Re: [TLS] Merkle Tree Certificates

2023-03-20 Thread David Benjamin
Hi Panos, > - Previously, in the ICA suppression draft you had correctly brought up the challenge of keeping an up-to-date ICA cache while most browsers are not up to date. The Merkle tree mechanism requires constant updates. Would that be even more of challenge with browsers that have not been up

Re: [TLS] Merkle Tree Certificates

2023-03-20 Thread David Benjamin
I don't think flattening is the right way to look at it. See my other reply for a discussion about flattening, and how this does a bit more than that. (It also handles SCTs.) As for RFC 7924, in this context you should think of it as a funny kind of TLS resumption. In clients that talk to many ser