[TLS] Re: draft-ietf-tls-rfc9147bis: PQC key share CH frag mentation vs stateless server

Sophie Schmieg <[email protected]>
Newsgroups gmane.ietf.tls
Message-ID <CAEEbLAZ_BK6A4TgknuV12oy5UEEePWo4xx3eW_PGW7xERZDonw@mail.gmail.com>
I don't see it being feasible to force every client/server pair that wants
to use PQC through the HRR path. We already have a similar problem as is,
in that the client currently can really only afford to add one PQC
keyshare, so if the server wants a different choice of parameters or a
different algorithm altogether, there is a forced HRR roundtrip. From
talking to various folks, PQC is currently only seen as feasible because of
there being a single guess and that single guess usually succeeding. I
cannot see a solution that forces an extra roundtrip on everyone
succeeding. Maybe the stateless server can sent an HRR no matter what
fragment it receives, indicating that it is a stateless server and needs
information packaged up the right way?

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.