This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 48 · Nov 24 – 30, 2025

crypto/tls: add support for NIST curve based ML‑KEM hybrids

Nice to knowstdlib

What changed
The proposal adds two hybrid ML‑KEM groups that use NIST curves to the TLS draft.
Production impact
The source does not say.
Try it
Read the proposal to see the group names.
Source
github.com/golang/go/issues/71206

Understand it, then run it

Run it now

Todaygo
// This program runs in Go 1.27.1 and shows that the new hybrid groups
// (SecP256r1MLKEM768 and SecP384r1MLKEM1024) are not yet available
// in the standard library.  The list of cipher suites is printed
// to illustrate the current capabilities.

package main

import (
	"crypto/tls"
	"fmt"
)

func main() {
	// Retrieve the list of cipher suites that crypto/tls currently supports.
	suites := tls.CipherSuites()

	// Print the names of the supported cipher suites.
	fmt.Println("Supported TLS cipher suites:")
	for _, s := range suites {
		fmt.Println("-", s.Name)
	}

	// Check whether the proposed hybrid groups are present.
	hasSecP256r1MLKEM768 := false
	hasSecP384r1MLKEM1024 := false
	for _, s := range suites {
		if s.Name == "SecP256r1MLKEM768" {
			hasSecP256r1MLKEM768 = true
		}
		if s.Name == "SecP384r1MLKEM1024" {
			hasSecP384r1MLKEM1024 = true
		}
	}

	fmt.Printf("\nSecP256r1MLKEM768 present: %v\n", hasSecP256r1MLKEM768)
	fmt.Printf("SecP384r1MLKEM1024 present: %v\n", hasSecP384r1MLKEM1024)
}

What it printed when we ran it on Go 1.27.1

Supported TLS cipher suites:
- TLS_AES_128_GCM_SHA256
- TLS_AES_256_GCM_SHA384
- TLS_CHACHA20_POLY1305_SHA256
- TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
- TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256

SecP256r1MLKEM768 present: false
SecP384r1MLKEM1024 present: false

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed