3.1.1.1.3 Public Key Pair

The client MUST have an RSA public key pair[RFC8017] (public key MUST be 2048-bit) that can be used in a key exchange (see sections 3.1.5.4.3, 3.1.5.4.4 and 3.1.5.4.5). The same public key pair MUST be used in all key exchanges.

The public key pair MUST be generated before the first PUBLIC_KEY message (see section 3.1.5.4.3) is sent from the client to the server.