Markdown Version | Transcript | Recording 1 | Recording 2 | Session Materials

Session Date/Time: 23 Jul 2026 07:00 ✎ Suggest a correction

TLS

Summary

The TLS Working Group met at IETF 126 to discuss the status of active working group drafts, address recent mailing list behavior, review updates to DTLS 1.3, and evaluate several newly proposed drafts.

Key outcomes included a clear mandate for the chairs to exercise stronger moderation controls over the mailing list, a consensus decision to require replay protection in DTLS 1.3, and plans to take several active or proposed drafts (such as signed Encrypted Client Hello (ECH) updates and workload identifier scope hints) to the mailing list for further discussion or adoption calls.


Key Discussion Points

1. TLS WG Update

Sean Turner presented the WG status update using the slide deck TLS WG Update.

2. DTLS 1.3

Eric Rescorla presented updates to draft-ietf-tls-rfc9147bis based on the DTLS 1.3 slide deck.

3. Authenticated ECH Config Distribution and Rotation

Alessandro Ghedini presented Authenticated ECH Config Distribution and Rotation, detailing draft-sullivan-tls-signed-ech-updates.

4. Workload Identifier Scope Hint

Yaroslav Rosomakho presented Workload Identifier Scope Hint covering draft-rosomakho-tls-wimse-cert-hint.

5. Supplemental Authentication in TLS 1.3

Yaroslav Rosomakho presented Supplemental Authentication in TLS 1.3 based on draft-rosomakho-tls-supplemental-auth.

6. PQC Continuity

Yaron Sheffer presented PQC Continuity on draft-sheffer-tls-pqc-continuity.


Decisions and Action Items

Decisions

  1. DTLS 1.3 Replay Protection: Replay protection will be made mandatory in draft-ietf-tls-rfc9147bis (PR 317 will be merged).
  2. Mailing List Moderation: The chairs will implement stricter moderation policies, including thread squelching and potential moderation queues, to protect the mailing list from toxic behavior and unproductive process debates.

Action Items

  1. Chairs: Issue an adoption call on the mailing list for draft-sullivan-tls-signed-ech-updates.
  2. Chairs: Initiate the FATT point person assignment for draft-ietf-tls-pake.
  3. Yaroslav Rosomakho & Shumon Huque: Coordinate on overlapping extension semantics between WIMSE client certificate hints (draft-rosomakho-tls-wimse-cert-hint) and DANCE's client certificate solicitation work.
  4. David Benjamin & Martin Thomson: Provide detailed feedback and review on epoch closure handling (PR 326) in draft-ietf-tls-rfc9147bis.

Next Steps


Session Date/Time: 24 Jul 2026 14:00

TLS

Summary

The TLS Working Group met at IETF 126 to discuss several active initiatives, including password-authenticated key exchange (PAKE) mechanisms, hybrid post-quantum and traditional (PQ + T) signature schemes, XOF-based key schedules, and empirical measurements of Encrypted Client Hello (ECH) deployments. The group held key discussions on whether to pursue dual certificates or composite signatures for PQ+T hybrid authentication, resulting in a clear preference to focus work on composite signatures.


Key Discussion Points

1. PAKE Extension for TLS 1.3

Christopher Wood presented an update on draft-ietf-tls-pake (A Password Authenticated Key Exchange Extension for TLS 1.3).


2. Framing PQ + T Signatures for TLS

Sean Turner introduced the discussion on post-quantum and traditional (PQ + T) hybrid signature schemes.

A. Dual Certificates in TLS 1.3

Rifaat Shekh-Yusef and Hannes Tschofenig presented the dual-certificates approach.

B. Composite Signatures (Use of Composite ML-DSA in TLS 1.3)

Tiru Reddy presented the composite signature approach.


3. XOF-Based Key Schedules for TLS 1.3

Nick Sullivan presented a proposal to introduce Extendable-Output Function (XOF) based key schedules into TLS 1.3.


4. Encrypted Client Hello (ECH) Active Measurements

Jonas presented research on active measurements of Encrypted Client Hello (ECH) deployments.


Decisions and Action Items

Session Polls

The chairs conducted several polls to determine the path forward on PQ + T hybrid signatures:

  1. Do we have enough information to take a decision on the way forward for PQ + T Signatures for TLS?

    • Result: yes: 67, no: 10, no_opinion: 1 (total: 146)
  2. Should the WG work on PQ + T Signatures for TLS?

    • Result: yes: 53, no: 20, no_opinion: 12 (total: 148)
  3. Should the WG only work on one: -pqt-dual-certs or -composite-ml-dsa?

    • Result: yes: 55, no: 11, no_opinion: 14 (total: 149)
  4. Should the WG work only on: -pqt-dual-certs?

    • Result: yes: 8, no: 51, no_opinion: 12 (total: 148)
  5. Should the WG work only on: -composite-ml-dsa?

    • Result: yes: 53, no: 8, no_opinion: 17 (total: 149)
  6. Can we allocate code points and move?

    • Result: yes: 11, no: 7, no_opinion: 3 (total: 151)
  7. Can we allocate code points and not adopt the draft?

    • Result: yes: 31, no: 23, no_opinion: 8 (total: 151)

Key Decisions


Next Steps

Related Documents

draft-ietf-tls-extended-key-update, draft-ietf-tls-key-share-prediction, draft-ietf-tls-mlkem, draft-ietf-tls-pake, draft-ietf-tls-rfc9147bis, draft-ietf-tls-super-jumbo-record-limit, draft-ietf-tls-tlsflags, draft-ietf-tls-trust-anchor-ids, draft-ietf-tls-wkech, draft-rosomakho-tls-supplemental-auth, draft-rosomakho-tls-wimse-cert-hint, draft-sheffer-tls-pqc-continuity, draft-sullivan-tls-signed-ech-updates