On Wed, Jul 15, 2026 at 08:22:29PM +0100, Stephen Farrell wrote: > > The above ignores (or at least doesn't call out) TLS server handling of > private keys and certificates. I think that makes a difference for the > dual vs composite situations. I also think we'd (the TLS WG) be wise to > pay attention to server package maintainers on that topic. (Which is not > the same as paying attention to those who operate the most commonly used > servers.) I'm not sure myself what, if any, preferences they might have, > but many of them will have to make changes, if whatever PQ auth solution > is to work for the vast majority of TLS servers. (Which I assume is a > goal.)
To make some kind of PQ auth work, just add ML-DSA to code. That's what I did. Not great, but does the job. Unfortunately, it seems that is not the preferred kind of PQ auth, and supporting that requires much more extensive changes. Changes where there is no documented guidance. -Ilari _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
