IETF advances PQ crypto drafts for TLS and SSH
IETF working groups pressed forward on post-quantum cryptography proposals for TLS and SSH, alongside adoption debates for segment routing and DNSSEC updates. Governance threads also examined the status of ARC and the scope of the SEAT charter.
Keccak-based TLS 1.3 key schedule draft
An IETF draft proposes a Keccak-based key schedule for TLS 1.3. The Keccak team and formal-analysis volunteers joined the discussion to work on optimizations. The work offers an alternative construction that developers tracking TLS crypto agility will want to follow.
SSH WG call for adoption of ML-DSA signature drafts
The IETF SSH working group opened a call for adoption of hybrid and pure ML-DSA signature drafts, closing on August 17th. The thread drew active debate from 22 participants, including D.J. Bernstein. The outcome will shape how SSH incorporates post-quantum signatures.
Expanding hybrid ML-DSA combinations for SSH
Participants debated whether to expand the set of hybrid ML-DSA signature combinations in the SSH draft. The discussion weighed compliance requirements against a preference for minimalism. The choice affects implementers who must balance standards coverage with code complexity.
Spring SID-as-source-address adoption call
The SPRING working group considered adoption of draft-yang-spring-sid-as-source-address. Technical pushback focused on VRF reachability and next-hop symmetry concerns. Operators relying on segment routing need clarity on these reachability constraints.
Composite PQ signatures draft for SSH
The SSH working group examined adoption of the draft-miller composite post-quantum signatures proposal. Overlapping drafts and curve selection debates surfaced among the ten participants. Competing approaches leave implementers watching for convergence on a single composite scheme.
DMARC discussion on making ARC historic
The DMARC working group evaluated consensus on marking ARC (RFC 8617) as Historic and publishing an experiment report. Five participants contributed to the technical exchange. Mail authentication deployers must track whether ARC remains a recommended path.
Multi-algorithm DNSSEC requirements debate
DNSOP participants reviewed a multi-algorithm DNSSEC draft, covering post-quantum support and downgrade signaling rules. The thread clarified sanity constraints for algorithm agility. DNS operators preparing for PQ transitions need the resulting signaling rules.
SEAT charter clarification on TLS observation
The SEAT working group sought clarification on whether read-only TLS handshake observation violates its charter ban on protocol changes. Ekr flagged a potential spirit violation in the four-message exchange. The boundary affects any work that inspects but does not modify TLS.