Module 8
Protocols
4 lessonsabout 155 minPractitioner / Advisor
After this module you can
- Calculate the real byte cost of a hybrid TLS 1.3 handshake
- Explain what breaks in IKEv2, SSH, S/MIME and code signing
Before thisM7: X.509 and PKI
- 01TLS 1.3 hybrid key exchange: your own measurementMeasure the X25519 and X25519MLKEM768 ClientHello in your own environment and explain, component by component, where the difference comes from, unlike in the RSA/ECDSA era
- 02Beyond TLS: IKEv2 and SSHDistinguish RFC 9370 (multiple key exchanges in IKEv2) from RFC 8784 (PPK mixing) as different mechanisms, and when each is used
- 03S/MIME and code signing: a different lifetime logicExplain why the threat model of S/MIME and code signing (signature lifetime) is fundamentally different from that of TLS (the moment of connection)
- 04Signature verification performance: the right framePresent the raw data of BIS othp107 (SOURCED) and derive the ~7.47x ratio from it, showing the division (DERIVED)