Joseph Salowey <[email protected]> wrote:
> This is the working group last call for Post-quantum hybrid ECDHE-MLKEM Key
> Agreement for TLSv1.3. Please review draft-ietf-tls-ecdhe-mlkem [1] and
> reply to this thread indicating if you think it is ready for publication or
> not.

I think the document should move forward, but I would
favor marking X25519MLKEM768 as Recommended=Y.

(Given that P-256 and P-384 are each marked
Recommended=Y on their own, I also think it'd be
reasonable to mark the hybrid SecP256r1MLKEM768 and
SecP384r1MLKEM1024 as Recommended=Y.

That is, I don't think I can follow a logic that says
X25519MLKEM768 should be recommended, but not the
others (unless one were to imply that standalone P-256
and P-384 should not be recommended).

But solving the question of these two variants needn't
hold up progress.)

-Jan

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to