4 ms·
Is there any reason why in TLS the DH g^x the client sends is not encrypted with the server's RSA key? That way, a DH compromise merely lose forward secrecy an
by devit 11y ago
Is there any reason why in TLS the DH g^x the client sends is not encrypted with the server's RSA key?
That way, a DH compromise merely lose forward secrecy and the data would still be safe as long as the server private keys are not compromised.
- X-Istence 11y agoBecause you can have anonymous TLS connections that only use DH for forward security.
- xnyhps 11y agoStrictly speaking that's not forward-secret anymore, as stealing the private key gives some advantage to cracking the session. The practical reason is probably that using DHE with TLS is already many times slower than (plain) RSA. This would only make it slower.