I wrote: > It's not that anyone has quoted an official > NSA document prohibiting non-hybrid PQ.
Sorry, that should say "It's not that anyone has quoted an official NSA document prohibiting hybrid PQ." Too many negations. :-) At some point on the list there was a deceptive quote "Do not use a hybrid or other non-standardized QR solution on NSS mission systems except for those exceptions NSA specifically recommends to meet standardization or interoperability requirements". To see that this is not a hybrid prohibition, simply look at the preceding sentence of https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF stating in boldface "Should one use a hybrid or other non-standardized QR solution while waiting for a final NIST post-quantum standard?", and observe that we're no longer in the "waiting" situation. ---D. J. Bernstein _______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-le...@ietf.org