Re: [TLS] Proposal for hybrid solution using most of the ideas
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Proposal for hybrid solution using most of the ideas



Nasko Oskov wrote:
Session resumption is already secure since it uses existing crypto state as
part of the negotiation. There are no problems in that case.

I don't agree -- session resumption is orthogonal to renegotiation, at
least in my own code.  A MITM could exploit that.  This is one part of
RI that I agree with.

Mike

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.