Tue Mar 1 03:41:44 UTC 2011

The communication of the short term (RSA) connection key in a cert is not
really part of the TLS Handshake Protocol right?  The TLS Handshake Protocol
*just* uses identity (RSA public) keys to establish a symmetric session key
between a client and server right? ...Unless the TLS Handshake Protcol allows
peers to send additional info to each other as part of TLS I don 't know about?

(Also, since EVERY connection needs to generate a short term RSA public/private
key pair....I hope RSA key pair generation is NOT expensive?)


