Re: [TLS] External PSK with certificate-based authentication

2017-12-07 Thread Russ Housley
> On Dec 2, 2017, at 1:51 PM, Eric Rescorla wrote: > > On Sat, Dec 2, 2017 at 10:10 AM, Russ Housley > wrote: > At the bottom of page 136, the current draft says: > >Note: TLS does not currently permit the server to send a >certificate_request message in no

Re: [TLS] External PSK with certificate-based authentication

2017-12-02 Thread Eric Rescorla
On Sat, Dec 2, 2017 at 10:10 AM, Russ Housley wrote: > At the bottom of page 136, the current draft says: > >Note: TLS does not currently permit the server to send a >certificate_request message in non-certificate-based handshakes >(e.g., PSK). If this restriction were to be relaxed

[TLS] External PSK with certificate-based authentication

2017-12-02 Thread Russ Housley
At the bottom of page 136, the current draft says: Note: TLS does not currently permit the server to send a certificate_request message in non-certificate-based handshakes (e.g., PSK). If this restriction were to be relaxed in future, the client's signature would not cover the server'