On Mon, Sep 16, 2019, at 05:28, Peter Gutmann wrote: > Just out of curiosity, why do you say EtM is a non-starter? It neatly fixes > the problems caused my MtE.
I don't know that many stacks implement it. We don't. There's nothing wrong with it, but it's down to practicalities. My understand is that implementing MtE isn't justified relative to just moving to an AEAD. _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls