[TLS] Re: tls-composite-mldsa downgrade to ML-DSA
tirumal reddy <[email protected]>
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <CAFpG3geBpcqDeCopYX5k_Addd9u1TQZg-sWr6pEm9jpPJxV3-w@mail.gmail.com> |
Hi Ilari, Thanks for the feedback. I have updated the draft in PR https://github.com/tireddy2/composite-mldsa/pull/15 to address this scenario. Best Regards, -Tiru On Thu, 6 Aug 2026 at 19:26, Ilari Liusvaara <[email protected]> wrote: > Noticed this when reviewing draft-reddy-tls-composite-mldsa-10: > > While the security considerations does discuss downgrade to traditional > authentication, it does not discuss downgrade to stand-alone ML-DSA. > Such downgrade would be pointless if one fully trusted ML-DSA. However, > the whole point of composite authentication is not to fully trust either > component, so such downgrade needs to be taken into account. > > In general, TLS Relying Party fully trusts any signature algorithm it > accepts. And thus mitigating the issue is up to Relying Party policy. > > I think accepting both composite and stand-alone ML-DSA only makes > sense if composites are being deprecated for stand-alone PQ. This > would mean only deploying composites in closed environments or with > security profile standard. Relying Parties enforce the use of acceptable > algorithms, which has presumably been narrowed to something manageable. > > > > > -Ilari > > _______________________________________________ > TLS mailing list -- [email protected] > To unsubscribe send an email to [email protected] > _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]