Re: [TLS] Proposal to Enhance TLS Mutual Authentication Security

2023-03-26 Thread Eric Rescorla
AS Viktor noted in a separate e-mail TLS 1.3 already encrypts the client certificate. -Ekr On Sun, Mar 26, 2023 at 4:00 PM Yannick LaRue wrote: > Dear TLS Working Group, > > > > I am writing to propose a new method for enhancing the security of mutual > authentication in TLS. The current TLS p

[TLS] Proposal to Enhance TLS Mutual Authentication Security

2023-03-26 Thread Yannick LaRue
Dear TLS Working Group, I am writing to propose a new method for enhancing the security of mutual authentication in TLS. The current TLS protocol requires the exchange of client and server certificates in cleartext during the initial handshake, which exposes sensitive client information to pote