@raphael as I understand with TLS you typically establish session keys withh the certificate/public keys. I guess you could share the "proof" of the signature keys, but since the session keys would be symmetric cryptography you could trivially tamper with the actual response