[TLS] Re: [EXT] Re: MLKEM Consensus Call (was WG Las t Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08))

"Blumenthal, Uri - 0553 - MITLL" <[email protected]> Mon, 20 Jul 2026 00:36:58 +0000
Newsgroups gmane.ietf.tls
Message-ID <BN0P110MB141939C541783675A47A44B190C3A@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM>
> Given the proposed solution with the addendum of Joe, I like to comment
> the following:
>
> * The risk mitigation taken (given the PRNG) relies on paper-work only.


The risk mitigation taken relies on the common sense (I know, in short supply now), and adherence to the standards. I.e., if it says “use NIST-blessed DRBG”, the implementation SHALL use it.


Otherwise, if you assume that part of the standard will be ignored — why would other parts of that standard or your RFC be followed correctly?

> * The risk mitigation does not necessarily require an implementation
> (though possible, cheap, and easy).


It merely requires the implementation to abide by the letter of the standards it claims to implement. Not a rocket science/

> PPS: I will shut my mouth now and go back to work (Joe).

Thank you (and others who’d hopefully follow your example) kindly!

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/x-pkcs7-signature, 8 KB) - not displayed