From 203dd460f713f048a172b72aff5e48c4c7dd4928 Mon Sep 17 00:00:00 2001 From: stf <7o5rfu92t@ctrlc.hu> Date: Tue, 16 Jan 2024 16:04:47 +0100 Subject: [PATCH] export_key is only used by clients --- draft-irtf-cfrg-opaque.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/draft-irtf-cfrg-opaque.md b/draft-irtf-cfrg-opaque.md index b4e29302..d5e8e3f6 100644 --- a/draft-irtf-cfrg-opaque.md +++ b/draft-irtf-cfrg-opaque.md @@ -981,7 +981,7 @@ The server inputs the following values: The client receives two outputs: a session secret and an export key. The export key is only available to the client and may be used for additional application-specific purposes, as outlined in {{export-key-usage}}. -Clients and servers MUST NOT use the output `export_key` before +Clients MUST NOT use the output `export_key` before authenticating the peer in the authenticated key exchange protocol. See {{alternate-key-recovery}} for more details about this requirement. The server receives a single output: a session secret matching the