> On May 10, 2018, at 10:17 AM, Eric Rescorla <[email protected]> wrote:
>
>> Do you prepend some new "magic" to the (RFC5077 or similar) session
>> tickets? Or just look for a matching STEK key name and let that be
>> the "magic"?
>
> I would imagine, but NSS, at least, doesn't support external PSKs.
Good to know. Does any implementation other than OpenSSL support
external PSKs? How do you distinguish between external PSKs and
resumption PSKs?
--
Viktor.
_______________________________________________
TLS mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/tls