It simply means that the *final output* of HMAC would be truncated to 10 bytes - but *not* that its input or key would be truncated in any way.
Then I would propose changing "CipherSpec.hash_size" to CipherSpec.mac_length so that "hash_size" does not have
two related but different meanings. Mike _______________________________________________ TLS mailing list TLS@xxxxxxxxxxxxxx https://www1.ietf.org/mailman/listinfo/tls