Re: Hybrid PQC: x25519-mlkem fails in openssl 3.5.5 with default provider

murugesh pitchaiah <[email protected]> Sat, 28 Mar 2026 16:38:43 +0530
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <CAOu9RAeqQbvWSs0JKt2PRcQ9rzeXhSUJ8_p2f7Rxux7_BodYgQ@mail.gmail.com>
--000000000000b22ffa064e13a454
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thanks Victor for quick response.

Regards,
Murugesh

On Sat, 28 Mar, 2026, 4:35=E2=80=AFpm Viktor Dukhovni, <openssl-users@dukho=
vni.org>
wrote:

> On Sat, Mar 28, 2026 at 02:37:59PM +0530, murugesh pitchaiah wrote:
>
> > Based on the original implementation in BoringSSL, ported from C++ to C=
,
> > refactored, and integrated into the OpenSSL default and FIPS providers.
> > Including also the X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM102=
4
> > TLS hybrid key post-quantum/classical key agreement schemes.
> >
> > (snip)
> >
> > Does that mean even without explicit group set, it's included already i=
n
> > TLS 1.3 handshake ? For RSA certificate too ?
>
> Yes, and the certificate is irrelevant.  In TLS 1.3 key exchange groups
> are negotiated independently of the certificates.
>
> --
>     Viktor.  =F0=9F=87=BA=F0=9F=87=A6 =D0=A1=D0=BB=D0=B0=D0=B2=D0=B0 =D0=
=A3=D0=BA=D1=80=D0=B0=D1=97=D0=BD=D1=96!
>
> --
> You received this message because you are subscribed to the Google Groups
> "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
> To view this discussion visit
> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/ace170Dd2YS=
U6oN1%40chardros.imrryr.org
> .
>

--=20
You received this message because you are subscribed to the Google Groups "=
openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-users/CAOu9RAeqQbvWSs0JKt2PRcQ9rzeXhSUJ8_p2f7Rxux7_BodYgQ%40mail=
.gmail.com.

--000000000000b22ffa064e13a454
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Thanks Victor for quick=C2=A0response.=C2=A0<div dir=3D"a=
uto"><br></div><div dir=3D"auto">Regards,=C2=A0</div><div dir=3D"auto">Muru=
gesh=C2=A0</div></div><br><div class=3D"gmail_quote gmail_quote_container">=
<div dir=3D"ltr" class=3D"gmail_attr">On Sat, 28 Mar, 2026, 4:35=E2=80=AFpm=
 Viktor Dukhovni, &lt;<a href=3D"mailto:[email protected]">openssl=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quot=
e" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">=
On Sat, Mar 28, 2026 at 02:37:59PM +0530, murugesh pitchaiah wrote:<br>
<br>
&gt; Based on the original implementation in BoringSSL, ported from C++ to =
C,<br>
&gt; refactored, and integrated into the OpenSSL default and FIPS providers=
.<br>
&gt; Including also the X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM10=
24<br>
&gt; TLS hybrid key post-quantum/classical key agreement schemes.<br>
&gt; <br>
&gt; (snip)<br>
&gt; <br>
&gt; Does that mean even without explicit group set, it&#39;s included alre=
ady in<br>
&gt; TLS 1.3 handshake ? For RSA certificate too ?<br>
<br>
Yes, and the certificate is irrelevant.=C2=A0 In TLS 1.3 key exchange group=
s<br>
are negotiated independently of the certificates.<br>
<br>
-- <br>
=C2=A0 =C2=A0 Viktor.=C2=A0 =F0=9F=87=BA=F0=9F=87=A6 =D0=A1=D0=BB=D0=B0=D0=
=B2=D0=B0 =D0=A3=D0=BA=D1=80=D0=B0=D1=97=D0=BD=D1=96!<br>
<br>
-- <br>
You received this message because you are subscribed to the Google Groups &=
quot;openssl-users&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:openssl-users%[email protected]" target=
=3D"_blank" rel=3D"noreferrer">openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org</a>.<b=
r>
To view this discussion visit <a href=3D"https://groups.google.com/a/openss=
l.org/d/msgid/openssl-users/ace170Dd2YSU6oN1%40chardros.imrryr.org" rel=3D"=
noreferrer noreferrer" target=3D"_blank">https://groups.google.com/a/openss=
l.org/d/msgid/openssl-users/ace170Dd2YSU6oN1%40chardros.imrryr.org</a>.<br>
</blockquote></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;openssl-users&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/a/openss=
l.org/d/msgid/openssl-users/CAOu9RAeqQbvWSs0JKt2PRcQ9rzeXhSUJ8_p2f7Rxux7_Bo=
dYgQ%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter">https://group=
s.google.com/a/openssl.org/d/msgid/openssl-users/CAOu9RAeqQbvWSs0JKt2PRcQ9r=
zeXhSUJ8_p2f7Rxux7_BodYgQ%40mail.gmail.com</a>.<br />

--000000000000b22ffa064e13a454--