Why both X25519+Kyber512 and P256+Kyber512?
Because there are good HW implementations supporting P256, and (at least for some people) it’s good enough?
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls