[TLS] Re: [EXTERNAL] Erlang/OTP and Bouncy Castle now su pporting SLH-DSA in end-entity certificates
"Dang, Quynh H. \(Fed\)" <[email protected]>
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <MW4PR09MB10059FEE9E8A62E42693A8FD2F3A72@MW4PR09MB10059.namprd09.prod.outlook.com> |
Hi all, There is an on-going discussion of the paper mentioned in the email below at https://discord.com/channels/1229434220154196008/1234415342634143796 . A new paper with the title "The ePrint:2026/1591 Quantum Algorithm Does Not Solve DCP" has been published at https://eprint.iacr.org/2026/1693 . Regards, Quynh. From: John Mattsson <[email protected]> Sent: Thursday, August 13, 2026 6:34 AM To: <[email protected]> <[email protected]> Subject: [EXTERNAL] [TLS] Erlang/OTP and Bouncy Castle now supporting SLH-DSA in end-entity certificates Hi, We constantly try to maintain an overview of what different TLS libraries support, especially now that we are in the middle of the PQC migration. While several TLS libraries have supported SLH-DSA in CA certificates for some time, I'm happy to report that both Erlang/OTP [1] and Bouncy Castle now support SLH-DSA as the public key in end-entity certificates. They also support ML-DSA and ML-KEM. SLH-DSA performance is adequate for all of our telecom use cases. Have I missed any other TLS libraries with comparable support? Given the risk of potential future attacks against lattice-based schemes such as the one discussed in [2], I believe all TLS libraries should support SLH-DSA and HQC-KEM. Note that PQ/T hybrids do not help at all. Cheers, John Preuß Mattsson [1] https://www.erlang.org/ [2] https://eprint.iacr.org/2026/1591 _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]