Re: [TLS] RFC7924 (Cached Information Extension) Update for TLS 1.3

2023-08-15 Thread Simon Mangel
Hi Dennis, > Can you expand more on the intended use case? When would it make sense > to use a RFC7924-like mechanism over TLS 1.3's session resumption? > > I skimmed RFC 7924 and session resumption seems strictly better as it's > already widely deployed, allows for the DH handshake to be optio

Re: [TLS] Abridged Certificate Compression

2023-08-15 Thread Bas Westerbaan
> > If you are going to do this, you might as well go the whole hog and > provide a mechanism that allows the client to say if it already has a cert > on file for that particular host, e.g. by means of a digest. > If clients cache intermediates as they go, then reporting that list to a server is a

Re: [TLS] RFC7924 (Cached Information Extension) Update for TLS 1.3

2023-08-15 Thread Dennis Jackson
Hi Simon, On 15/08/2023 03:41, Simon Mangel wrote: We believe it to be useful in cases where the network bandwidth is severely restricted, such that one would want to keep the number of "full" handshakes as small as possible. Session resumption ticket lifetimes are limited to 7 days in TLS 1.3