> I think we would like to avoid deliberately breaking these devices with TLS > 1.3. (I think TLS 1.3 has been subject to enough friction already.)
I'm not sure I can agree with fixing TLS 1.3 so that it can work with potentially backdoored devices. Isn't it the kind of friction we would want? David _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls