On Sat, Aug 13, 2022, at 04:13, Scott Fluhrer (sfluhrer) wrote:
> Well, if we were to discuss some suggested hybrids (and we now know the 
> NIST selection), I would suggest these possibilities:
>
> - X25519 + Kyber512
> - P256 + Kyber512
> - X448 + Kyber768
> - P384 + Kyber768

Any specific pairs of primitives should be specified in a different document to 
this one.

Ultimately, I want fewer choices, but the direction the discussion is headed 
seems about right.  At least in the short term, I think we need to eschew 
compression and only include one offer.  Partly because I think that there 
might be better options available to us than compression, partly because 
compression will be annoying to implement correctly, and partly because we're 
still in the phase where this is being trialed.

_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to