[TLS] Re: draft-ietf-tls-rfc9147bis: PQC key share CH frag mentation vs stateless server
Sophie Schmieg <[email protected]>
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <CAEEbLAZ_BK6A4TgknuV12oy5UEEePWo4xx3eW_PGW7xERZDonw@mail.gmail.com> |
I don't see it being feasible to force every client/server pair that wants to use PQC through the HRR path. We already have a similar problem as is, in that the client currently can really only afford to add one PQC keyshare, so if the server wants a different choice of parameters or a different algorithm altogether, there is a forced HRR roundtrip. From talking to various folks, PQC is currently only seen as feasible because of there being a single guess and that single guess usually succeeding. I cannot see a solution that forces an extra roundtrip on everyone succeeding. Maybe the stateless server can sent an HRR no matter what fragment it receives, indicating that it is a stateless server and needs information packaged up the right way? _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]