On Sat, Aug 13, 2022, at 04:13, Scott Fluhrer (sfluhrer) wrote: > Well, if we were to discuss some suggested hybrids (and we now know the > NIST selection), I would suggest these possibilities: > > - X25519 + Kyber512 > - P256 + Kyber512 > - X448 + Kyber768 > - P384 + Kyber768
Any specific pairs of primitives should be specified in a different document to this one. Ultimately, I want fewer choices, but the direction the discussion is headed seems about right. At least in the short term, I think we need to eschew compression and only include one offer. Partly because I think that there might be better options available to us than compression, partly because compression will be annoying to implement correctly, and partly because we're still in the phase where this is being trialed. _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls