I have reviewed this document as part of the Ops area directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the Ops area directors. Document editors and WG chairs should treat these comments just like any other last-call comments. Summary: This draft defines the algorithm identifiers and encoding conventions for using the quantum-resistant SLH-DSA signature scheme within the X.509 Public Key Infrastructure. Major issue: I’m not an expert in this area, so I’d like to ask: given that the same or very similar OIDs are used for both Pure SLH-DSA and Hash SLH-DSA, is there a high risk of accidentally mixing up the two modes during implementation or certificate processing? If so, would it be helpful to include additional guidance in the draft to help avoid such misconfiguration? Best Regards, Linda Dunbar