Thank you for posting it there. If I understand correctly, the resolution
should be to use internal hash algorithms — in this case, SHAKE.
Now, the question is whether to wait for the implementation of a public API
to make the change as general as possible, or to try implementing it on the
PG side?
    -Filip-
st 29. 10. 2025 v 6:17 odesílatel Nico Williams <nico(at)cryptonector(dot)com>
napsal:
> I posted (including your attachment, by accident, since at first I was
> going to forward your post) about this to the IETF TLS WG mailing list.
>
> https://mailarchive.ietf.org/arch/msg/tls/CEaZg1l-4iVg0_wdEr5_rXfGYWc/
>
>