Private Diffie/Helman Tokens
Private Diffie/Helman Tokens
Posted Dec 5, 2024 22:34 UTC (Thu) by pitb0ss (subscriber, #137324)In reply to: Private Diffie/Helman Tokens by eharris
Parent article: Let's Encrypt sets date for ending OCSP support
It has more to do with knowing that the DH token you are negotiating a short lived key with is at least somewhat "authentic". On the web through let's encrypt this is done through proving ownership (or at least control) over the domain, or server that the host name points to. Without that assurance you could just as easily use my DH token for Google's or your bank's. You should verify it's correctness at some level. The domain model isn't perfect but it's good enough.
