*
I also could see folks trying to avoid the HRR
  *
altogether and rip the X25519 out of the hybrid key
  *
share  and use immediately.  That's not a "reuse", I
  *
suppose, but still seems a bad idea.

Can you say why?  My inclination would be to codify it and say that any hybrid 
keyshare could be used for its constituent parts unless the definition of the 
hybrid says otherwise.
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to