14.02.2017 Views

Presented by Jason A Donenfeld FOSDEM 2017

2kVT3mc

2kVT3mc

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The Key Exchange<br />

▪ Very limited set of primitives:<br />

▪ Elliptical curve Diffie-Hellman,<br />

hashing, authenticatedencryption.<br />

▪ Just 1-RTT.<br />

▪ Extremely simple to implement in<br />

practice, and doesn’t lead to the<br />

type of complicated messes we<br />

see in OpenSSL and StrongSwan.<br />

▪ No certificates, X.509, or ASN.1:<br />

both sides exchange very short<br />

(32 <strong>by</strong>tes) base64-encoded<br />

public keys, just as with SSH.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!