Hi folks,

https://github.com/tlswg/tls13-spec/pull/699/files

A while back Steven Valdez pointed out that now that we have the PSK binder
change and dual key ladders, each set of traffic keys is generated from a
different
base secret which has a label folded in [0], so we don't need to have the
"phase" parameter in the traffic key calculation in Section 7.3, which
simplifies things
a bit. Due to an oversight, this didn't make it into the PR, but it seems
straightforward.

Please let me know ASAP if I have missed something here or you otherwise
object.

-Ekr


[0] client_early_traffic_secret, [sender]_handshake_traffic_secret,
[sender]_traffic_secret_N respectively
_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to