RFC 10024proposedA1IETF · 2026-08

Hybrid ML-KEM / ECDHE key exchange for TLS 1.3

Defines X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024 as hybrid key-exchange groups for TLS 1.3.

What it changes in practice
  • ·Load balancers, gateways, proxies and middleboxes must tolerate larger handshakes
  • ·Client and server support must both land before the benefit is real
  • ·Confidentiality protection arrives before authentication protection
Last verified 2026-09-06
Same layer