[TLS] Re: New Liaison Statement, "Liaison communication to IETF regarding draft-ietf-tls-mlkem"

Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de> Mon, 06 April 2026 18:30 UTC

Return-Path: <muhammad_usama.sardar@tu-dresden.de>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id AE02DD715B2F for <tls@mail2.ietf.org>; Mon, 6 Apr 2026 11:30:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775500226; bh=+jL3sXraSR5cLH9GnoZ29yr26fTrAB54LuGAz0wmkhE=; h=Date:Subject:To:CC:References:From:In-Reply-To; b=Dr87cAIe3KKCS2w6su2LJRWOcAGlyAPOgA3IN361yoGwj2Kxt0zaSRkxBHpaFjL2m qTuxPTBRj6jTwddafKMUJZ3tfMXUP5epj+R/B2wwxbVnPad3HCRNQG89JSnlXxocML nAOfEaUuh0+z8BaHOvO9QcQhJ7eV7xFN1wPNIXAs=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=tu-dresden.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iV46N0t2Ahiq for <tls@mail2.ietf.org>; Mon, 6 Apr 2026 11:30:25 -0700 (PDT)
Received: from mailout7.zih.tu-dresden.de (mailout7.zih.tu-dresden.de [141.76.32.220]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 820C8D715B18 for <tls@ietf.org>; Mon, 6 Apr 2026 11:30:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tu-dresden.de; s=dkim2022; h=Content-Type:In-Reply-To:From:References:CC:To :Subject:MIME-Version:Date:Message-ID:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=lUeSsJkVpzv+CdsachEcX+88rwbihNxJD/NfwcPt4Oc=; b=e1DmNYumOyHbjcx3E6J2cJyH2I E/Nj6jlsYjUo8Y86SgMA8z2sWifRuTUTq2uyZz04WrOpURTgQ7k/wG3bjP0mWQol0o3OUYcKcXVth DpltLxH9NtAjC/VKhUQs2HKzCNQPkmR8sl6rqYwvwkk9YEcy9LxiCFF7f/RcvwFCVTIAxIeNJAPzM xpglaEIbk2Y7EOnJ+Oqtyg5Sn+0b8HeHmJaebN/spZwdZHiZZEBP7rA3KlTmclEye627xAou56j7O 30ru/CzPvHNlyvtVYhy0/rNQjQsuIsQEmCicGEaPlcIoI142qV4FJr449xqQjvdMLp8sqiEnjyQ5r 9hl1TEig==;
Received: from msx-t422.msx.ad.zih.tu-dresden.de ([172.26.35.139] helo=msx.tu-dresden.de) by mailout7.zih.tu-dresden.de with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <muhammad_usama.sardar@tu-dresden.de>) id 1w9oiK-002biW-1D; Mon, 06 Apr 2026 20:30:24 +0200
Received: from [10.12.5.228] (141.76.13.165) by msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.37; Mon, 6 Apr 2026 20:30:17 +0200
Message-ID: <3d933b83-2b0a-40ac-80b9-dd2cc15b4766@tu-dresden.de>
Date: Mon, 06 Apr 2026 20:30:16 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Russ Housley <housley@vigilsec.com>
References: <CAF8qwaBcotZqOnY2qJ6d0fRoa=5v0sZTOSWqeqkou+bLJcy9LA@mail.gmail.com> <CABcZeBPr+WeivTWpSCVC4f95fRuSiOytvvBPB_6r+af9Didhgw@mail.gmail.com> <CEB84168-5998-432A-9D62-36E28B9CDFA5@vigilsec.com> <CABcZeBM-eoqh+kJ7H6SiwC9p4tKAt+YiQhzetJZJmPNpXc+5OA@mail.gmail.com> <CAF8qwaALDXR6d=jLD46wXmKHDjyj=OdJ1X3a1AgxF+ByQceeMg@mail.gmail.com> <697d6134-0083-4933-8531-9be49118be7d@cs.tcd.ie> <adCCIZsvHqgci5LT@chardros.imrryr.org> <597455e4-29e1-46a0-a9a7-b87c5adbaec7@cs.tcd.ie> <adFBMGhVMOl2eptE@chardros.imrryr.org> <34c6c882-4cef-4350-9afa-0edb0b460eb6@cs.tcd.ie> <adHR1YEW-mPEb_BT@chardros.imrryr.org> <MEAPR01MB36540326A63FD5EAB70F652BEE5CA@MEAPR01MB3654.ausprd01.prod.outlook.com> <CAPxHsS+fv2S_Ydub24AHnFJUESxkr=h1me5NEtdsZ4bCqAip-Q@mail.gmail.com> <5b703cb2-721b-485c-963a-c6661b40c4c8@tu-dresden.de> <59ADD91D-9A81-4DC5-A3B5-3D8C2747AB96@vigilsec.com>
Content-Language: en-US
From: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>
In-Reply-To: <59ADD91D-9A81-4DC5-A3B5-3D8C2747AB96@vigilsec.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms060507080809040001010902"
X-ClientProxiedBy: MSX-L421.msx.ad.zih.tu-dresden.de (172.26.34.141) To msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139)
X-TUD-Virus-Scanned: mailout7.zih.tu-dresden.de
Message-ID-Hash: SXKCYJAQJEUCM4PTIZIIOVLZ654N6FLJ
X-Message-ID-Hash: SXKCYJAQJEUCM4PTIZIIOVLZ654N6FLJ
X-MailFrom: muhammad_usama.sardar@tu-dresden.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: New Liaison Statement, "Liaison communication to IETF regarding draft-ietf-tls-mlkem"
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/1H-LiY5yMez18-NFDqPnnVvj-OE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hi Russ,

On 06.04.26 19:02, Russ Housley wrote:
>> Soliciting an LS to "do the trick" for showing consensus does not 
>> address the technical concerns of two dozen people who have opposed 
>> publication in the WGLC. Given that*there is no public evidence of 
>> IEEE 802.11bt having consensus on using pure ML-KEM in TLS protocol*, 
>> isn't it fair to ask for technical rationale?
>
> This response ignores a lot of context that has already been shared in 
> this thread.  I am responding so that people that have not been 
> following closely do not this your red text is correct.
>
> IEEE 802.11bt is an approved project to add PQC to 802.11 wireless 
> network standards, which already make use of EAP-TLS. The  Project 
> Authorization Request (PAR) explicitly mentions ML-DSA, ML-KEM and 
> SLH-DSA as examples of PQC algorithms.  The TLS WG has 
> adopted draft-ietf-tls-mldsa, draft-ietf-tls-mlkem, and other 
> algorithm-related I-Ds, which indicates to the rest of the world that 
> PQC algorithm documents are in the works.  On the IETF/IEEE 802 
> coordination call prior to IETF 125, the was a heads up that the WGLC 
> for draft-ietf-tls-mlkem was underway, but it might not achieve rough 
> consensus.  The IEEE 802.11 WG sent a LS to indicate their desire foe 
> the document.  Sending that LS required a formal vote, so your 
> statement is absolutely incorrect.
>
> You can find the approved Project Authorization Request (PAR) for 
> 802.11bt here: 
> https://mentor.ieee.org/802.11/dcn/25/11-25-0958-00-0PQC-draft-p802-11bt-par.pdf

Thanks for the pointer. In my reading, this PDF only establishes their 
transition to PQC, which could very much be hybrids. At best, it seems 
to just have a quick mention of FIPS 203 in "Additional Explanatory 
Notes" and that could be used in hybrid fashion in TLS, no? Am I missing 
something?

Regarding consensus: While the vote to send the LS confirms IEEE’s 
interest in the progress of the draft, does that vote specifically 
endorse an exclusive non-hybrid implementation in TLS? If there is a 
record (e.g., meeting recording, email thread) of technical rationale 
within 802.11 for preferring pure ML-KEM over hybrid, that would be very 
helpful for the WG to see, and maybe use in the draft for motivation.

Thanks.

Best regards,

-Usama