On Wed, Mar 06, 2024 at 04:25:16PM +0000, John Mattsson wrote: > I think TLS should register all algorithm variants standardized by > NIST. That means ML-KEM-512, ML-KEM-768, and ML-KEM-1024. And in > the future a subset of HQC/BIKE/Classic McEliece.
Just as note, supporting Classic McEliece is not possible at all due to the key size exceeding hard TLS 1.3 limit. Even FrodoKEM, which seems to be quite widely viewed as "next step up" from likes of ML-KEM, has painfully large keys. But at least those do not bust any hard limits. -Ilari _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls