3 ms·
50 pages in I still haven't found how they propose this helps with WAN traffic or with mTLS. All of this seems to assume you always own the server side, which
by oneplane 3y ago
50 pages in I still haven't found how they propose this helps with WAN traffic or with mTLS.
All of this seems to assume you always own the server side, which you pretty much don't. Even on page 5 with the summary of the solution it doesn't touch that subject.
You'd think that if you own the server and the client anyway, you'd just capture it right there if you need to.
As for just the DH 'server' doing key distribution, that's something we already know how to do and doesn't require "we install nginx on a random server and call it an appliance" style vendors.