[TLS] Re: Fwd: New Version Notification for draft-yusef-tl s-pqt-dual-certs-02.txt
Stephen Farrell <[email protected]> Wed, 15 Jul 2026 22:18:21 +0100
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <[email protected]> |
On 15/07/2026 20:52, Erwin Hoffmann wrote: > b) Composite keys: Here, we have one cert in flight with two different > algs. Certs are used for auth only, thus some mechanism needs to be > defined to allow (PKI) verification. Not only that: the TLS server is IMO more likely to need to support multiple composite private keys in order to interop with almost any client. There's a combinatoric problem there, given that we can't seem to downselect to only a few composites despite trying over and over. There are pros and cons of dual vs. composite for the TLS server package maintainer that we should, but typically don't much, include in WG discussions. S. _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
OpenPGP_signature.asc
(application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE----- wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCalf5HQUDAAAAAAAKCRDk2On5l6gz3Sjn AQCLrC8N5PeIf2iC5adsVATgpylFcEm0Zq6612RdaauIkQEAiu+Wly2oYMBIZbTmuAQ42XzYDfh2 1IBoP9YY2un8hgg= =zPop -----END PGP SIGNATURE-----