freenode

← digests

IETF crypto and protocol debates

Internet & Protocols2026-07-29

IETF working groups saw active movement on post-quantum cryptography and protocol maintenance, led by a heated SSH signature adoption call and a related formal complaint. Parallel threads addressed TLS key schedules, ARC status, DNSSEC multi-algorithm rules, and an MLS profile.

TLS draft proposes Keccak-based key schedule

A new IETF draft floated Keccak-based constructions for the TLS 1.3 key schedule. The Keccak team and formal-analysis volunteers joined the discussion to examine optimizations. The work could shape how TLS evolves its core cryptographic primitives.

SSH group opens adoption call for ML-DSA signatures

The SSH working group issued a call for adoption of hybrid and pure ML-DSA signature drafts, closing 17 August. Debate was active and included contributions from D.J. Bernstein on the merits and risks. The outcome will influence post-quantum migration paths for SSH.

DMARC considers marking ARC historic

The DMARC working group evaluated consensus on designating ARC (RFC 8617) as Historic and publishing a corresponding experiment report. Participants weighed the practical status of the mechanism against its original goals. A decision would clarify the standing of ARC for implementers and operators.

Bernstein files RFC 2026 complaint against SSH chairs

D.J. Bernstein submitted a formal complaint under RFC 2026 alleging that the SSH working group chairs violated IETF consensus and transparency rules. The filing adds a governance dispute to the ongoing post-quantum signature discussions. Process integrity questions of this kind can affect how working-group decisions are received.

DNSOP debates multi-algorithm DNSSEC requirements

Participants in DNSOP examined a multi-algorithm DNSSEC draft, focusing on post-quantum support and downgrade signaling rules. The thread sought clearer sanity constraints for algorithm combinations. The rules will matter for operators deploying mixed or future-proof DNSSEC configurations.

Further SSH discussion on hybrid versus pure PQ signatures

A shorter follow-up thread on the same SSH adoption call examined hybrids versus pure post-quantum signatures and associated risk models. Limited additional input refined the earlier positions. The distinction affects how SSH deployments balance compatibility and cryptographic strength.

Proposal to ease DELEXT restrictions for DNS delegations

Roy Arends suggested allowing future delegation types to coexist with NS records under DE=1 rather than mandating DELEG. The change would relax what some view as overly tight constraints in the current model. Flexibility here could simplify introduction of new DNS delegation mechanisms.

MLS adoption call for two-party profile

The MLS working group opened an adoption call for a two-party profile draft, closing 28 July 2026. Authors and two other participants voiced support while Rohan and Richard raised questions on requirements, scope, and alternatives. The profile would define a narrower MLS mode for simpler two-party use cases.