Outside standards have been referenced for ages, certainly ISO and probably 
others.  Surely there is a common IETF policy on how to deal with this, in 
particular the unfortunate practice of many other standards bodies to charge 
significant sums of money for their standards.

               paul



Internal Use - Confidential
From: John Mattsson <[email protected]>
Sent: Wednesday, July 22, 2026 1:10 PM
To: Yoav Nir <[email protected]>
Cc: [email protected]
Subject: [IPsec] Re: I-D Action: 
draft-ietf-ipsecme-hybrid-kem-ikev2-frodo-01.txt


[EXTERNAL EMAIL]
Yoav Nir wrote:
>It makes sense that any "Using algorithm A in IKEv2" draft is going to have 
>algorithm A as a normative reference

Yes. The adopted version had draft-longa-cfrg-frodokem as a normative reference.

As I said, I strongly oppose this change. Making a paywalled cryptographic 
specification a normative reference is a very significant change. I do not 
think the IETF should adopt or publish any documents with normative references 
to paywalled cryptography. I therefore suggest that the authors submit a -02 
revision reverting it.

Cheers,
John Preuß Mattsson

From: Yoav Nir <[email protected]<mailto:[email protected]>>
Date: Wednesday, 22 July 2026 at 18:57
To: John Mattsson 
<[email protected]<mailto:[email protected]>>
Cc: [email protected]<mailto:[email protected]> 
<[email protected]<mailto:[email protected]>>
Subject: Re: [IPsec] I-D Action: 
draft-ietf-ipsecme-hybrid-kem-ikev2-frodo-01.txt
[with no hats]

It makes sense that any "Using algorithm A in IKEv2" draft is going to have 
algorithm A as a normative reference, because you can't implement the new 
document without using the old document.

This is also what we did with RFC 8031 and 8420 - the last two times we had a 
new algorithm in an IPsecME document.

Yoav

On 22 Jul 2026, at 18:58, John Mattsson 
<[email protected]<mailto:[email protected]>>
 wrote:

The -01 version makes the paywalled ISO reference normative. In the adopted -00 
version, it was only informative. Keeping the paywalled reference informative 
was a requirement for my support of adoption.

I strongly oppose this change, which, to my knowledge, has not been discussed 
on the IPsec mailing list.

Cheers,
John Preuß Mattsson


On 2026-07-04, 17:42, 
"[email protected]<mailto:[email protected]>" 
<[email protected]<mailto:[email protected]>> wrote:
Internet-Draft draft-ietf-ipsecme-hybrid-kem-ikev2-frodo-01.txt is now
available. It is a work item of the IP Security Maintenance and Extensions
(IPSECME) WG of the IETF.

   Title:   Post-quantum Key Exchange in IKEv2 with FrodoKEM
   Authors: Guilin Wang
            Leonie Bruckert
            Valery Smyslov
            Meiling Chen
   Name:    draft-ietf-ipsecme-hybrid-kem-ikev2-frodo-01.txt
   Pages:   16
   Dates:   2026-07-04

Abstract:

   FrodoKEM is an unstructured lattice based Key Encapsulation Mechanism
   (KEM), standardized by ISO.  Compared to ML-KEM, it is considered
   with more conservative security.  This draft specifies how to use
   FrodoKEM by itself or as an additional key exchange in IKEv2 along
   with a traditional key exchange.  These options enable to negotiate
   IKE and Child SA keys that are safe against a Cryptographically
   Relevant Quantum Computer (CRQC).

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-ipsecme-hybrid-kem-ikev2-frodo/ 
[datatracker.ietf.org]<https://urldefense.com/v3/__https:/datatracker.ietf.org/doc/draft-ietf-ipsecme-hybrid-kem-ikev2-frodo/__;!!LpKI!jWyg0WpnTQWxc_G82C7WUnNb2O_j67FIJJj7SISxYkeEVT4rQewo3vxe57ezuzwBM3ehLes1YHkA-eS9UARdT32HK8_abvKu$>

There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-hybrid-kem-ikev2-frodo-01
 
[datatracker.ietf.org]<https://urldefense.com/v3/__https:/datatracker.ietf.org/doc/html/draft-ietf-ipsecme-hybrid-kem-ikev2-frodo-01__;!!LpKI!jWyg0WpnTQWxc_G82C7WUnNb2O_j67FIJJj7SISxYkeEVT4rQewo3vxe57ezuzwBM3ehLes1YHkA-eS9UARdT32HK2Le0ljy$>

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-ipsecme-hybrid-kem-ikev2-frodo-01
 
[author-tools.ietf.org]<https://urldefense.com/v3/__https:/author-tools.ietf.org/iddiff?url2=draft-ietf-ipsecme-hybrid-kem-ikev2-frodo-01__;!!LpKI!jWyg0WpnTQWxc_G82C7WUnNb2O_j67FIJJj7SISxYkeEVT4rQewo3vxe57ezuzwBM3ehLes1YHkA-eS9UARdT32HK6OerxEr$>

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts



_______________________________________________
IPsec mailing list -- [email protected]<mailto:[email protected]>
To unsubscribe send an email to 
[email protected]<mailto:[email protected]>

_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to