[TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt> (ML-KEM Post-Quantum Key Agreement for TLS 1.3) to Informat ional RFC

Christian Huitema <[email protected]>
Newsgroups gmane.ietf.tls
Message-ID <[email protected]>
On 8/11/2026 9:18 AM, Nadim Kobeissi wrote:
> Hi DJB,
>
> Sorry, let me try to be more constructive.
>
> I really think that the way you’re communicating your concerns is 
> simply impossible to digest by most of us.

I think deployments now have the choice between "hybrid" and "solo" 
deployments of PQ algorithms. There will be reference documents for 
both. The IETF has expressed a clear preference for hybrids through the 
"preference" flag, and also by pushing the hybrid specification on the 
standard track and the solo specification as an informational document. 
I understand the concern that this may be too subtle, and that many 
would prefer a more forceful way to steer deployments away from the solo 
option. On the other hand, I don't think that belaboring the point in 
e-mail to the TLS working group would achieve that goal of "steering 
deployments away from solo PQ".

If Dan and others do think that there are good arguments to steer 
deployments away from solo PQ, then by all means publish these 
arguments. Nadim suggests using web site or scientific publication, so 
as to obtain a permanent reference. Another possibility would be to 
prepare an RFC explaining the issues with solo PQ. As stated in its web 
site (https://www.rfc-editor.org/authors/rfc-independent-submissions/), 
the Independent Stream covers a number of classes of submissions, 
including discussions of technologies, ... and critiques of the IETF 
process, so I think that would be an appropriate venue. There are also 
examples of such documents in the IETF stream like RFC 8900 (IP 
Fragmentation Considered Fragile), or in the IAB stream like RFC 4840 
(Multiple Encapsulation Methods Considered Harmful), but doing that will 
require consensus within a working group or within the IAB, which may 
delay the publication for some time.

-- Christian Huitema

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.