Hi folks, This debate simply is not relevant to the WG discussion, because neither CNSA 2.0 nor RFC 9151 are products of the IETF [0], and TLS 1.3 *does* specify algorithms at the 256-bit level, both for key establishment and for symmetric encryption.
Ken, as Scott says, if you want to argue that the TLS WG should deprecate all algorithms with security < 256 bit, then that would be on-topic for this list. Is that what you are arguing? On the other hand, if you want to complain about RFC 9151, then this is not an appropriate forum for that. -Ekr [0] For that matter, neither is RFC 8890, for the same reason. On Sat, Jul 11, 2026 at 7:59 AM Scott Fluhrer (sfluhrer) <sfluhrer= [email protected]> wrote: > Might I point out how silly this argument is? > > Ken is complaining that NSA wants to use a group with "only" 192 bits of > security strength, while what we generally use is x25519, which has a > security strength of 126 bits (by the same metric). > > Could Dan Bernstein (designer of x25519) be accused of deliberately > weakening security? Could the TLS working group also be accused, by not > only permitting that, but other additional "weak" groups as well (P256, all > the finite field groups) and AES-128? > > If you want to make the case to the working group that it should deprecate > all "below 256 bit" crypto, such as X25519MLKEM768 and SecP256r1MLKEM768, > and instead rely only on things such as mlkem1024, please make the case. I > personally don't have any concerns about the prequantum security of either > x25519 or P384, but if the working group decides otherwise, so be it. > > In any case, the CNSA requirements apply only to US National Security > Systems; anyone else can do anything they want. I believe that it is > reasonable for an organization to make requirements on what is used in > their internal network, as much as you don't approve of those decisions. > > ------------------------------ > *From:* Ken Kubota <[email protected]> > *Sent:* Saturday, July 11, 2026 7:00 AM > *To:* Deb Cooley <[email protected]> > *Cc:* [email protected] <William.Layton= > [email protected]>; [email protected] <[email protected]> > *Subject:* [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends > 2026-07-08) > > "I'm not sure what your point is here" > Although strong cryptography (256 bits of security) could generally have > been available for every end user for the past two decades on standard > consumer devices, the U.S. government is intentionally deploying, through > the NSA, degraded (weakened) encryption. > RFC 9151 (2022), which provides only 192 bits of security (curve P-384), > is one example. > This is contrary to RFC 8890 ("The Internet is for End Users"), which I > interpret as meaning that U.S. government interests must not take > precedence over those of end users (i.e., human beings, mankind). Strong > cryptography (256 bits of security) should be available to everyone. > > In my opinion, the warning email [1] constitutes a violation of RFC 3934 > Section 2, and therefore I asked questions 1, 2, 3, and 4 in the section > addressed to you [2], which you decided not to answer except for the first > part of question 1, even though they could be answered with a simple "yes" > or "no" (or a short sentence). > This creates the impression that the rules are applied very restrictively > to some people [3], while not being applied at all to others. > > _______________________________________________ > TLS mailing list -- [email protected] > To unsubscribe send an email to [email protected] >
_______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
