{
  "module": "key-exchange",
  "title": "Key exchange & secure channels",
  "about": "The controls each worksheet names, by exhibit. Generated by tools/teach-build.js from the worksheet front matter; a lab whose build removes one of these breaks that worksheet.",
  "worksheets": [
    {
      "exhibit": "diffie-hellman-mitm",
      "repo": "systemslibrarian/crypto-lab-diffie-hellman-mitm",
      "url": "https://systemslibrarian.github.io/crypto-lab-diffie-hellman-mitm/",
      "worksheet": "https://crypto-lab.systemslibrarian.dev/teach/key-exchange/diffie-hellman-mitm/",
      "source_commit": "8d69dbc7ae4f",
      "checked": "2026-09-22",
      "anchors": [
        {
          "kind": "id",
          "value": "passive"
        },
        {
          "kind": "id",
          "value": "p-preset"
        },
        {
          "kind": "id",
          "value": "p-a"
        },
        {
          "kind": "id",
          "value": "p-b"
        },
        {
          "kind": "id",
          "value": "p-run"
        },
        {
          "kind": "id",
          "value": "p-break"
        },
        {
          "kind": "id",
          "value": "p-toy"
        },
        {
          "kind": "id",
          "value": "p-out"
        },
        {
          "kind": "id",
          "value": "mitm"
        },
        {
          "kind": "id",
          "value": "m-preset"
        },
        {
          "kind": "id",
          "value": "m-a"
        },
        {
          "kind": "id",
          "value": "m-b"
        },
        {
          "kind": "id",
          "value": "m-m1"
        },
        {
          "kind": "id",
          "value": "m-m2"
        },
        {
          "kind": "id",
          "value": "m-run"
        },
        {
          "kind": "id",
          "value": "m-next"
        },
        {
          "kind": "id",
          "value": "m-all"
        },
        {
          "kind": "id",
          "value": "m-steplabel"
        },
        {
          "kind": "id",
          "value": "m-out"
        },
        {
          "kind": "id",
          "value": "i-msg"
        },
        {
          "kind": "id",
          "value": "i-edit"
        },
        {
          "kind": "id",
          "value": "i-send"
        },
        {
          "kind": "id",
          "value": "i-out"
        },
        {
          "kind": "id",
          "value": "fix"
        },
        {
          "kind": "id",
          "value": "f-clean"
        },
        {
          "kind": "id",
          "value": "f-tamper"
        },
        {
          "kind": "id",
          "value": "f-out"
        }
      ]
    },
    {
      "exhibit": "downgrade-wire",
      "repo": "systemslibrarian/crypto-lab-downgrade-wire",
      "url": "https://systemslibrarian.github.io/crypto-lab-downgrade-wire/",
      "worksheet": "https://crypto-lab.systemslibrarian.dev/teach/key-exchange/downgrade-wire/",
      "source_commit": "2de65778ff73",
      "checked": "2026-09-22",
      "anchors": [
        {
          "kind": "id",
          "value": "intro"
        },
        {
          "kind": "id",
          "value": "strip"
        },
        {
          "kind": "id",
          "value": "strip-play"
        },
        {
          "kind": "id",
          "value": "strip-reset"
        },
        {
          "kind": "id",
          "value": "strip-x25519mlkem768"
        },
        {
          "kind": "id",
          "value": "strip-x25519"
        },
        {
          "kind": "id",
          "value": "binding-unbound"
        },
        {
          "kind": "id",
          "value": "binding-bound"
        },
        {
          "kind": "id",
          "value": "policy-preferred"
        },
        {
          "kind": "id",
          "value": "policy-required"
        },
        {
          "kind": "id",
          "value": "strip-run"
        },
        {
          "kind": "id",
          "value": "strip-compare"
        },
        {
          "kind": "id",
          "value": "policy"
        },
        {
          "kind": "id",
          "value": "policy-run"
        },
        {
          "kind": "id",
          "value": "failopen"
        },
        {
          "kind": "id",
          "value": "retry-fail-open"
        },
        {
          "kind": "id",
          "value": "retry-fail-closed"
        },
        {
          "kind": "id",
          "value": "failopen-run"
        },
        {
          "kind": "id",
          "value": "sentinel"
        },
        {
          "kind": "id",
          "value": "sen-Serverwritesthesentinel"
        },
        {
          "kind": "id",
          "value": "sen-Clientchecksthesentinel"
        },
        {
          "kind": "id",
          "value": "scope"
        }
      ]
    },
    {
      "exhibit": "protocol-checker",
      "repo": "systemslibrarian/crypto-lab-protocol-checker",
      "url": "https://systemslibrarian.github.io/crypto-lab-protocol-checker/",
      "worksheet": "https://crypto-lab.systemslibrarian.dev/teach/key-exchange/protocol-checker/",
      "source_commit": "24c7e9c2dd01",
      "checked": "2026-09-22",
      "anchors": [
        {
          "kind": "id",
          "value": "proto-select"
        },
        {
          "kind": "id",
          "value": "run-btn"
        },
        {
          "kind": "id",
          "value": "fix-toggle"
        },
        {
          "kind": "id",
          "value": "lab-body"
        },
        {
          "kind": "id",
          "value": "search-status"
        },
        {
          "kind": "id",
          "value": "library-grid"
        },
        {
          "kind": "label",
          "value": "How the search actually works (for the curious)"
        }
      ]
    },
    {
      "exhibit": "tls-handshake",
      "repo": "systemslibrarian/crypto-lab-tls-handshake",
      "url": "https://systemslibrarian.github.io/crypto-lab-tls-handshake/",
      "worksheet": "https://crypto-lab.systemslibrarian.dev/teach/key-exchange/tls-handshake/",
      "source_commit": "dbbdc73da172",
      "checked": "2026-09-22",
      "anchors": [
        {
          "kind": "id",
          "value": "prevBtn"
        },
        {
          "kind": "id",
          "value": "nextBtn"
        },
        {
          "kind": "id",
          "value": "autoBtn"
        },
        {
          "kind": "id",
          "value": "resetBtn"
        },
        {
          "kind": "id",
          "value": "fault-none"
        },
        {
          "kind": "id",
          "value": "fault-ecdhe"
        },
        {
          "kind": "id",
          "value": "fault-transcript"
        },
        {
          "kind": "id",
          "value": "attack-reuse-cert"
        },
        {
          "kind": "id",
          "value": "attack-own-key"
        },
        {
          "kind": "id",
          "value": "attack-relay"
        },
        {
          "kind": "id",
          "value": "scope"
        },
        {
          "kind": "label",
          "value": "Client-computed shared secret, 32 bytes"
        },
        {
          "kind": "label",
          "value": "Server-computed shared secret, 32 bytes"
        },
        {
          "kind": "label",
          "value": "Show one derivation in full — how server_handshake_traffic_secret is computed"
        }
      ]
    }
  ]
}
