Hi Uri,

[trimming heavily since the text/plain component is made of lies and I don't
want to misattribute nested quotes]

On Thu, Apr 17, 2025 at 09:17:29PM +0000, Blumenthal, Uri - 0553 - MITLL wrote:
> 
>    There’s maintenance of the code for both parts of the KEM and ensuring
>    they’re properly integrated, maintenance of parallel PKI structures, need
>    to allocate the costs for two moves [1] instead of one which already makes
>    some users argue (which can be a royal pain in a large deployment), likely
>    many other things I’m too lazy to concentrate on now (besides, there’s
>    that feeling that I don’t need to convince “my” clientele at all, and
>    there’s little chance to convince this audience anyway, which dampens the
>    eagerness to strive).

Thanks for writing up this list.

Just to check my understanding: the PKI only comes into play for signatures,
and there is no PKI needed for ephemeral key exchange as is used in TLS 1.3?
(For the specific case of ephemeral key exchange in TLS 1.3, it seems that the
"move" is just a software update, albeit one that needs heavy testing and in
your enviroment qualification.)

-Ben

_______________________________________________
TLS mailing list -- tls@ietf.org
To unsubscribe send an email to tls-le...@ietf.org

Reply via email to