Re: [TLS] PSS and 1.2

2016-07-24 Thread Martin Thomson
On 24 July 2016 at 13:26, Ilari Liusvaara wrote: > The legacy type of RSA-PSS is RSA, right? If I understand you correctly, then yes. When (if) the proposed revamp goes ahead, we will have to qualify this with the note that this can only be used with TLS_*_RSA_... We should probably say somethi

Re: [TLS] PSS and 1.2

2016-07-24 Thread Martin Thomson
Actually, I just realized that I should do this anyway. On 24 July 2016 at 22:33, Martin Thomson wrote: > On 24 July 2016 at 13:26, Ilari Liusvaara wrote: >> The legacy type of RSA-PSS is RSA, right? > > If I understand you correctly, then yes. When (if) the proposed > revamp goes ahead, we wil

Re: [TLS] PSS and 1.2

2016-07-24 Thread Ilari Liusvaara
On Sun, Jul 24, 2016 at 11:45:48AM +0200, Martin Thomson wrote: > David Benjamin noted that we really need to decide whether PSS was > something that we should have supported in TLS 1.2. We can't have a > situation where there are two implementations of 1.3 that for some > reason have 1.3 disabled

Re: [TLS] PSS and 1.2

2016-07-24 Thread Eric Rescorla
I am in favor of this change. We should be trying to move to PSS in general and there's no reason why 1.3 clients which support PSS can't also support it for 1.2 -Ekr On Sun, Jul 24, 2016 at 11:45 AM, Martin Thomson wrote: > David Benjamin noted that we really need to decide whether PSS was >