> It would be nice to add a note that without proper rotation, PFS is
> compromised by the use of TLS tickets. People may not understand why
> they need to put 3 keys in this file and may never change them.

Agreed, we have to clarify that a never changing tls-tickets-keys
file is worse than no file at all.



> Great feature!

Agreed!



Thank you!

Lukas

                                          

Reply via email to