Hi,

I have a two questions on this document.

First, it keeps stating DTLS is excluded from this draft's recommendations
but the reasons cited for why this is needed for TLS apply eually to DTLS.
So why is DTLS excluded from this? If there are valid reasons, I think the
document should at least state these.

Second point is the text about NIST:

In 2016, the US National Institute of Standards and Technology (NIST)
started a multi-year effort to standardize algorithms that will be "safe"
once quantum computers are feasible [PQC
<https://csrc.nist.gov/projects/post-quantum-cryptography>]. The first IETF
discussions happened around the same time [CFRGSLIDES
<https://www.ietf.org/proceedings/95/slides/slides-95-cfrg-4.pdf>].In 2024
NIST released standards for [ML-KEM
<https://csrc.nist.gov/pubs/fips/203/final>], [ML-DSA
<https://csrc.nist.gov/pubs/fips/204/final>], and [SLH-DSA
<https://csrc.nist.gov/pubs/fips/205/final>]. While industry was waiting
for NIST to finish standardization, the IETF has had several efforts
underway. A working group was formed in early 2023 to work on operational
and transitional uses of PQC in IETF protocols, [PQUIPWG
<https://datatracker.ietf.org/wg/pquip/about/>]. Several other working
groups, including LAMPS [LAMPSWG
<https://datatracker.ietf.org/wg/lamps/about/>], TLS [TLSWG
<https://datatracker.ietf.org/wg/tls/about/>], and IPSECME [IPSECMEWG
<https://datatracker.ietf.org/wg/ipsecme/about/>], are working on drafts to
support hybrid algorithms and identifiers, for use during a transition from
classic to a post-quantum world.

I don't see the relevance of this bit of history. I do see that this point
might be contentious for some people who feel IETF is "subservient" to NIST.

I would propose to remove it, or at most keep the latter bit in a slightly
reworded way.

I also feel the clear distinction between pure (by NIST) and hybrid (by
IETF) is lost a bit, but rather than fixing that, I'd just favour removing
all the text.

Paul
_______________________________________________
Uta mailing list -- uta@ietf.org
To unsubscribe send an email to uta-le...@ietf.org

Reply via email to