Yes, exactly. I believe that Andrew is referring to the fact that hybrids aren't RECOMMENDED=Y which is silly, and the impetus behind Bas’s recent effort: https://datatracker.ietf.org/doc/draft-westerbaan-tls-keyshare-recommendations/
Nadim Kobeissi Symbolic Software • https://symbolic.software > On 5 Jun 2026, at 8:53 PM, Eric Rescorla <[email protected]> wrote: > > > > On Fri, Jun 5, 2026 at 12:38 PM Salz, Rich <[email protected] > <mailto:[email protected]>> wrote: >> This happened after a significant amount of time and was deliberately >> steered toward the opposite of said result >> >> My recollection and view is the exact opposite. ML-KEM key exchange was >> never going to be RECOMMENDED=Y. > > This matches my recollection as well. Rather, both pure ML-KEM and the > ECC/ML-KEM hybrids were going to be Recommended=N, and then we decided late > in the process (after IESG approval) to make the hybrid Recommended=Y. > > -Ekr > > > _______________________________________________ > TLS mailing list -- [email protected] > To unsubscribe send an email to [email protected]
_______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
