BoringSSL (Chrome) generates a new keypair for each connection. We do too.
ML-KEM keygen is quite cheap anyway.

On Fri, Nov 1, 2024 at 1:11 PM Salz, Rich <rsalz=40akamai....@dmarc.ietf.org>
wrote:

> Are folks generating a new key every connection or just using a
> longer-lived keypair and not re-using the random?
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-le...@ietf.org
>
_______________________________________________
TLS mailing list -- tls@ietf.org
To unsubscribe send an email to tls-le...@ietf.org

Reply via email to