freenode

← digests

IETF SSH and TLS PQ signature drafts advance

Internet & Protocols2026-07-27

IETF working groups spent the day on post-quantum signature adoption calls and TLS key-schedule redesigns. Parallel threads examined attested TLS binding analysis, BGP unreachability encoding, and smaller protocol experiments.

SSHM chairs open adoption call for ML-DSA signature drafts

IETF SSH Working Group chairs opened a call for adoption, closing 17 August, on hybrid and pure ML-DSA signature drafts. Daniel J. Bernstein challenged the process wording and argued that hybrid constructions reduce the risk of implementation bugs relative to pure post-quantum schemes. The discussion is heated because multiple overlapping composite-signature proposals are already on the table.

TLS draft replaces HKDF key schedule with Keccak XOF

A new individual draft proposes replacing the TLS 1.3 HKDF-HMAC-SHA-2 key schedule with a single Keccak permutation schedule. The change targets efficiency gains when ML-KEM, Dilithium, or SHA-3 is already present in the stack. Participants examined concrete performance and security trade-offs of the XOF-based construction.

Composite PQ signatures draft draws SSH WG scrutiny

The SSH Working Group is weighing adoption of draft-miller-sshm-composite-sigs-00 alongside related hybrid proposals. Debate centers on overlapping draft scope and on which elliptic curves should be paired with the post-quantum components. Implementers must track which composite formats ultimately gain consensus.

Researchers dispute formal analysis of attested TLS relay attacks

Two researchers continue to contest the security goals and formal-analysis results for intra-handshake binding in attested TLS, the mechanism tied to CVE-2026-3369. The exchange focuses on whether the published model adequately captures relay-attack resistance. Clarity on the binding property will affect how attested TLS is specified going forward.

IDR draft encodes UPA unreachability in MP_REACH_NLRI

Robert Raszuk objects to draft-krierhorn-idr-upa-04 for placing UPA unreachability information inside MP_REACH_NLRI rather than MP_UNREACH_NLRI. The choice affects how BGP speakers signal prefix unavailability. Correct encoding is required for interoperable withdrawal handling.

TCPM reviews packet-trimming NACK and DSCP draft

The TCPM Working Group supplied initial technical comments on draft-mazilu-tcpm-packet-trimming-00. The draft defines a NACK option and DSCP signaling for packet trimming. Feedback addresses option format and interaction with existing congestion-control mechanisms.

DMARC WG weighs making ARC Historic

A short DMARC Working Group thread examines whether to publish the ARC experiment report and reclassify RFC 8617 as Historic. Participants are testing for consensus on closing the Authenticated Received Chain experiment. The outcome will determine the documented status of ARC in the standards track.

SEAT draft debates resumption ban and KEM alternative

The SEAT Working Group is discussing draft-fossati-seat-expat-03, which proposes banning session resumption and explores a KEM-based alternative. Comments address the security rationale for the ban and the practicality of the KEM approach. The design choices will shape attested TLS endpoint behavior.