[TLS] Channel binding versus keying material exporters
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[TLS] Channel binding versus keying material exporters



Can someone comment on the similarities and differences of TLS channel binding and TLS keying material exporters? Is the keying material derived from a TLS master key using a keying material exporter suitable for channel binding as well, if used for key confirmation? If a higher-level application wishes to do additional authentication and bind the endpoints of that authentication to the endpoints of the TLS connection, should one use key confirmation with keying material exporters or something from TLS channel binding?

Thanks,

Douglas

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.