What should be done with the fresh attribute after a rekey operation? The specification indicates that it should be copied from the key being replaced if you believe Table 131 (and therefore could be false even though the new key has never been served up to a client), or should be set to true if you believe section 3.34. I agree with Michael (see below) that the fresh attribute should be set to true after a rekey operation. Does anyone have another opinion? John