Re: [pkcs11] Sensitivity and extractability of derived keys

From
Michael StJohns
Date
2013-08-14T15:38:00+00:00
ID
Thread
Re: [pkcs11] Sensitivity and extractability of derived keys
On 8/14/2013 6:08 AM, Oscar So wrote: Michael, Can you point me to the section of the spec which mentions 3) ?
Robert mostly copied the TLS12 stuff from TLS.
That text is in the TLS (2.25.5) section (and is in the SSL 2.24.5 section as well).
I haven't had a chance to look elsewhere.
Mike Also, I believe 3) is an option, an open option.
You do 3) only if you absolutely need it.
Otherwise, by default, one should not do 3).
Thanks!
-Oscar