Closed hannestschofenig closed 9 months ago
I agree that less is more. Selecting a subset of those chosen by MLS sounds like a good starting point.
Unfortunately, there are problems with choosing subset from MLS cipher suites:
What I think is the absolute minimum:
... But I still think all the 18 should be supported.
Remember, this is not about what individual application needs to support (it can profile down to single cipher suite), it is about what any application can support.
And if non-base modes are to be supported, this obviously causes combinatorial blowup.
We have to remove Kyber from the list since it would block the publication of this document. So far I haven't heard anyone from the constrained IoT device community asking for the compact curves. They probably don't use HPKE in the first place.
PR with the reduced ciphersuite list created here: #48
The group needs to decide what ciphersuites it wants to have listed in the draft. The idea is to only list those ciphersuites that are needed by developers rather than exhaustively listing all combinations.
Input appreciated!