I would suggest "For TLS, it is important to note that PQC efforts are exclusively for TLS 1.3 or later."
To me, the draft (even v3) is not clear on this point. At some point in future, PQ will become an urgent security issue, and the wording "outside of urgent security fixes" in the draft seems to imply that then we will start working on PQC for TLS 1.2. I suggest being explicit on this point. How about this: For TLS it is important to note that the focus of these efforts is exclusively TLS 1.3 or later. Put bluntly, post-quantum cryptography for TLS 1.2 WILL NOT be supported (see {{iana}}) at any time and anyone wishing to deploy post-quantum cryptography should expect to be using TLS 1.3.
_______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-le...@ietf.org