Hi Eric, Thank you. I addressed them in https://github.com/csosto-pk/pq-mlkem-ikev2/commit/6d0254ffeabe0fdc9654d34ee018559c97823fb1 , in https://github.com/csosto-pk/pq-mlkem-ikev2/commit/30f5e6e8c67712a81eb97ce367e6c29b36d8f055 , and in https://github.com/csosto-pk/pq-mlkem-ikev2/commit/1e2a74c653796248078b72b17be915a291b22643.
-----Original Message----- From: Éric Vyncke via Datatracker <[email protected]> Sent: Tuesday, June 23, 2026 9:53 AM To: The IESG <[email protected]> Cc: [email protected]; [email protected]; [email protected]; [email protected] Subject: [EXTERNAL] [IPsec] Éric Vyncke's Discuss on draft-ietf-ipsecme-ikev2-mlkem-06: (with DISCUSS and COMMENT) CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. Éric Vyncke has entered the following ballot position for draft-ietf-ipsecme-ikev2-mlkem-06: Discuss When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ for more information about how to handle DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-mlkem/ ---------------------------------------------------------------------- DISCUSS: ---------------------------------------------------------------------- # Éric Vyncke INT AD comments for draft-ietf-ipsecme-ikev2-mlkem-06 CC @evyncke Thank you for the work put into this document. Please find below some blocking DISCUSS points (easy to address), some non-blocking COMMENT points/nits (replies would be appreciated even if only for my own education). I hope that this review helps to improve the document, Regards, -éric Note: this ballot comments follow the Markdown syntax of https://github.com/mnot/ietf-comments/tree/main, i.e., they can be processed by a tool to create github issues. ## DISCUSS (blocking) As noted in https://datatracker.ietf.org/doc/statement-iesg-handling-ballot-positions-20220121/, a DISCUSS ballot is a request to have a discussion on the points below; I really think that the document would be improved with a change here, but can be convinced otherwise. ### Section 2.2 The "SHOULD" in `If the checks fail, the responder SHOULD send a Notify payload of type INVALID_SYNTAX as a response to the request from initiator.` misses the additional guidance per https://datatracker.ietf.org/doc/statement-iesg-statement-on-clarifying-the-use-of-bcp-14-key-words/ Adding some text about "preventing DoS" could be the guidance (my guess) The other "SHOULD" in the document have such a guidance. ---------------------------------------------------------------------- COMMENT: ---------------------------------------------------------------------- ## COMMENTS (non-blocking) ### Use of NIST Please do s/NIST/US NIST/g in all occurence. I note that section 1.1 use "US" in the expansion of NIST, so, after this occurence "NIST" can stay unchanged. ### Abstract s/This draft specifies/This *document* specifies/ ### Section 1 s/This document describes how ML-KEM [FIPS203] can be used /This document *specifies* how ML-KEM [FIPS203] can be used / as it is a PS. ### Section 1.1 The curious reader (myself included) would welcome some explanations on the "shared secret(ss)" as it does not appear to be used in this document. ### Section 1.2 There is no such thing as "network MTU" so s/can exceed the network MTU/can exceed the *path* MTU/ (as used further in the text) Later in text s/require two or three *network* IP packets/require two or three IP packets/ (or even "more than 1 IP packet" as the path MTU can be very small in IPv4 ...) ### Section 2.2 Same issue: there is no such thing as "network MTU" so s/network MTU/*path* MTU/ ### Section 4 Please add an informative reference to c _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected] _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
