tlswg / tls13-spec

TLS 1.3 Specification
562 stars 158 forks source link

#1281 describe effects of creating new long-term keys #1282

Closed emanjon closed 1 year ago

emanjon commented 1 year ago

I think it would make sense to give more guidance on what to do when the connection closes.

1281

emanjon commented 1 year ago

Can we just describe in non-normative prose the risks/hazards of failing to do so?

Yes, that seems like an acceptable outcome that it likely is easy to reach consensus about. I'll change the PR to do that.

emanjon commented 1 year ago

@kaduk I made a new proposal. Just stating that the "Forward secret with respect to long-term keys" is no longer satisfied if the implementation creates new long-term keys. I did not describe the risks/hazards of failing to do so as I feel it would be too long and detailed to describe al the cases.

emanjon commented 1 year ago

Ben's rewriting has been merged and the two comments from Martin has been addressed.