I support publication, provided that X25519MLKEM768 is distinguished from the 
others by e.g. recommended=Y, or by not specifying other curves at all.
The traditional reason for the other elliptic curves (government endorsement) 
is less of a concern in combination with MLKEM.

I also support the idea being brought up of offering combinations of/with 
higher presumed security levels such as X448 and/or MLKEM1024, with no comment 
as to which combinations make sense.
That said, I would be fine with adding those in a separate document to not slow 
this one down.

Regarding the potential patent issue, I count on public/industry pressure 
sorting this out if necessary and support adding other PQ KEMs in the future. 
Again, I do not intend to slow this document down.

-- TBB

===== IETF Stuff =====
This document may not be modified, and derivative works of it may not be
created, except to format it for publication as an RFC or to translate it into
languages other than English.

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to