Didn't CNSA 2 only allow hybrids if there is no alternative? There is a
codepoint for MLKEM1024 in TLS now.

On Mon, Jan 6, 2025 at 9:57 AM Kris Kwiatkowski <k...@amongbytes.com> wrote:

> Sure, but for the record the same applies to SecP3841MLKEM1024
>
>
> I think the main motivation for ECDH/P-384 is CNSA compliance, so I don't
> think it is "the same applies". Yes,
> it is slower than x25519 or ECDH/p256.
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-le...@ietf.org
>
_______________________________________________
TLS mailing list -- tls@ietf.org
To unsubscribe send an email to tls-le...@ietf.org

Reply via email to