IETF
Every article tagged IETF, newest first.
3 articles
IETF holds standalone ML-KEM TLS draft for review
The RFC Editor has paused the standalone ML-KEM-for-TLS draft while IETF process complaints are reviewed. The hold delays publication but does not revoke hybrid RFC 10024 or establish a cryptographic flaw.
TLS 1.2 made servers refuse a resumption whose name had changed. TLS 1.3 removed that rule.
We have submitted a position paper to the IAB workshop on post-quantum authentication, and published the whole evidence base behind it: eleven CVE identifiers across eight pieces of software since 2014, reproductions against current OpenSSL, Go and nginx, a fourteen-host measurement of public endpoints, and what conforming would save a deployment that cannot safely resume today. It is a proposal, not a standard, and the page says so at the top.
Post-quantum TLS 1.3 hybrid is now RFC 10024
The IETF has published RFC 10024, formally standardizing X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 as hybrid post-quantum key agreement mechanisms for TLS 1.3. The three groups replace the long-running draft-ietf-tls-ecdhe-mlkem specification that browsers and libraries were already shipping as a de facto default. Here is what the RFC locks in, and what it still leaves for a separate migration.
Turn quantum risk into a credential.
Book a discovery call and get an indicative scope and pricing for your organisation.