> On May 10, 2018, at 10:17 AM, Eric Rescorla <e...@rtfm.com> wrote:
> 
>> Do you prepend some new "magic" to the (RFC5077 or similar) session
>> tickets?  Or just look for a matching STEK key name and let that be
>> the "magic"?
> 
> I would imagine, but NSS, at least, doesn't support external PSKs.

Good to know.  Does any implementation other than OpenSSL support
external PSKs?  How do you distinguish between external PSKs and
resumption PSKs?

-- 
        Viktor.

_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to