Module 8

Protocols

4 lessonsabout 155 minPractitioner / Advisor

After this module you can

  • Calculate the real byte cost of a hybrid TLS 1.3 handshake
  • Explain what breaks in IKEv2, SSH, S/MIME and code signing

Before thisM7: X.509 and PKI

  1. 01TLS 1.3 hybrid key exchange: your own measurementMeasure the X25519 and X25519MLKEM768 ClientHello in your own environment and explain, component by component, where the difference comes from, unlike in the RSA/ECDSA era
  2. 02Beyond TLS: IKEv2 and SSHDistinguish RFC 9370 (multiple key exchanges in IKEv2) from RFC 8784 (PPK mixing) as different mechanisms, and when each is used
  3. 03S/MIME and code signing: a different lifetime logicExplain why the threat model of S/MIME and code signing (signature lifetime) is fundamentally different from that of TLS (the moment of connection)
  4. 04Signature verification performance: the right framePresent the raw data of BIS othp107 (SOURCED) and derive the ~7.47x ratio from it, showing the division (DERIVED)
Next moduleM9: Key management and HSMs