Re: [TLS] Draft 18 review : Hello Retry Request and supported groups cache

2016-11-23 Thread Eric Rescorla
On Wed, Nov 23, 2016 at 5:25 AM, Olivier Levillain < olivier.levill...@ssi.gouv.fr> wrote: > >> There were actually two points in my message: > >> - I was not convinced by this way of signalling a preference without > >> enforcing it, but I understand that, if we keep supported_groups, it > >>

Re: [TLS] Draft 18 review : Hello Retry Request and supported groups cache

2016-11-23 Thread Olivier Levillain
>> There were actually two points in my message: >> - I was not convinced by this way of signalling a preference without >> enforcing it, but I understand that, if we keep supported_groups, it >> does not cost much and the client can safely ignore the server sent >> extension; >> - however, I

Re: [TLS] Draft 18 review : Hello Retry Request and supported groups cache

2016-11-23 Thread Eric Rescorla
On Wed, Nov 23, 2016 at 12:19 AM, Olivier Levillain < olivier.levill...@ssi.gouv.fr> wrote: > Hi, > > >> Being able to send supported_groups does allow a server to choose to > make > >> a tradeoff between an extra round trip on the current connection and its > >> own group preferences. One

Re: [TLS] Draft 18 review : Hello Retry Request and supported groups cache

2016-11-23 Thread Olivier Levillain
Hi, >> Being able to send supported_groups does allow a server to choose to make >> a tradeoff between an extra round trip on the current connection and its >> own group preferences. One example where a server might want to do this is >> where it believes that X25519 is likely a more future-proof

Re: [TLS] Draft 18 review : Hello Retry Request and supported groups cache

2016-11-22 Thread Eric Rescorla
On Tue, Nov 22, 2016 at 11:09 AM, Steven Valdez wrote: > Being able to send supported_groups does allow a server to choose to make > a tradeoff between an extra round trip on the current connection and its > own group preferences. One example where a server might want to do

Re: [TLS] Draft 18 review : Hello Retry Request and supported groups cache

2016-11-22 Thread Steven Valdez
Being able to send supported_groups does allow a server to choose to make a tradeoff between an extra round trip on the current connection and its own group preferences. One example where a server might want to do this is where it believes that X25519 is likely a more future-proof group and would