Re: [TLS] Choice of Additional Data Computation

2020-05-16 Thread Felix Günther
Hi, On 2020-05-15 22:04 +0200, Eric Rescorla wrote: > Actually, the full epoch is included in the overall sequence number and > hence used to generate the nonce. > > https://tools.ietf.org/html/draft-ietf-tls-dtls13-37#section-4 > > Does that help? Sorry, I forgot about reading this difference

Re: [TLS] Choice of Additional Data Computation

2020-05-16 Thread Hanno Becker
> Actually, the full epoch is included in the overall sequence number and hence > used to generate the nonce. Good point Ekr, I missed that. So, we're here at the moment: (1) Only the CID issue really _needs_ fixing somehow. (2) Other header fields are currently authenticated through a mixture o