TLS chairs call rough consensus to advance pure ML-KEM over sustained objection
Across draft-ietf-tls-mlkem-05, -07, and -08 the working group split over whether an RFC for standalone post-quantum key establishment was necessary plumbing or a dangerous signal. On 19 July 2026 the chairs found rough consensus to advance it anyway.
A draft that will not stay quiet
By mid-2026 the TLS working group had run Working Group Last Call on pure ML-KEM key establishment for TLS 1.3 more than once, under more than one draft number, and still could not put the argument to rest. The document lineage, draft-ietf-tls-mlkem, defines codepoints so that TLS 1.3 peers can perform key establishment with FIPS 203 ML-KEM alone, without a hybrid classical component. Hybrid ECC plus ML-KEM constructions were already moving through the same community. The pure draft was never sold as better cryptography than hybrids. Its supporters called it necessary plumbing for regulation, size, compute, and simplicity. Its opponents called it a decision to throw away a security property TLS 1.3 had been built to keep.
On 8 December 2025 the TLS chairs recorded that there was no consensus to publish the document as-is. The draft returned to WG Document state, with another WGLC planned. That sentence would be quoted for months. When an Area Director later framed a second last call as a narrow confirmatory step after a first WGLC that had "passed," formal-methods participant Nadim Kobeissi disputed the framing on the list. "The December 8 conclusion, cited by the AD as his own reference [2], reads: "we do not have consensus to publish the document as is.""
The fight that followed mixed three layers that rarely stay separated in post-quantum standardization: the technical meaning of pure versus hybrid KEM use in TLS 1.3; the process meaning of rough consensus, Recommended flags, and Informational optics; and the political meaning of NSA alumni, Five Eyes participation, and the long memory of Dual_EC_DRBG and BULLRUN.
What pure ML-KEM removes
Hybrid key establishment is secure if either component remains unbroken. Pure ML-KEM removes that compositional guarantee. TLS 1.3 hybrids had been giving the deployed Internet post-quantum protection via ML-KEM while retaining classical assurance via elliptic curves. Kobeissi, whose background includes co-authoring verified models that contributed to TLS 1.3 standardization, made that the core of a blocking objection filed 21 February 2026 against publication of draft-ietf-tls-mlkem-07:
"A pure post-quantum key establishment option for TLS 1.3 discards compositional security under component compromise -- a property deliberately designed into TLS 1.3 that has served the deployed Internet well -- and the document identifies no concrete benefit gained in exchange."
Draft author and editor contributor Deirdre Connolly corrected the Motivation text Kobeissi had initially misquoted. The shipping Motivation language was not a claim that the world must migrate beyond hybrids as a cryptographic necessity. It named concrete drivers. Connolly wrote: "Use cases include regulatory frameworks that require standalone post-quantum key establishment, targeting smaller key sizes or less computation, and simplicity."
That trio became the steelman for publication. CNSA 2.0 style profiles and other FIPS-adjacent procurement rules do not always allow hybrid PQ. Some industries, Soatok Dreamseeker argued during the July 2026 last call on draft-ietf-tls-mlkem-08, need an RFC for reasons that have little to do with cryptographers' taste. FIPS documents do not by themselves specify how to use ML-KEM inside TLS. Telecom and government buyers still ask for RFCs. Uri Blumenthal of MIT Lincoln Laboratory pressed the capture-now-decrypt-later clock: if data must remain secret after a cryptographically relevant quantum computer arrives, surviving only until that day is not a victory. "If the data must remain secure after CRQC - you do not get bonus points for surviving only until CRQC."
Objectors answered that none of those motives justified deleting a working safety property. Performance deltas between ML-KEM-only and ECDHE plus ML-KEM, Kobeissi argued, do not approach the threshold that would justify discarding a well-analyzed guarantee. Tanja Lange, objecting through both the February -05 last call and the July -08 last call, put the deployment politics more bluntly than the formal-methods framing:
"I think it is irresponsible of the WG to publish an RFC that encourages risky behavior. Users will take the reputation of the IETF and understand this as a recommendation, whether it says = N or not."
And: "Still, it's better to add ML-KEM than not deploying it, but please not without ECC."
Lange also pointed at real-world buyers. On-list discussion of Canadian government posture, in her reading, showed authorities waiting on an RFC before recommending ditching hybrids for fully exposed PQC. The fear was not hypothetical mansplaining about flags. It was that Recommended=N would be ignored the moment an IETF document existed to point at.
Ken Kubota made the same Recommended-flag point in process language. "It has already been pointed out earlier on this mailing list [1] that RECOMMENDED = N is not a remedy, since the non-hybrid mechanism would still be implemented and used, effectively (!) weakening internet security by encouraging its deployment." Sam Leavin, reiterating opposition as the -08 last call ended on 8 July 2026, wrote: "Just because some people want to make it easier for others to use a less powerful security mechanism doesn't mean that the IETF needs to assist them."
David Adrian reminded the list of a different process axiom: "Rough consensus is not veto-based." Kobeissi agreed with the axiom and rejected the implication. A blocking objection, he said, citing RFC 7282, is a request that chairs engage technical substance on the record before declaring consensus, not a personal veto.
February 2026: -05, -07, FATT, and decoupling hybrids
The winter last-call window centered on draft-ietf-tls-mlkem-05 (WGLC scheduled to end 27 February 2026) and the -07 text under active objection. Muhammad Usama Sardar, tied to the FATT formal-analysis effort, strongly opposed -07. He cited a missing FATT report and inadequate security considerations, and said he would appeal if rough consensus were declared anyway. "No FATT report is shown despite my repeated requests to the chairs for last 10 days."
Connolly used the same period to surface draft HEAD guidance on key reuse and ciphertext reuse: avoid static ML-KEM keypair reuse when forward secrecy matters; if reusing, respect bounds from subsequent multi-target analyses; ciphertexts must not be reused. ML-KEM's IND-CCA and FO transform story supports some reuse in principle, but multi-target and multi-ciphertext work (including discussion around analyses such as eprint 2025/343) and the unsalted message space fed arguments about roughly 2^64-scale multi-target limits. Those notes were an attempt to make the pure-PQ option less foot-gun shaped even if the WG published it.
Bas Westerbaan argued for decoupling. There was appetite, he said, not to block hybrid work on the exact Recommended-field story for every hybrid and KEM. He was drafting an Internet-Draft to move hybrids toward Recommended=Y, so that pure-ML-KEM politics would not indefinitely hostage the hybrid deployment path. "There was a desire of many in that discussion not to block the hybrid draft on the question how to update the Recommended field precisely for all the hybrid and existing KEMs. To make progress, sometimes you have to decouple things."
Lange's February message also attacked a soft consensus culture that treats silence as assent. "I very much dislike this definition of "participant" and the assumption that those who don't speak up are in agreement. I've been a participant for more than 10 years and I strongly object to the publication." On 6 July 2026, after -08 appeared, she forwarded that history and closed simply: "I do not support publishing this document." Concerns from the -05 round, she said, remained unaddressed.
July 2026: -08, standards literacy, and the SIKE analogy
WG Last Call for draft-ietf-tls-mlkem-08 was set to end 8 July 2026. The early July traffic was partly a seminar on what an RFC is. Markku-Juhani O. Saarinen argued that cybersecurity engineers must learn the kinds of standards and their caveats. Informational RFCs are not seals of approval; he offered RFC 7693 on BLAKE2 as personal history. European "harmonised standards" language, he noted, creates presumption of conformity that ordinary international crypto documents do not automatically enjoy. John Preuß Mattsson of Ericsson added that ETSI SAGE and 3GPP, not only NIST, have been decisive cryptographic SDOs for mobile systems, sometimes ahead of NIST on Rijndael and Keccak deployments.
Soatok Dreamseeker defended the boring reason the RFC needed to exist and rejected a SPECK-style backdoor analogy for ML-KEM. SPECK had ridden ISO process fractures into RFID standards against cryptographers' judgment; that, Soatok argued, was not the ML-KEM situation. On the NOBUS backdoor theory aimed at pure ML-KEM adoption, the counter was procurement reality: "If the NSA thought they had a NOBUS backdoor in ML-KEM, why would they be moving everything to use it for TOP SECRET classified information as fast as they can?"
Blumenthal reported that credible cryptographers, with one exception in his tally, supported publication, and later separated implementation from negotiation: implementing an algorithm and offering it at session setup are different acts. Objectors were unconvinced that market and configuration reality would honor that separation once codepoints existed.
PQC immaturity arguments invoked the SIKE break and uncertainty language in RFC 9958. Supporters called SIKE a bad analogy for whether ML-KEM must be available under CRQC and harvest-now-decrypt-later pressure. Mattsson separately distinguished ephemeral KEM migration from long-term authentication keys on devices that never rotate SSH identities, arguing that signature and authentication PQ timing is not the same problem as ephemeral key exchange, and that OpenSSH-style capture-now goals should not be confused with authentication-key neglect.
The hash that NIST removed
Parallel to pure-versus-hybrid politics ran a sharper cryptographic dispute: the fate of Kyber's m <- H(m) step inside encapsulation.
Third-round Kyber hashed the encapsulator's message contribution. FIPS 203 ML-KEM removed that step, relying on approved random bit generation. Objectors, led on-list in July by Jacob Appelbaum with Kubota amplifying, called the removal a deleted defense-in-depth measure against Dual_EC_DRBG-shaped hidden structure and against a peer-recoverable m oracle when ML-KEM is composed with TLS. Peter Schwabe, a Kyber co-author, was cited as favoring the cheap hash in encaps. Cost figures recalled from 2023 pqc-forum benchmarking were on the order of hundreds to low thousands of cycles.
Appelbaum insisted the entropy debate was a sideshow. "Refusal to address the technical issue of destroying any possible hidden structure is the issue. My core concern has nothing to do with entropy." In his telling, hashing does not claim to fix a fully owned system RNG; it destroys algebraic structure in m before encryption and before the decapsulating peer can recover that m. TLS drafts, he argued, neither require nor explain the approved-RBG assumption that FIPS 203 uses to justify the removal.
Mattsson pushed back on both conspiracy framing and technical mechanism. He said he cares deeply about attacker-controlled RNGs and has argued at NIST for multiple independent entropy sources, including in FN-DSA discussion. But on m <- H(m) he summarized the pqc-forum outcome as he understood it: the step does not add entropy, does not protect a value the attacker can already observe in the interesting cases, helps only narrow biased-but-entropic RNGs, and does nothing against a fully broken RNG. The right fix is better RNGs outside ML-KEM. He also asked why EU cryptographers who proposed removal escaped the same SIGINT narrative. "The fact that SIGINT agencies have systematically weakened standards to facilitate interception is a fact, but it has very little to do with TLS."
Wang Guilin framed a clean research question: a bad RNG makes raw m dangerous; a good RNG makes hashing optional; could hashing introduce new weaknesses that raw sampling would not have? Under a secure hash he expected hashing to be at least as safe, at the cost of cycles and some entropy. Appelbaum treated that as the right comparison and pointed at related KEMs with different hash choices as a natural experiment.
Quynh of NIST had publicly claimed that the FIPS 203 authoring group had no NSA meetings and that NSA had zero authorship. On 9 July 2026 Appelbaum challenged that claim against FOIA material: secret NSA and NIST PQC meetings, NSA weight on [email protected], comments from "Donna and the NSA" incorporated into a PQC NISTIR that FIPS 203 cites, and June 2020 track-changes comments attributed to Morgan of NSA on NIST internal drafts. David Cooper, NIST-affiliated, engaged on generation of m and process history. The narrow-versus-broad reading of "authorship" and "meeting" never produced a reconciliation that objectors accepted. Whether those NIST process fights belong inside a TLS WGLC security considerations section remained an open process question as the -08 call ended.
NSA alumni, recusal, and vote counting
The temperature rose when Kubota answered William Layton of NSA and Security Area Director Deb Cooley together. Kubota listed hybrid safety-belt logic, RFC 9958 immaturity language, the SIKE break, and the Schwabe hash preference, then tied hash removal to Dual_EC history and undisclosed NSA contribution narratives from FOIA highlights.
Cooley declined recusal. "The topic of the working group last call is about a draft, not about NSA, I perceive no reason to recuse." She added: "I will also point out that I am retired from the US Federal Government, and I have no obligations to them, just like any other person changing companies wouldn't retain responsibilities of their previous company." She warned that new participants who violate stated policies get private warnings before further action, and pointed at prior recusal discussion elsewhere in the IETF for general crypt work.
Appelbaum answered that the issue was not personal animus. "The issue is not personal. The issue is trust in a standards process." He invoked RFC 7258 on pervasive monitoring as attack, NYT SIGINT Enabling material on influencing commercial cryptography, DER SPIEGEL reporting on NSA attendance at IETF meetings, and BULLRUN-era TLS and SSL operational language about millions of sessions and needing both sides of a conversation. Eliot Lear called parts of the exchange highly inappropriate. Appelbaum disagreed and said unanswered yes-or-no conflict questions were the problem.
Kubota escalated with residual-obligation questions Cooley did not answer in yes-or-no form, cited RFC 9151's P-384 profile as intentional weakening relative to 256-bit options, and on 12 July leaned on a Daniel J. Bernstein microblog vote count of intelligence-aligned supporters. Kubota's arithmetic, if Bernstein's public tally were correct, ran through U.S., UK, and Canadian intelligence participation and allied defense-sector voices, including Thales, and concluded that Five Eyes really wanted pure ML-KEM passed. "My bet is on the removal of the hash function. This would leave the door open to a repeat of the Dual_EC_DRBG backdoor scenario, either now or at some point in the future."
Supporters and middle-ground participants tried to keep two thoughts at once. Mattsson accepted historical SIGINT weakening as fact while demanding the NSA politics leave the TLS list and calling several security-level comparisons wrong; X25519's roughly 128-bit classical security, he noted, does not make Bernstein a deliberate weakener in the sense Kubota's rhetoric implied. Blumenthal concurred with Cooley's recusal answer. Dreamseeker and Saarinen kept returning to literacy about tracks, flags, and outsider misreading: the IETF controls its own messaging, not every procurement officer's skimming habits.
Bernstein himself figured in the editorially visible record mainly as a cited external objector and as the microblog source for vote-counting, not as a continuous on-list author of the July threads. His broader objections were ambient reference points whenever someone needed a public tally or a long-memory critique of NIST PQC process.
The chairs call rough consensus
The document did not die in last call. On 19 July 2026, TLS chair Joseph Salowey posted the consensus determination for draft-ietf-tls-mlkem-08, and it went against the objectors. The chairs acknowledged the room had split and that a wave of first-time participants had arrived through what Salowey called the extensive social media coverage, then set raw headcount aside. "By pure numbers, more people want to progress the document than not, but this alone does not constitute rough consensus," he wrote. "However, if we look at pre-existing WG participants or people with demonstrated expertise, roughly 7/10 WG participants favor advancing the document, which shows rough consensus to move the document forward."
Rough consensus came with a punch list, and the chairs were explicit that they would not reopen the pure-versus-hybrid question. They folded several last-call objections into the text instead. The IANA considerations section would spell out what the Recommended "N" flag means, importing language the IESG had already approved for pure ML-DSA and citing RFC 9847: that N indicates an item "has not been evaluated by the IETF," not that it is flawed. Appelbaum's randomness objection became its own action item. The chairs agreed the raw m value passed to ML-KEM.Encaps(), and the PRNG-state exposure it enables, warranted security-considerations text, while noting the concern "pertains to the ML-KEM algorithm itself and is not unique to TLS" and pointing at the secure-PRNG requirements in NIST SP 800-90A-C and RFC 9846. Quynh Dang of NIST proposed tightening the Dual_EC_DRBG reference so readers would not misread which RNG the attack compromises. draft-ietf-tls-mlkem-09, carrying the agreed changes, was posted the next day, 20 July 2026.
The determination moved the fight past the point where objectors could still shape the document, but it did not convert them. Ken Kubota answered within the hour, unmoved by the chairs' distinction between established participants and newcomers: "the presence of a double-digit number of identified intelligence agency operatives from the NSA, GCHQ, and CSE, the resulting conflict of interest, and their uniform voting behavior remain completely unaddressed." Appelbaum's hash-removal and FOIA dossier, Sardar's FATT-report appeal language, Kobeissi's blocking objection, and Lange's and Leavin's refusals to support publication were not retracted by the consensus call. They were overruled by it.
The parallel CFRG work on hybrids and KEM combiners sat beside the TLS fight as a second institutional stage. Participants who wanted conservative combiners and participants who wanted deployable constructions carried related disagreements about chair handling and scope into that venue. The TLS list traffic reproduced here does not settle that CFRG complaint; it only makes clear why combiner politics and pure-ML-KEM politics refused to stay in separate boxes. Anyone trying to standardize how to glue KEMs together was downstream of the same trust arguments about NIST changes, NSA history, and whether "the standard settled it" is an acceptable reply inside the IETF.
Steelmanning both coalitions without declaring a winner leaves an uncomfortable symmetry. The publication side can say, fairly, that refusing an RFC does not erase CNSA-style requirements, that hybrids remain available, that Recommended=N and Informational labeling are real signals, that ML-KEM is not SPECK, and that delaying pure codepoints leaves regulated operators inventing non-interoperable private suites while harvest-now adversaries keep recording traffic. The objection side can say, fairly, that TLS 1.3's hybrid compositional story was not a fashion statement, that SIKE's death is a reminder about young primitives, that codepoints get implemented and preferred whenever both peers offer them, that deleting Kyber's cheap hash replaced a concrete structural defense with an approved-RBG assumption the TLS drafts do not enforce, and that a standards body with documented experience of SIGINT interest in TLS cannot treat recusal and influence questions as mere rudeness.
The working group had been here before, in December 2025, with a chair conclusion that there was no consensus to publish as-is. This time the chairs read the same room and reached the opposite result, not because the objections got weaker but because the weight of established expertise landed on the other side. Pure ML-KEM for TLS is not only a ciphersuite table row. It is a referendum on whether the IETF's job, in the first decade of real PQC deployment, is to maximize optionality for constrained regulators and operators or to refuse pathways that make compositional security optional while the algorithms are youngest and institutional trust is thinnest. The chairs have now answered, for this document: optionality wins, marked "N," over the sustained objection of some of the people who helped verify TLS 1.3 in the first place. Whether that answer survives an appeal is the next question.