCWDXIHHOQBNJIFHWZWCR7CZ54TYZSMC
X-MailFrom: nico@cryptonector.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Transport Layer Security Discussion List <tls@ietf.org>, Sean Turner <sean+ietf@sn3rd.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: New Liaison Statement, "Liaison communication to IETF regarding draft-ietf-tls-mlkem"
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/5j582vvQfY-dKEki-mKZ3KocVSI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On Fri, Apr 03, 2026 at 12:16:09PM -0700, Eric Rescorla wrote:
> [0] I agree with you that the level of contention here is out of proportion
> to the stakes of how much it matters whether the RFC is published.

Yes.  The work item was adopted in spite of some objections.  Those
objections were raised again at WGLC, with more objectors than earlier.
I don't think any _new_ objections were raised.

Under those circumstances, and considering that some SDO will publish
this if not us, it would be much better to now publish ourselves, as
then we get to give guidance that we might not otherwise, and I would
rather we give that guidance.

> [1] Note that we do this ourselves sometimes for other reasons.

Yes.  On several occasions.  E.g., we've published GSER instead of
taking that to the ITU-T SG 17.  E.g., we've competed -but also worked
closely- with ECMA on JSON.

Nico
--