On 03/30/2017 08:47 AM, Andreas Straub wrote: > GCM also isn't > quite as easily available on some platforms as we'd like, whereas CBC > and HMAC are pretty much ubiquitous.
The HTTP/2 spec mandates support of TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 [1] and I'd guess HTTP/2 is already supported everywhere that any OMEMO client would live. I'd rather see it use an AEAD algorithm than hold back due to outdated reasons. [1]: https://tools.ietf.org/html/rfc7540#section-9.2.2 _______________________________________________ Standards mailing list Info: https://mail.jabber.org/mailman/listinfo/standards Unsubscribe: [email protected] _______________________________________________
