I thought that I remember (sic) that NIST said that hybrid key exchange, where one was FIPS approved, was still FIPS approved, and further that the order did not matter. Do I remember correctly? And, if so, does that mean “anything” hybrid with MLKEM is FIPS-okay now?
_______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-le...@ietf.org