[saag] Re: [EXTERNAL] Re: NIST Requests Comments on SP 800-52 Rev. 2 | Selection, Configuration, and Use of TLS Implementations

Eric Rescorla <[email protected]> Tue, 2 Jun 2026 14:15:55 -0700
Newsgroups gmane.ietf.saag
Message-ID <CABcZeBOgziEy3sYPp-QxabkHy9moGu8_dV1NY=YuTJz6hHQ5_Q@mail.gmail.com>
--===============5213599017843438090==
Content-Type: multipart/alternative; boundary="00000000000040bbe806534bd3d9"

--00000000000040bbe806534bd3d9
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thanks. That helps.


On Tue, Jun 2, 2026 at 10:38=E2=80=AFAM Dang, Quynh H. (Fed) <quynh.dang@ni=
st.gov>
wrote:

> Hi Eric,
>
>
>
> The document will be updated to incorporate advancements of the last 7
> years, including the recent Internet Engineering Task Force (IETF) drafts
> on TLS 1.3. We are planning to reduce the recommendation for TLS 1.2
> support from =E2=80=9Cshould=E2=80=9D to =E2=80=9Cmay=E2=80=9D and removi=
ng conditional allowances for TLS
> 1.0 and 1.1. To help us evaluate whether these changes to version
> recommendations are acceptable, we seek feedback on the following areas o=
f
> particular concern:
>
>
>
>    1. Is there a strong reason for NIST to continue to recommend that
>    servers *should *support TLS 1.2, or can the recommendation be changed
>    such that servers *may *support TLS 1.2?
>
> I think this should say "MAY". As a practical matter, you want to deploy
PQ ASAP and that means TLS 1.3.



>    1.
>    2. Is there a compelling reason to conditionally allow support for TLS
>    1.0 or TLS 1.1 if the system administrator determines that it is neces=
sary?
>
> I agree with what I understand John Mattsson to be saying that you should
not allow this.

-Ekr


>
>    1.
>
>
>
> We plan to align our PQC cipher suite recommendations with the general PQ=
C
> guidance presented in NISTIR 8547 (
> https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf ), or any
> in any superseding document. The current recommendation is to complete
> migration to PQ security by the end of 2035.
>
>
>
> Regards,
>
> Quynh.
>
>
>
> *From:* Eric Rescorla <[email protected]>
> *Sent:* Monday, June 1, 2026 6:46 PM
> *To:* Dang, Quynh H. (Fed) <[email protected]>
> *Cc:* IETF SAAG <[email protected]>
> *Subject:* [EXTERNAL] Re: [saag] NIST Requests Comments on SP 800-52 Rev.
> 2 | Selection, Configuration, and Use of TLS Implementations
>
>
>
> Hi Quynh,
>
>
>
> Are you able to advise on this question?
>
>
>
> Thanks,
>
> -Ekr
>
>
>
>
>
> On Thu, May 7, 2026 at 2:11=E2=80=AFPM Eric Rescorla <[email protected]> wrote=
:
>
> Hi Quynh,
>
>
>
> I started looking at this document and I wanted to level set on
> expectations.
>
>
>
> The latest version of this document is from 2019 and it really is in
> fairly bad need of  revision beyond the questions asked on the NIST page.
>
>
>
> Is there some plan to do that? If so, can you share that plan, including
> the timeline? Otherwise I fear that we're going to be making a lot of
> duplicative comments. For example, I would expect everyone to suggest tha=
t
> you recommend if not require PQ algorithms.
>
>
>
> -Ekr
>
>
>
>
>
> On Thu, May 7, 2026 at 10:11=E2=80=AFAM Dang, Quynh H. (Fed) <quynh.dang=
=3D
> [email protected]> wrote:
>
> Hi SAAG members,
>
>
>
> We have posted a request of comments on SP 800-52 Rev. 2 | Selection,
> Configuration, and Use of TLS Implementations at
> https://csrc.nist.gov/news/2026/tls-comment-on-sp-800-52-rev-2 .
>
>
>
> The comment period is open through July 10th, 2026.
>
>
>
> Regards,
>
> Quynh Dang.
>
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
>

--00000000000040bbe806534bd3d9
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div>Thanks. That helps.</div><div><br></=
div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On=
 Tue, Jun 2, 2026 at 10:38=E2=80=AFAM Dang, Quynh H. (Fed) &lt;<a href=3D"m=
ailto:[email protected]" target=3D"_blank">[email protected]</a>&gt; wr=
ote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px=
 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>





<div lang=3D"EN-US">
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">Hi Eric,<u></u><u></u=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt"><u></u>=C2=A0<u></u><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"color:black">The document will be upd=
ated to incorporate advancements of the last 7 years, including
</span><span style=3D"font-size:10.5pt;font-family:&quot;Helvetica&quot;,sa=
ns-serif">the recent Internet Engineering Task Force (IETF) drafts on TLS 1=
.3. We are planning to reduce=C2=A0the recommendation for TLS 1.2 support f=
rom =E2=80=9Cshould=E2=80=9D=C2=A0to =E2=80=9Cmay=E2=80=9D=C2=A0and removin=
g conditional allowances
 for TLS 1.0 and 1.1. To help us evaluate whether these changes to version =
recommendations are acceptable, we seek feedback on the following areas of =
particular concern:<span style=3D"color:black">=C2=A0</span></span><u></u><=
u></u></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;He=
lvetica&quot;,sans-serif;color:black">=C2=A0</span><u></u><u></u></p>
<ol style=3D"margin-top:0in" start=3D"1" type=3D"1">
<li class=3D"MsoNormal" style=3D"color:black;margin-bottom:5.25pt">
<span style=3D"font-size:10.5pt;font-family:&quot;Helvetica&quot;,sans-seri=
f">Is there a strong reason for NIST to continue to recommend that servers
<i>should </i>support TLS 1.2, or can the recommendation be changed such th=
at servers
<i>may </i>support TLS 1.2?</span></li></ol></div></div></div></blockquote>=
<div>I think this should say &quot;MAY&quot;.=C2=A0As a practical matter, y=
ou want to deploy PQ ASAP and that means TLS 1.3.</div><div>=C2=A0</div><di=
v><br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0=
.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><div lan=
g=3D"EN-US"><div><ol style=3D"margin-top:0in" start=3D"1" type=3D"1"><li cl=
ass=3D"MsoNormal" style=3D"color:black;margin-bottom:5.25pt"><u></u></li><l=
i class=3D"MsoNormal" style=3D"color:black;margin-bottom:5.25pt">
<span style=3D"font-size:10.5pt;font-family:&quot;Helvetica&quot;,sans-seri=
f">Is there a compelling reason to conditionally allow support for TLS 1.0 =
or TLS 1.1 if the system administrator determines that it is necessary?</sp=
an><u></u><u></u></li></ol></div></div></div></blockquote><div>I agree with=
 what I understand John Mattsson to be saying that you should not allow thi=
s.</div><div><br></div><div>-Ekr</div><div>=C2=A0</div><blockquote class=3D=
"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(2=
04,204,204);padding-left:1ex"><div><div lang=3D"EN-US"><div><ol style=3D"ma=
rgin-top:0in" start=3D"1" type=3D"1"><li class=3D"MsoNormal" style=3D"color=
:black;margin-bottom:5.25pt"><u></u></li></ol>
<p class=3D"MsoNormal" style=3D"margin-bottom:5.25pt"><span style=3D"font-s=
ize:10.5pt;font-family:&quot;Helvetica&quot;,sans-serif;color:black">=C2=A0=
</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;He=
lvetica&quot;,sans-serif;color:black">We plan to align our PQC cipher suite=
 recommendations with the general PQC guidance presented in NISTIR 8547 (<a=
 href=3D"https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf" ta=
rget=3D"_blank">https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.=
pdf</a>
 ), or any in any superseding document. The current recommendation is to co=
mplete migration to PQ security by the end of 2035.<u></u><u></u></span></p=
>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;He=
lvetica&quot;,sans-serif;color:black"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;He=
lvetica&quot;,sans-serif;color:black">Regards,<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.5pt;font-family:&quot;He=
lvetica&quot;,sans-serif;color:black">Quynh.
</span><span style=3D"color:black"><u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt"><u></u>=C2=A0<u></u><=
/span></p>
<div style=3D"border-width:medium medium medium 1.5pt;border-style:none non=
e none solid;border-color:currentcolor currentcolor currentcolor blue;paddi=
ng:0in 0in 0in 4pt">
<div>
<div style=3D"border-width:1pt medium medium;border-style:solid none none;b=
order-color:rgb(225,225,225) currentcolor currentcolor;padding:3pt 0in 0in"=
>
<p class=3D"MsoNormal"><b><span style=3D"font-size:11pt;font-family:&quot;C=
alibri&quot;,sans-serif">From:</span></b><span style=3D"font-size:11pt;font=
-family:&quot;Calibri&quot;,sans-serif"> Eric Rescorla &lt;<a href=3D"mailt=
o:[email protected]" target=3D"_blank">[email protected]</a>&gt;
<br>
<b>Sent:</b> Monday, June 1, 2026 6:46 PM<br>
<b>To:</b> Dang, Quynh H. (Fed) &lt;<a href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a>&gt;<br>
<b>Cc:</b> IETF SAAG &lt;<a href=3D"mailto:[email protected]" target=3D"_blank"=
>[email protected]</a>&gt;<br>
<b>Subject:</b> [EXTERNAL] Re: [saag] NIST Requests Comments on SP 800-52 R=
ev. 2 | Selection, Configuration, and Use of TLS Implementations<u></u><u><=
/u></span></p>
</div>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<div>
<p class=3D"MsoNormal">Hi Quynh,<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Are you able to advise on this question?<u></u><u></=
u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Thanks,<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">-Ekr<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<div>
<p class=3D"MsoNormal">On Thu, May 7, 2026 at 2:11<span style=3D"font-famil=
y:&quot;Arial&quot;,sans-serif">=E2=80=AF</span>PM Eric Rescorla &lt;<a hre=
f=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt; wrote:<u><=
/u><u></u></p>
</div>
<blockquote style=3D"border-width:medium medium medium 1pt;border-style:non=
e none none solid;border-color:currentcolor currentcolor currentcolor rgb(2=
04,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class=3D"MsoNormal">Hi Quynh,<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">I started looking at this document and I wanted=C2=
=A0to level set on expectations.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">The latest version of this document is from 2019 and=
 it really is in fairly bad need of=C2=A0 revision beyond the questions ask=
ed on the NIST page.=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Is there some plan to do that? If so, can you share =
that plan, including the timeline? Otherwise I fear that we&#39;re going to=
 be making a lot of duplicative comments. For example, I would=C2=A0expect =
everyone=C2=A0to suggest that you recommend=C2=A0if not
 require PQ algorithms.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">-Ekr<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<div>
<p class=3D"MsoNormal">On Thu, May 7, 2026 at 10:11<span style=3D"font-fami=
ly:&quot;Arial&quot;,sans-serif">=E2=80=AF</span>AM Dang, Quynh H. (Fed) &l=
t;quynh.dang=3D<a href=3D"mailto:[email protected]" target=3D"_blan=
k">[email protected]</a>&gt; wrote:<u></u><u></u></p>
</div>
<blockquote style=3D"border-width:medium medium medium 1pt;border-style:non=
e none none solid;border-color:currentcolor currentcolor currentcolor rgb(2=
04,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<div>
<p class=3D"MsoNormal">Hi SAAG members,
<u></u><u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<p class=3D"MsoNormal">We have posted a request of comments on SP 800-52 Re=
v. 2 | Selection, Configuration, and Use of TLS Implementations at
<a href=3D"https://csrc.nist.gov/news/2026/tls-comment-on-sp-800-52-rev-2" =
target=3D"_blank">
https://csrc.nist.gov/news/2026/tls-comment-on-sp-800-52-rev-2</a> . <u></u=
><u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<p class=3D"MsoNormal">The comment period is open through July 10th, 2026.<=
u></u><u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<p class=3D"MsoNormal">Regards,<u></u><u></u></p>
<p class=3D"MsoNormal">Quynh Dang.
<u></u><u></u></p>
</div>
</div>
<p class=3D"MsoNormal">_______________________________________________<br>
saag mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">saa=
[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" targ=
et=3D"_blank">
[email protected]</a><u></u><u></u></p>
</div>
</blockquote>
</div>
</blockquote>
</div>
</div>
</div>
</div>

</div></blockquote></div></div>
</div>

--00000000000040bbe806534bd3d9--


--===============5213599017843438090==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2FhZyBtYWls
aW5nIGxpc3QgLS0gc2FhZ0BpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHNhYWctbGVhdmVAaWV0Zi5vcmcK

--===============5213599017843438090==--