CT-KIP ServerFinished Extension New extension in ServerFinished is used by CT-KIP server to transfer key to CT-KIP client Key material is wrapped in token’s public key or symmetric key Token’s public key may have been included in payload of ClientHello Symmetric key may be a shared secret Symmetric key may be derived from a passphrase Extension is applicable to both 1-pass and 2-pass variants of CT-KIP Extension could easily be added to support PSKC defined in draft-vassilev-portable-symmetric-key-container-01.txt |