[TLS] Re: tls-composite-mldsa downgrade to ML-DSA

tirumal reddy <[email protected]>
Newsgroups gmane.ietf.tls
Message-ID <CAFpG3geBpcqDeCopYX5k_Addd9u1TQZg-sWr6pEm9jpPJxV3-w@mail.gmail.com>
Hi Ilari,

Thanks for the feedback. I have updated the draft in PR
https://github.com/tireddy2/composite-mldsa/pull/15 to address this
scenario.

Best Regards,
-Tiru
On Thu, 6 Aug 2026 at 19:26, Ilari Liusvaara <[email protected]>
wrote:

> Noticed this when reviewing draft-reddy-tls-composite-mldsa-10:
>
> While the security considerations does discuss downgrade to traditional
> authentication, it does not discuss downgrade to stand-alone ML-DSA.
> Such downgrade would be pointless if one fully trusted ML-DSA. However,
> the whole point of composite authentication is not to fully trust either
> component, so such downgrade needs to be taken into account.
>
> In general, TLS Relying Party fully trusts any signature algorithm it
> accepts. And thus mitigating the issue is up to Relying Party policy.
>
> I think accepting both composite and stand-alone ML-DSA only makes
> sense if composites are being deprecated for stand-alone PQ. This
> would mean only deploying composites in closed environments or with
> security profile standard. Relying Parties enforce the use of acceptable
> algorithms, which has presumably been narrowed to something manageable.
>
>
>
>
> -Ilari
>
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.