[TLS] Channel binding versus keying material exporters
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[TLS] Channel binding versus keying material exporters
Can someone comment on the similarities and differences of TLS channel
binding and TLS keying material exporters? Is the keying material
derived from a TLS master key using a keying material exporter
suitable for channel binding as well, if used for key confirmation?
If a higher-level application wishes to do additional authentication
and bind the endpoints of that authentication to the endpoints of the
TLS connection, should one use key confirmation with keying material
exporters or something from TLS channel binding?
Thanks,
Douglas
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.