> - PFS or pure-PSK only. > > Small things can't do PFS unfortunately.
The TLS WG wants to work on a a way to combine a PSK with (EC)DH after the current specification is finished for quantum protection. Of course, that PSK must be distributed without any public-key crypto or it will not provide any quantum protection. Russ
_______________________________________________ TLS mailing list [email protected] https://www.ietf.org/mailman/listinfo/tls
