On 15/07/2026 20:52, Erwin Hoffmann wrote:
b) Composite keys: Here, we have one cert in flight with two different
algs. Certs are used for auth only, thus some mechanism needs to be
defined to allow (PKI) verification.

Not only that: the TLS server is IMO more likely to need to support
multiple composite private keys in order to interop with almost any
client. There's a combinatoric problem there, given that we can't
seem to downselect to only a few composites despite trying over and
over.

There are pros and cons of dual vs. composite for the TLS server
package maintainer that we should, but typically don't much, include
in WG discussions.

S.

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to