Skip to main content

Complaint regarding a declaration of consensus to adopt a non-hybrid draft (D. J. Bernstein) - 2025-08-12
Response - 2025-10-01

Summary

The IESG received an appeal from Dan Bernstein on August 12, 2025 for the decision of the TLS Working Group (“WG”) Chairs for declaring a rough consensus to adopt draft-connolly-tls-mlkem-key-agreement. Additionally, this appeal requested the IESG to determine whether one or more process failures occurred during the handling of the appellant's complaint on this TLS WG matter by the Security Area Directors.

SEC ADs Paul Wouters and Deb Cooley did not participate in the processing of this appeal.

The IESG has concluded that there were no process failures by the SEC ADs. The IESG declines to directly address the complaint on the TLS WG document adoption matter. Instead, the appellant should refile their complaint with the SEC ADs in a manner which conforms to specified process.

The appeal is denied.

Timeline of Events

On April 1, 2025, the TLS WG Chairs began an WG adoption call for draft-connolly-tls-mlkem-key-agreement.

On April 15, 2025:

On April 16, 2025:

On April 18, 2025:

On June 5, 2025, the appelant sent an e-mail to the Security Area Directors (ADs), copying the TLS working group list, containing a link to a PDF file. The PDF contained a document titled “Complaint regarding a declaration of consensus to adopt a non-hybrid draft” and addressed the Security Area Directors, Paul Wouters and Deb Cooley. The document also contained language repudiating the rights granted to the IETF in Contributions under the various BCPs referenced in the Note Well.

Paul Wouters is the responsible Area Director for the TLS WG. On June 12, 2025, AD Wouters declined to process the e-mail or PDF as a valid complaint to the Area Director(s) under RFC 2026, Section 6.5.1. In this e-mail, AD Wouters noted that as AD Cooley is not the responsible AD for the implicated working group, she did not participate in handling the complaint.

On June 14, 2025, Dan Bernstein responded to AD Wouter’s e-mail contending that his previous e-mail was a valid complaint to the Area Directors and must be processed. AD Wouters did not respond further.

On August 12, 2025, Dan Bernstein sent a nearly identical e-mail to the IESG, copying the TLS list, containing a link to a PDF. The PDF contained a document with the same title and substantially similar text as that referenced by his e-mail of June 5, with added text describing his interactions with AD Wouters. The document contains an appeal to the IESG of both the original matter and AD Wouters’s subsequent handling of the complaint.

Understanding of the Complaints

(WG Process Complaint #1) The appellant believes that consensus was inappropriately declared by the TLS WG chairs for the adoption of draft-connolly-tls-mlkem-key-agreement.

The appellant also asks the IESG to determine whether one or more process failures occurred during the handling of appellant's complaint of June 5 to the SEC ADs; specifically whether:

  • (AD Process Complaint #1) AD Wouters responded to a complaint directed to the WG chairs (https://mailarchive.ietf.org/arch/msg/tls/RK1HQB7Y-WFBxQaAveeT7pHZbbc/), mixing process clarifications with commentary on the substance of the complaint.
  • (AD Process Complaint #2) ADs Cooley and Wouters erred in not conducting all discussion of appellant’s complaint on public mailing lists as the appellant requested;
  • (AD Process Complaint #3) ADs Cooley and Wouters erred by assigning the handling of appellant’s complaint to the responsible AD rather than responding jointly;
  • (AD Process Complaint #4) AD Wouters erred in rejecting the appellant’s complaint as invalid and for declining to process it further.

The IESG notes that the appellant’s appeal itself was presented to the IESG in the same manner that he had already been advised was potentially invalid; if the complaint to AD Wouters was invalid then the appellant’s submission in this matter might also be, and no valid appeal would be before the IESG at this time. The IESG chooses to overlook this potential contradiction in order to clarify the issue.

The appellant also repeats his assertion that private conversations between chairs, Area Directors, and other members of IETF leadership are prohibited and all discussions of his complaints and appeals must be conducted on public mailing lists or in minuted meetings.

AD Process Complaint #1: Responsibility of Chairs vs ADs

In his April 16 response to the appellant's complaint, AD Wouters responded to the substance of a complaint directed to the WG chairs as noted by the appellant, while providing process clarifications.

The IESG concludes the substance points made by Paul Wouters were intended to save the appellant time, by providing the framing with which the responsible AD would process a possible appeal should one be received. Per Section 6.1 of RFC2418, “the AD has the authority and the responsibility to assist in making those decisions at the request of the Chair or when circumstances warrant such an intervention.”

This process complaint is dismissed.

AD Process Complaint #2: Transparency and IESG Communication

The appellant makes this summary of his claim:

…secret discussions among the ADs or other arbiters are not permitted by the record-keeping requirements in BCP 9, and are not permitted by IETF’s requirement of “extreme transparency”.

The IESG notes that this is at least the second appeal in which the appellant has raised requirements of "extreme transparency”. The appellant has been answered previously.

On the “record-keeping requirements”, Section 8 of RFC 2026 (BCP 9) states that:

Each of the organizations involved in the development and approval of Internet Standards shall publicly announce, and shall maintain a publicly accessible record of, every activity in which it engages, to the extent that the activity represents the prosecution of any part of the Internet Standards Process. For purposes of this section, the organizations involved in the development and approval of Internet Standards includes the IETF, the IESG, the IAB, all IETF Working Groups, and the Internet Society Board of Trustees.

[...]

The formal record of an organization's standards-related activity shall include at least the following:

  • the charter of the organization (or a defining document equivalent to a charter);
  • complete and accurate minutes of meetings;
  • the archives of Working Group electronic mail mailing lists; and
  • all written contributions from participants that pertain to the organization's standards-related activity.

These requirements indeed apply to the IESG. The IESG’s formal meetings are open to observers, recorded, and minutes are published by the Secretariat as specified. Official decisions of the IESG are confirmed and minuted during such formal meetings.

However, Section 3.2 of RFC 3710 goes into more detail about the IESG specifically:

The IESG publishes a record of decisions from its meetings on the Internet, and conducts an open meeting at every IETF meeting. It publishes more detailed documentation of decisions as RFCs, Internet Drafts or messages to the IETF-announce mailing list, with copies kept on the IETF website when appropriate.

The IESG also has private group discussions, using any means of its choice, including email. Records of those discussions are not required to be made public. This is believed to be vital in permitting a frank exchange of viewpoints and worries, allowing people to speak out freely on topics known to be controversial, and permitting people to change their minds based on presented arguments. Decisions and their justification are a matter of public record.

Additionally, Section 6.5.4 of RFC 2026 states:

At all stages of the appeals process, the individuals or bodies responsible for making the decisions have the discretion to define the specific procedures they will follow in the process of making their decision.

The appellant has misinterpreted the record-keeping requirements of RFC 2026. With respect to appeals, this requirement applies to the public notice and maintenance of the appeals and their outcomes. That is, RFC 2026 prohibits appeals from being ignored and the outcomes of appeals from being kept secret; it does not require that every conversation be recorded or that every working-copy of an appeal response be made public.

The IESG concludes that ADs Cooley and Wouters did not err in conducting any discussions they may have had regarding the management of their Area via means other than a public mailing list. As a general principle, the IESG (both jointly and individually) may conduct private discussions when working toward decisions, provided that the decisions themselves and their rationale are presented publicly.

This process complaint is dismissed.

AD Process Complaint #3: Delegation of Responsibility between Area Directors

RFC 2418, as updated by RFC 7475, defines an Area as a “management division within the IETF” which “is managed by one or more Area Directors.” BCP 9 says that a complaint about working group procedure may be addressed to “the Area Director(s) for the area in which the Working Group is chartered.”

Section 4 of RFC 3710 says that:

The IESG is in charge of managing the working group process. While the process of managing a working group is assigned to the working group chairs, the IESG is in charge of those processes that are beyond the scope of the working group chair's role. Most of these functions are delegated by the IESG to a single Area Director - the "responsible Area Director" for the group.

Further, in Section 7.4, it says regarding appeals specifically:

Most decisions by a working group chair can be appealed to the AD, and decisions by an individual AD can be appealed to the IESG.

The appellant addressed his complaint of June 5 to ADs Wouters and Cooley jointly, as the Area Directors for the Security area, where the TLS working group is chartered. In AD Wouter’s response, he said that:

First, the Security Area Directors have divided their work based on Working Groups, with me being the responsible AD for the TLS WG so as per the Security Area workflow decided by the Security Area Directors, I will be the only Area Director handling your message at this point, which is presumably aimed to be a message under BCP 9 (RFC 2026) Section 6.5.1.

The appellant argues that the Security Area Directors are jointly responsible for attempting to address his complaint, and that the delegation of this responsibility to only one of the Area Directors was a process failure.

However, Section 6.5.4 of RFC 2026 states that:

At all stages of the appeals process, the individuals or bodies responsible for making the decisions have the discretion to define the specific procedures they will follow in the process of making their decision.

The IESG concludes that while appellant is correct that both ADs Wouters and Cooley are ultimately responsible for managing the resolution of his complaint, choosing to delegate this responsibility to one of the Area Directors is a valid exercise of the discretion granted by BCP 9.

This process complaint is dismissed.

AD Process Complaint #4: Validity of Complaint Submission

In his June 12 response to appellant's complaint, AD Wouters raised the following objections to the format of this complaint:

  • (Filtered email) Appellant sent the complaint from an e-mail account which does not permit incoming messages unless the sender agrees to potentially 'pay Professor Bernstein $250'.
  • (Applicability of the Note Well) Conflict between statements in the referenced PDF and the terms of the IETF Note Well

On Filtered Email Accounts

The IESG finds that use of a filtered e-mail account is not an automatic bar to participating in the Internet Standards Process and is not itself a valid reason to refuse a complaint. However, the IESG cautions the appellant that any non-receipt of messages sent to him (e.g., the message from the IETF Executive Director alluded to in AD Wouter’s response) in no way reduces the effect of those messages in the Standards Process. Thus, if a participant failed to learn of a decision they wished to appeal within the two-month timeframe allotted for such appeals, an appeal would nonetheless be untimely.

This element of the process claim is supported by the IESG in that it recognizes that participation in the Standards Process is possible, albeit not recommended, with an email account which filters incoming email.

On the Applicability of the Note Well

In response to the appelant, AD Wouters directed that the appellant resubmit the complaint in a format that was explicitly subject to the policies referenced in the IETF Note Well, either directly to AD Wouters or via the TLS working group mailing list. It indicated that a failure to do so would be considered abandonment of the attempt to file a complaint with the Area Director. Finally, the message alerted the appellant that they were free to appeal the refusal to process the unamended complaint to the IESG. This response is to that appeal.

The statement from the PDF referenced by the June 5 email from the appellant that AD Wouters indicated was problematic is the following:

Finally, I have recently become aware that IETF Administration LLC believes that it can force parties to trade away other rights in exchange for exercising their rights to appeal. Concretely, IETF Administration LLC appears to believe that it is free to post modified versions of complaints, and that it is free to falsely attribute those modified versions to the original author, without regard to copyright law, moral-rights law (e.g., integrity rights), fraud law, etc. To be clear, those beliefs are incorrect. I have never consented to, and do not consent to, any such trade.

The appellant characterizes this text as “a reminder of various rights, such as copyrights and the right to appeal” which “exist whether or not they're pointed out.”

However, the IESG assesses that this text is far more than a reminder – it is a claim that the appellant has not and does not consent to the rights granted to the IETF under BCP 78 which says that an IETF Contribution is:

any submission to the IETF intended by the Contributor for publication as all or part of an Internet-Draft or RFC (except for RFC Editor Contributions described in Section 4 below) and any statement made within the context of an IETF activity. Such statements include oral statements in IETF sessions as well as written and electronic communications, made at any time or place, that are addressed to:

  • the IETF plenary session,
  • any IETF working group or portion thereof,
  • any Birds of a Feather (BOF) session,
  • the IESG, or any member thereof on behalf of the IESG,
  • the IAB, or any member thereof on behalf of the IAB,
  • any IETF mailing list, including the IETF list itself, any working group or design team list, or any other list functioning under IETF auspices,
  • the RFC Editor or the Internet-Drafts function (except for RFC Editor Contributions, as described in Section 4 below).

Additionally, the appellant was previously advised by the IETF Executive Director that a complaint to an Area Director or an appeal to the IESG is clearly an “electronic communication [...] addressed to [...] the IESG, or any member thereof on behalf of the IESG,” and thus any complaint or appeal is necessarily a Contribution. Under BCP 78, a contributor grants various rights to the IETF in all contributions, including the rights:

(a) to copy, publish, display, and distribute the Contribution, in whole or in part,
(b) to prepare translations of the Contribution into languages other than English, in whole or in part, and to copy, publish, display, and distribute such translations or portions thereof,
(c) to modify or prepare derivative works (in addition to translations) that are based on or incorporate all or part of the Contribution, and to copy, publish, display, and distribute such derivative works, or portions thereof unless explicitly disallowed in the notices contained in a Contribution (in the form specified by the Legend Instructions),

Thus, the appellant’s language repudiating the rights granted the IETF under BCP 78 is inappropriate. It creates ambiguity about whether the PDF was a Contribution – from context it appears to be, but it contains language saying it is not.

BCP 78 does not directly address the handling of participants who refuse to grant the rights it describes. However, it and other BCPs do consider related situations which may guide us in this case.

First, BCP 79 describes the expected behavior for participants who are unable or unwilling to grant the IPR rights imposed on Contributions – such a participant “must not contribute to or participate in IETF activities.” A similar principle can be applied to participants who are unable or unwilling to grant the other rights entailed in making IETF Contributions. Such participants must not make Contributions.

Secondly, as AD Wouters noted in his reply, BCP 78 considers Contributions which contain language repudiating other rights granted to the IETF by the act of making a Contribution:

No information or document that is subject to any requirement of confidentiality or any restriction on its dissemination may be submitted as a Contribution or otherwise considered in any part of the IETF Standards Process, and there must be no assumption of any confidentiality obligation with respect to any Contribution. Each Contributor agrees that any statement in a Contribution, whether generated automatically or otherwise, that states or implies that the Contribution is confidential or subject to any privilege, can be disregarded for all purposes, and will be of no force or effect.

The appellant dismissed this by saying that:

My complaint is not confidential. Creating derived works, as IESG did with a previous PDF, is modification, not dissemination.

Notwithstanding this, a refusal to grant the rights required by BCP 78 is a claim to reserve a privilege in the Contribution. Either the appellant has implicitly agreed that their claim “can be disregarded for all purposes and will be of no force or effect” or the appellant has knowingly violated the requirements of BCP 78.

The IESG finds that it was appropriate for AD Wouters to ask the appellant to clarify whether he was agreeing that his claims can be disregarded or was declining to participate further in IETF activities. Appellant’s e-mail of June 14 did not clarify which of these cases he chooses to proceed under, but insisted that AD Wouters proceed with the substance of the unamended complaint in parallel with any discussion of the validity of it.

As the appellant neither resubmitted his complaint in a format which was clearly a Contribution nor addressed this question, no processable complaint was submitted to the Security Area Directors. While AD Wouters would have been within his rights to disregard the complaint’s statements under BCP 78, choosing to halt processing and ask the complainant to clarify the situation instead is a valid exercise of his procedural discretion.

This element of the process complaint is dismissed.

WG Process Complaint

For the reasons discussed above, the IESG concludes no valid appeal was sent to the SEC AD processing to resolve the appellant's complaint about the TLS Working Group (“WG”) Chairs declaring a rough consensus to adopt draft-connolly- tls-mlkem-key-agreement. Therefore, the IESG declines to intervene and instead directs the appellant to file a valid complaint to the SEC ADs for consideration. This approach is consistent with the appeals chain defined in Section 6.5.1 of RFC2026, where WG disputes are first escalated to the responsible AD before they come to the IESG.

Conclusion

The IESG notes that Dan Bernstein did file this appeal to the IESG approximately two months after the response from AD Wouters, and his initial e-mail can be construed as “initiating” the appeal process within the required timeframe.

In accordance with the IESG Statement on Norms and Practices of the Conflict Resolution and Appeals Process, Dan Bernstein has until 14 days from this response to resubmit this complaint to the Security ADs.