> - PFS or pure-PSK only.
> 
> Small things can't do PFS unfortunately.

The TLS WG wants to work on a a way to combine a PSK with (EC)DH after the 
current specification is finished for quantum protection.  Of course, that PSK 
must be distributed without any public-key crypto or it will not provide any 
quantum protection.

Russ

_______________________________________________
TLS mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/tls

Reply via email to