Joseph Salowey <> writes:

>At IETF 119 we had discussion that static DH certificates lead to static key
>exchange which is undesirable.

Has anyone every seen one of these things, meaning a legitimate CA-issued one
rather than something someone ran up in their basement for fun?  If you have,
can I have a copy for the archives?

The only time I've ever seen one was some custom-created ones for S/MIME when
the RSA patent was still in force and we were supposed to pretend to use
static-ephemeral DH for key transport instead of RSA.


TLS mailing list

Reply via email to