On Wed, Jan 10, 2024 at 12:14 PM Bas Westerbaan <bas=40cloudflare....@dmarc.ietf.org> wrote: > > Dear tls and cfrg working groups, > > With ML-KEM (née Kyber) expected to be finalized this year, it’s time to > revisit the question of which PQ/T hybrid KEMs to standardize, and which to > recommend.
My preference would be that we use an KEM hybrid that works not just for TLS but for HPKE etc with all the parameters set. I think its fine if adapted for ML-KEM as is. Remembering which works here and which doesn't there is work that we don't need to do and if gotten wrong could cause problems. Sincerely, Watson -- Astra mortemque praestare gradatim _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls