Skip to content

Size limit in TLS session establishment #28

Discussion options

You must be logged in to vote

Great question.
I don't claim to be an expert here, but I will give it a try based on discussions that I've overheard.

TLS "works" with larger keys and packet fragmentation. If you're testing on a local, unsaturated, network you might not even notice the difference. But people like CloudFlare seem to care, and care a lot about violating the TCP congestion window, for example see Cloudflare blog: Sizing Up Post-Quantum Signatures -- the discussion on TCP Congestion Window starts about halfway down the page. Their conclusion seems to be that congestion window violation alone can more-than-triple TLS handshake times from 100 ms to 300 ms.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@JaimeGomezGarcia
Comment options

Answer selected by JaimeGomezGarcia
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants