Re: [TLS] DSA support in TLS 1.3.

2015-08-28 Thread Ronald del Rosario
ECDSA can be smaller, faster, and more secure all at once; and if you don't like ECDSA or want an alternative, there's RSA. Isn't that a step backward reverting to RSA? Ron F. Del Rosario CONFIDENTIALITY NOTICE: This e-mail and any files attached may contain

Re: [TLS] Deprecate DH_anon in favor of raw public keys?

2015-08-28 Thread Ronald del Rosario
Or what we do in WebRTC, which uses a certificate that has no good information in it?” +1. Anxiously waiting for response on this, as I am currently helping non-profit groups build a private and secure P2P Messaging System using WebRTC, which of course utilizes encrypted P2P connection between

[TLS] Request for information: Lightweight Mutual Authentication for Constrained Devices?

2016-02-23 Thread Ronald del Rosario
Greetings TLS Group, Looking for standards/drafts/documentation or similar research discussing a mutual authentication framework for contained devices (Devices with limited processing power, battery, runs on wireless Network) Thanks in advance, Ron

Re: [TLS] Industry Concerns about TLS 1.3

2016-09-27 Thread Ronald del Rosario
+1 to Tony I am also in charge of enforcing TLS Standards in our CDE. I also do not speak on behalf of my employer, but: PCI extended the migration from SSLv3 and TLS 1.0 to a secure version (TLS 1.1 or higher) until June