I have read the document, and I support publication.

That said, I think that a few things can be improved. Both ML-DSA and SLH-DSA 
offer deterministic and hedged signing modes. The negotiation does not pick one 
of these signing modes because the verifier does not know and does not need to 
know which mode was used.  I think the document should state this fact.

FIPS204 defines both a pure and a pre-hash variant of ML-DSA; however, RFC 9881 
specifies only the pure variant. As a result, there are no OIDs available for 
the negotiation of pre-hash variant of ML-DSA. I think the discussion of the 
pre-hash variant of ML-DSA should be removed since it cannot be negotiated.

None of the signature algorithms offered in the document are hybrid; they are 
all pure. I think the discussion of hybrid terminology should be removed since 
it is not relevant to theML-DSA or SLH-DSA.

Russ

P.S. I checked the hex strings for the OIDs in Appendix B, and they are correct.


> On Jul 10, 2026, at 11:50 AM, The IESG <[email protected]> wrote:
> 
> 
> The IESG has received a request from the IP Security Maintenance and
> Extensions WG (ipsecme) to consider the following document: - 'Signature
> Authentication in the Internet Key Exchange Version 2
>   (IKEv2) using PQC'
>  <draft-ietf-ipsecme-ikev2-pqc-auth-09.txt> as Proposed Standard
> 
> The IESG plans to make a decision in the next few weeks, and solicits final
> comments on this action. Please send substantive comments to the
> [email protected] mailing lists by 2026-07-31. Exceptionally, comments may
> be sent to [email protected] instead. In either case, please retain the beginning
> of the Subject line to allow automated sorting.
> 
> Abstract
> 
> 
>   Signature-based authentication methods are utilized in the Internet
>   Key Exchange Version 2 (IKEv2).  The current version of the IKEv2
>   protocol, specified in RFC 7296, supports traditional digital
>   signatures.
> 
>   This document specifies a generic mechanism for integrating post-
>   quantum cryptographic (PQC) digital signature algorithms into the
>   IKEv2 protocol.  The approach allows for seamless inclusion of any
>   PQC signature scheme within the existing authentication framework of
>   IKEv2.  Additionally, it outlines how Module-Lattice-Based Digital
>   Signatures (ML-DSA) and Stateless Hash-Based Digital Signatures (SLH-
>   DSA), can be employed as authentication methods within the IKEv2
>   protocol, as they have been standardized by US NIST.
> 
> 
> 
> 
> The file can be obtained via
> https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-pqc-auth/
> 
> 
> 
> No IPR declarations have been submitted directly on this I-D.
> 
> 
> 
> 
> 
> _______________________________________________
> IETF-Announce mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to