On 15/07/2026 20:52, Erwin Hoffmann wrote:
b) Composite keys: Here, we have one cert in flight with two different algs. Certs are used for auth only, thus some mechanism needs to be defined to allow (PKI) verification.
Not only that: the TLS server is IMO more likely to need to support multiple composite private keys in order to interop with almost any client. There's a combinatoric problem there, given that we can't seem to downselect to only a few composites despite trying over and over. There are pros and cons of dual vs. composite for the TLS server package maintainer that we should, but typically don't much, include in WG discussions. S.
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
