4 ms·
I need to correct something here. The temporary RSA key generation is never used for ephemeral DH, but rather for the situation where RSA key exchange is reque
by brl 17y ago
I need to correct something here. The temporary RSA key generation is never used for ephemeral DH, but rather for the situation where RSA key exchange is requested and only a signing key is available.
The server does not even verify an explicit signature on the client DH value because this is covered when the entire handshake is validated in the final step (The finish message).
Since the server does not perform an RSA operation on the client value, my conclusion about performance is totally bogus.