On 15 November 2016 at 09:28, Eric Rescorla <e...@rtfm.com> wrote: > One way to split the difference between these two would be to use an > extension to negotiate the encrypted record format.
Yes, that could work. It would need special rules for 0-RTT, but in theory a negotiated extension could do anything to the protocol. _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls