ace-wg / est-oscore

Other
0 stars 0 forks source link

Additional optimization in 3.4 #28

Closed gselander closed 8 months ago

gselander commented 8 months ago

Add one bullet describing optionality to enroll static DH keys. Something like:

The PKCS#10 request MAY request a certificate for a static DH key instead of a signature key resulting in a more compact CSR with a MAC instead of a signature. Additionally, subsequent EDHOC sessions using static DH keys for authentication has less overhead that key exchange protocols using signature based authentication credentials.