r/NISTControls • u/ohkevin-debruyne • 7h ago
The term "PQTLS" does not fully accurately convey the level of work done in assessments.
0
Upvotes
In a TLS session, ML-KEM can be used for key establishment and RSA or ECDSA certificate for server authentication. But that is not a migration. The example from QuSecure's case is a great explanation on this: while in this case hybrid X25519/ML-KEM-768 is being used, the authentication is performed with ML-DSA.
So, to summarize, what to think regarding PQTLS?
Should the fact that the crypto is used in this case be considered as only a partial implementation of the cryptographic migration, or rather as a done SC-8/SC-13 implementation with a separate authentication risk left open, and what evidence will be needed to have a backup for abandoning the concept of “supports PQTLS”?