Re: Any drafts for IMAP4/TLS and/or POP3/TLS
[email protected] (David P. Kemp) Tue, 2 Sep 1997 09:43:38 -0400
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <[email protected]> |
> From: David Brownell <[email protected]> > > [many good points snipped ..] > > Finally, I wonder where one would want to put a conventional set > of Diffie-Hellman parameters (modulus, exponent) that "MAY" be used > by TLS servers implementing this spec. The virtue of having such a > set which "MAY" be used is that to the extent they're widely used, > clients can precompute their private keys, producing better TLS > session setup times (one less prime search, one less modExp). > Of course the idea is not to mandaate ("MUST") such parameters. > There are both security and performance implications to the modulus > (specifically, its size) being used. > > Arguably such a set of parameters should be in the TLS spec. > But, it's not there now, and not looking to be. Perhaps it'd > be approprate as a separate informational RFC, rather than as > part of either the IETF's TLS or {IMAP4,POP3}/TLS specs. If the IMAP/POP profile were to specify one or a few fixed DH parameters, it may be worthwhile referencing the exponential groups in the IPsec Oakley protocol, instead of writing up another document with different parameters.