Hi EKR,
> I agree we shouldn't *disable* key_share, but it seems like the right > answer here is to instead combine the PAKE output with the existing key > establishment. > I probably just missed this in the discussion, but what would be the advantage of combining PAKE with the existing key exchange? I'm not necessarily opposed. My main motivation is to reduce some complexity in the draft. Chris P.
_______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-le...@ietf.org