On Mon, 8 Sept 2025 at 14:29, Douglas Stebila <[email protected]> wrote:

> From a technical perspective I'd like to revisit this point. My memory is
> that the
> plausible KEMs actually have fast key generation, as does EC. Why not just
> keep the requirement as-is?
>
>
> This seems like a sufficiently significant change (on text that has been
> present in the draft since 2020) that I’ll need guidance from the working
> group / chairs on how to proceed.
>
> Do any implementations currently do that?
>

Yes, and we have a writeup of it here --
https://rustls.dev/perf/2024-12-17-pq-kx/

Thanks,
Joe
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to