Re: [TLS] DH group validation
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] DH group validation
Eric Rescorla <ekr at networkresonance.com> writes:
>One of the remaining TODOs in TLS 1.2 is what (if anything) the client should
>do to validate the server's offered DH group.
Isn't this trivially solveable by switching from PKCS #3 to DSA/X9.42/<generic
DLP key mechanism> and referring to any standard that tells people how to
apply this? Presumably all it'd take is the addition of fields for the new
DLP key parameters, and a reference to the standard of choice for how to
generate and verify the keys.
Peter.
_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.