[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Flo D <Flo.D@ncsc.gov.uk> Mon, 29 June 2026 14:43 UTC

Return-Path: <Flo.D@ncsc.gov.uk>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 0D999109E0BAF; Mon, 29 Jun 2026 07:43:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782744186; bh=v/1C4aqTgfuuJQA8TgB6adlEjOVXFixpUXzzFQKf7BU=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=bJGtWRt5fwKtICJfq9X/U8f5we5bkEBpArLLwc+dwAC94mQgyXzncYGNRgJYODYdL jCyy4cyxn0SE8ivAwcS1wbBxzaJWZXhft5rK0LYz6M4VOYRE5MkfU9ijbUIqjcagsf 9op6pUpEIPCAjDM+23nHIjgKpy1z85w4IO06SMgo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_GOV_DKIM_AU=-0.001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ncsc.gov.uk
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G5jBkrWHx4Fq; Mon, 29 Jun 2026 07:43:05 -0700 (PDT)
Received: from CWXP265CU009.outbound.protection.outlook.com (mail-ukwestazon11011046.outbound.protection.outlook.com [52.101.100.46]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id A509B109E09EF; Mon, 29 Jun 2026 07:42:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Alc2dQ1iBJVMHSt4/YIqN3P2kOi98Thp4bsZU+7RMrYzFOAzFFyoyFxbmngXA9aoW+5Z3V6a2zyeREWktmXciDNQ1nr3t7xsgWbVjdv8Hh5AFfb5T0UJw9TuAqLXg2pHgex23oqyZkp8IdEvyniSuAq3g0nmMj/vycgBJMyvKWXA6xEx7dNc+pEZ8ruB/AyBs4ITUeGyJNO5AmLAJMr3Dn+EDUCoo6OS1+q98B2MZkdcidxiTBtxX2HoA6DIL4XzEC4f6GZa0o3fiS138pshEK+IJXLFi6ls/ghJJLvevHAodFTYiu6IlMod/onz1uNvEklcdZg0vaCB68kDp1Snpg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:MIME-Version; bh=lQXNfggyXFKQbUy3uzi2FL4SfAovAlWIqBQ/SE+Ltyc=; b=YflgYhSvCVnkF5ndAoAnnX8Q6MM5sAB0VtYnpg0A8x5YDdfeSlOVLA8Z6uc6q9Z5ws9jWGnHm8+YZxrYEtEvoMRCwUd9ILyornZVh5bUZXspcywfwENLpCV8Ywz8JXK4J0Sl/SLMb7w1elpqSRouVXIVJLNjfSjnspwyqJ6LevYXsaGM4hHQEwYFZtm0U6yOz/sJ37PRnDF9v4j673pyKMoVUjdDz8jDSVPOK6WX9UODGsElru6/QYyof6K6PSFVf5ydz773v6OXjxxddkeSZt+d3MvI2KRTY8ASKB+8wa26LIbUAzV/up42w6sdH97SZM0SW0IoWi2j/3i8wgTGvg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ncsc.gov.uk; dmarc=pass action=none header.from=ncsc.gov.uk; dkim=pass header.d=ncsc.gov.uk; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ncsc.gov.uk; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=lQXNfggyXFKQbUy3uzi2FL4SfAovAlWIqBQ/SE+Ltyc=; b=r8aOnuYDn2R3vC4ULIq7fHV5RGwN+y4iTdtcUbuptDC1gSSnn3zMO/UVdFpm7/1nmw8GVWhTRsWpsr0R4YybY5rp4bJko9Xb6dnPBE3GM9LcbAUv/xPrCNRGRDtJBlmFnUTw08foPp2qlb3d0c86Uw7UeWv0G1IBaRy4XFpPomwXaOFXCT/xVxMznd+YtMBZzlSkiqV96KqFndyAwuhhjJbD2I61l7zisePEVncX7p66Dd/Z2Q3bSzUoj2tz+le/M9QuvYqzLJctG1wubIHemVZguuJ0dsKG+fpM0QwbZcbyWe0pwRzgF6Bu89zGINZKbB1ZDLnJ7Q9uloHt6GZDKQ==
Received: from LO2P123MB5158.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:1d7::13) by CW1P123MB7930.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:244::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.159.19; Mon, 29 Jun 2026 14:41:58 +0000
Received: from LO2P123MB5158.GBRP123.PROD.OUTLOOK.COM ([fe80::14d2:1977:2591:c914]) by LO2P123MB5158.GBRP123.PROD.OUTLOOK.COM ([fe80::14d2:1977:2591:c914%6]) with mapi id 15.21.0159.018; Mon, 29 Jun 2026 14:41:58 +0000
From: Flo D <Flo.D@ncsc.gov.uk>
To: Joseph Salowey <joe@salowey.net>, "tls@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
Thread-Index: AQHdA+pr5IrCFySO9UeOzphmg4q4ibZVopLQ
Date: Mon, 29 Jun 2026 14:41:58 +0000
Message-ID: <LO2P123MB515806E3D3EC8DC2BC5EBB3EA8E82@LO2P123MB5158.GBRP123.PROD.OUTLOOK.COM>
References: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg>
In-Reply-To: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg>
Accept-Language: en-US, en-GB
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_baa80bfd-e3bf-43fd-adc3-f03d6b80e814_ActionId=4e552582-58f5-4278-b272-4134a60f4828;MSIP_Label_baa80bfd-e3bf-43fd-adc3-f03d6b80e814_ContentBits=0;MSIP_Label_baa80bfd-e3bf-43fd-adc3-f03d6b80e814_Enabled=true;MSIP_Label_baa80bfd-e3bf-43fd-adc3-f03d6b80e814_Method=Privileged;MSIP_Label_baa80bfd-e3bf-43fd-adc3-f03d6b80e814_Name=OFFICIAL-UNMARKED;MSIP_Label_baa80bfd-e3bf-43fd-adc3-f03d6b80e814_SetDate=2026-06-29T14:40:23Z;MSIP_Label_baa80bfd-e3bf-43fd-adc3-f03d6b80e814_SiteId=14aa5744-ece1-474e-a2d7-34f46dda64a1;MSIP_Label_baa80bfd-e3bf-43fd-adc3-f03d6b80e814_Tag=10, 0, 1, 1;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ncsc.gov.uk;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: LO2P123MB5158:EE_|CW1P123MB7930:EE_
x-ms-office365-filtering-correlation-id: 843c83ae-5382-484b-2a93-08ded5ec92d6
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|23010399003|19092799006|4022899009|376014|42112799006|18002099003|22082099003|38070700021|11063799006|56012099006|6133799003|4133799003;
x-microsoft-antispam-message-info: yDWjMt1LWfzzP0SZCz4Qp+GXiExzx5cyC3zP5p50OK9GkoR28BOx5mfxUfoTMLtLOSCXi/hwmXv7z+Q9pc/kTM7pd2J+65ZNsLYGhNekvJpstk3GqvsFeND+mevFnWdH/OvMtq7d5xh+B7/XcX2yyW0T4TtNJ2GgTq4rI7bU8iT6YYjkzFj3MPD4YVFgETpdbjKwKFrYTj325vQfok7/PMItQDWXrEe6aau3QHWIupbVj+2sNwu2PRgEsu6pLHjOErc/1qWf8RGO/DE8PAFxVRtPnIBA28uaovvKvRsNPSGdzGDPQKnjDbSIq1rWOHa9k/8zIUru7HnvB3MOlCPfGVkPLM2oFo5ovyhr6373dZ0M8+ICRQ7issX9GHW8CBl3+LQ+MJof0vo7uIGN9bKcVXf9ejlh4F1HZeZbJR56mr/p1g5UWCZu5S4mNs6WLKO2fAge5Dh+fhLMqO1/euQpa4b4SAj8cjwnHJXI4zKzNxpRs9H/QkTxHQX89bD++F8FWyxRmBkBBpdEP4eRpnur49n7H4q8bZPvy7FXsi1iLyqP0bIFvJpdy1WYOColhKkkycdfrchmTrBVTQb4D4H0JhNAGVEd0Wnra9hHrIkY398MdARLB3rYzraZ1PHpli4ysWT16kXh+WKbQmGlZDbGriB8ydZXJ85ZXNiMkiOVIfwWKphi5Jtt2414UPwpttpfqU8V7BgElj5Ml6wO5bfKHc9umfDUvRWiXl+V8Z0uQ+M=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:LO2P123MB5158.GBRP123.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(23010399003)(19092799006)(4022899009)(376014)(42112799006)(18002099003)(22082099003)(38070700021)(11063799006)(56012099006)(6133799003)(4133799003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: +VWY/fS/Ycv8AzU303HxKjHoaqkVWQpmw4gMX1G42o7SpsSdVuOOB2MDapOLuwbgApDxqA6WJp3Uqw3bpNXEoiCKnK2XSMrXkg2aLmkIgMlbL5CXrl35nuzPb061iU46VPxmPzHE9tFfLi8eL53O4RkAtZKeDTZ1mZEJsg4UlWSh+GRCw5e15mNAGRnBhFXYJ5npXuHYR7l3JDE1jCVIBg59WjSY2yDEJjf8yPkUM3eDid6yvj3vh8oWvCWFRHcbSMWpnPPZp6VSdn6r4yjgJWc9FTe1pDI+zmIRxNxV7wR3p26T7lMZG97LF3ci/0kr/mnoKxQi1PLhf0O7qxc87xgrsl07OEJdfKA8B9asvNycp/qAQ5wkhYftjc+0dTOuvClPLO8vHm+hmZ94ANK5UgNeS+tRMYvkzKXxW+64rqHkLoo+Kfq5z8subxycQVVJdN+Jtz6v6zK45U+svZUSiLdXLXjZ4y8cNY4UEpZEqJopa86TiMswr0ieDQG+ecelV9f6zMnkDsi/Jzq5V8Bg8vTlHBYCtksSzREtRVkCiAKR0d9Qxy1A0Kh26+H78tsW5TvM6oiiBrOAtlv7saaj4JHFJG26W6TwFyK2xcabkt1BYfgE7bNIp8rrwYH+yetJTKuZdiwAJG59MMw/m2byNTnCcmdAMINthjvpNtjrponuFxAih6FCnHGN3svtGmBjyz2zwrlA5OTokq5TxHbPfEpcCL9+ryvHJYwCWPLt7dvxYgzZnrh6t8QPd4WsJnCj8hTE90WJhrp/SEusZTyLRjzRgDxgvEAI0TJiUpvRiG5Yh2K0iGBQWQkkEM8yI3QO5Pc4xS6wB6XVAisPWCd24hgPOL0bbg1B3nLs/1K6bnzSS7R158xoV7yaQ8S2HpFbohYPeTh6FSAOINBIR51Gvm6ONWntlfUx+lirKFZqoCcL5GT+Jck4YSqnpeWIetnQ/k/SW2bq9Ah5deeyTLdpk3o9gA+zauO4Mh2W5rjsvUTLnBeY1JNC7MrYBrY0cuDV/B2dliSNVn0JMZ3EfTQKzYmq7ykbn5QbqyIDeSGMkbnNOzPe2JE8l+QU3nmonNC/s7KzXfaVvqsUbXJ1nlAWw2d5eQihVsf0/AzuDNceBfiqvj7WxwOshipZaDjYxQNN5g8m4p8A/Jq+lFAxsIMWkidW0BcJPcQQM/FjKfiZL4PVCAmry6RSymnfLfLzszTEl07ezgFsCbZUiE9Ws6pJKXU2ddQYi20DzOcFvC10wjuCblmMUaS6Ix07EqLOzJQjml6n9woFsMLDTLvif+Y50CY0DNlp6W8C9qopMNLw5U03dUVhKNIPCsG00AFedyquAKud53NgIfNdrSbYg7CNPYMOviGEPFQgaTQw7tfYeASCUg6jTh9SMr/X2omtgFGTVtfN2AJT18pskqi0BFdpeOymRhlymekI3RSVbHe8xaCPVG7LLk7c7S875RQTa0a4x3dSmhDLatm6qovfwwWtGrxAfWjNUfh6dkWTQVSCl5H4RWH0ZRK+d8gky3fusW5+UPGAJ0HEgAnnXrCwwtnMq6B0Ais2WAeAOu1KBpGnU9BUuZYr/m8ocsbnfc38WukJTKEqY6wSkk1qTQgXVS58cQaOXk67nb3mW0RxfJ7sJKmlimUNN7o5ceKNEJN1PGXS3ilICHfaoa5bRdP+qd1au2bqHbyeynoZ+cb6duh4joTanV1uHo+lC7FOI9VIA4y+HRNBzKPcJDvG7nT+YLDkeQ==
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: ncsc.gov.uk
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: LO2P123MB5158.GBRP123.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 843c83ae-5382-484b-2a93-08ded5ec92d6
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Jun 2026 14:41:58.5024 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 14aa5744-ece1-474e-a2d7-34f46dda64a1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: rrCkcnTJT+DVCQ7rEkB5hqztw2Js/GBRomFsjBVHN+MxhnGxjkZP7kmoxcW+2QzBeJ2ED3U+wlinMzdd3ZTejLzYKrNz7viAV/4kpCE8f0k=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CW1P123MB7930
Message-ID-Hash: 6XKKBTPQ7GE5HKAIX5CJT2N7QCW25CUZ
X-Message-ID-Hash: 6XKKBTPQ7GE5HKAIX5CJT2N7QCW25CUZ
X-MailFrom: Flo.D@ncsc.gov.uk
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "tls-chairs@ietf.org" <tls-chairs@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/muKBRDoLZ1vdnQe_SIKfcBjBkr8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hi,

I support publication of this document.  I've supported this document in previous last calls but wanted to join this one for clarity.

NCSC's position is that system owners should be able to consider the pros and cons of using a PQ/T hybrid vs. using a PQC only scheme, and make the deployment choice that is right for them.  We would also like to be able to recommend use of RFCs rather than draft standards in operational systems, as this is clear and consistent for those reading our guidance.  As such, I am in favour of this document being published as an RFC.

Flo

-----Original Message-----
From: Joseph Salowey via Datatracker <noreply@ietf.org>
Sent: 24 June 2026 16:00
To: draft-ietf-tls-mlkem@ietf.org; tls-chairs@ietf.org; tls@ietf.org
Subject: [TLS] WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

This message initiates a new Working Group Last Call for draft-ietf-tls-mlkem[1], which defines standalone ML-KEM key establishment for TLS 1.3. The main question before the working group is: "Should the working group publish a document specifying stand alone ML-KEM?". If there is rough consensus then we will push to refine and publish the document; otherwise, we will stop discussing the draft and not progress it. Please respond to this call indicating whether you support publishing a document specifying a stand alone ML-KEM. Please refrain from further discussion on this topic as most arguments have been discussed multiple times.

Why are we holding this consensus call now?

Significant developments have occurred both within this document and in the broader TLS ecosystem to address the concerns raised in the last WGLC. Therefore, the third consensus call is warranted. We ask the working group to consider document publication in light of these recent changes:

- Promotion of Hybrids in draft-ietf-tls-ecdhe-mlkem: Following a separate consensus call, the WG agreed to promote the X25519MLKEM768 hybrid group to Recommended: Y in the IANA registry. Consequently, the IANA registry will reflect a clear community preference for a hybrid because Recommended: Y clearly indicates this while the standalone ML-KEM groups defined in this draft remain Recommended: N. The updated security considerations in [1] reference the IANA registry to emphasize this preference.

- Key Share Reuse Prohibited in draft-ietf-tls-rfc8446bis: The WG recently reached consensus to explicitly prohibit key share reuse across connections in TLS 1.3. The new text changes the guidance from SHOULD NOT to a strict MUST NOT. This resolves the concerns regarding static key reuse and its associated privacy and forward-secrecy risks for ML-KEM.

- Nadim updated the ProVerif model of TLS 1.3 to evaluate KEM and hybrid KEM groups in TLS 1.3. This supports other results which show that KEMs are secure when used in TLS 1.3 and that hybrid groups are secure even if one of the components is compromised.

- Liaisons: We received liaison statements from multiple SDOs including  O-RAN[2], IEEE 802.11[4] and from 3GPP[3]  expressing support for the publication of draft-ietf-tls-mlkem as an RFC as they rely on the IETF to provide a stable normative reference.

Please note that a third-party IPR disclosure exists [5] against this document regarding patents related to the underlying ML-KEM algorithm. This IPR declaration has not changed since the last WGLC. As a reminder, per BCP 79, the IETF takes no stance on the validity of patent claims, and the working group may decide to proceed with a technology despite IPR disclosures if it decides that such use is warranted.

Conduct Reminder: Given the heated nature of previous discussions on this topic, participants are strongly reminded to adhere to the IETF Code of Conduct (BCP 54) and the TLS WG's Mail List Procedures. Keep feedback professional, technical, and focused on the document's text.

This working group last call will end on 2026-07-08.

Joe and Sean

[1] https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/
[2] https://datatracker.ietf.org/liaison/2198/
[3] https://datatracker.ietf.org/liaison/2151/
[4] https://datatracker.ietf.org/liaison/2148/
[5] https://datatracker.ietf.org/ipr/search/?submit=draft&id=draft-ietf-tls-mlkem

_______________________________________________
TLS mailing list -- tls@ietf.org
To unsubscribe send an email to tls-leave@ietf.org