[TLS] Erlang/OTP and Bouncy Castle now supporting SLH-DSA in e nd-entity certificates

John Mattsson <[email protected]>
Newsgroups gmane.ietf.tls
Message-ID <AS2SPRMB00197441178DEE9AFD0F460589DB2@AS2SPRMB0019.eurprd07.prod.outlook.com>
Hi,

We constantly try to maintain an overview of what different TLS libraries support, especially now that we are in the middle of the PQC migration.

While several TLS libraries have supported SLH-DSA in CA certificates for some time, I’m happy to report that both Erlang/OTP [1] and Bouncy Castle now support SLH-DSA as the public key in end-entity certificates. They also support ML-DSA and ML-KEM. SLH-DSA performance is adequate for all of our telecom use cases.

Have I missed any other TLS libraries with comparable support?

Given the risk of potential future attacks against lattice-based schemes such as the one discussed in [2], I believe all TLS libraries should support SLH-DSA and HQC-KEM. Note that PQ/T hybrids do not help at all.

Cheers,
John Preuß Mattsson

[1] https://www.erlang.org/

[2] https://eprint.iacr.org/2026/1591

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.