[gnutls-devel] GnuTLS | KTLS key update support (!1625)

Read-only notification of GnuTLS library development activities gnutls-devel at lists.gnutls.org
Tue Oct 11 19:49:18 CEST 2022




František Krenželok commented on a discussion: https://gitlab.com/gnutls/gnutls/-/merge_requests/1625#note_1131944240

>prior to this change, since we ignored handshake msg, does that mean the connection fails when the peer sends a key_update?

Yes, that is correct
>since this change requires a kernel patch; what happens if the kernel patch is NOT applied but ktls is enabled?

KTLS will be used until key_update is received or send, after that it will be disabled and GnuTLS will fallback to default i.e. gnutls will handle encryption and decryption

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/1625#note_1131944240
You're receiving this email because of your account on gitlab.com.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnutls-devel/attachments/20221011/70489ad4/attachment.html>


More information about the Gnutls-devel mailing list