On Thu, May 10, 2018 at 8:46 AM, Viktor Dukhovni <ietf-d...@dukhovni.org>
wrote:

>
>
> > On May 10, 2018, at 10:17 AM, Eric Rescorla <e...@rtfm.com> wrote:
> >
> >> Do you prepend some new "magic" to the (RFC5077 or similar) session
> >> tickets?  Or just look for a matching STEK key name and let that be
> >> the "magic"?
> >
> > I would imagine, but NSS, at least, doesn't support external PSKs.
>
> Good to know.  Does any implementation other than OpenSSL support
> external PSKs?  How do you distinguish between external PSKs and
> resumption PSKs?
>

Mint does, but it doesn't implement session tickets, so they're just in one
giant database.

-Ekr


> --
>         Viktor.
>
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls
>
_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to