RSA ephemeral is not "prohibited". Is not standardized, thats true.
It would be easy to define a hello extension to add ephemeral RSA. The client would send the extension indicating that it would accept an ephemeral RSA key, and the server would respond with the same extension in the server hello indicating that it will send a server key exchange message with the key. This would avoid the need to define new cipher suites for ephemeral RSA. Mike _______________________________________________ TLS mailing list TLS@xxxxxxxxxxxxxx https://www1.ietf.org/mailman/listinfo/tls