Re: [TLS] Server validation of a second ClientHello

2019-02-08 Thread Hubert Kario
On Friday, 8 February 2019 04:31:18 CET Martin Thomson wrote: > TLS 1.3 is pretty firm about what you can change in a second ClientHello. > It lists a small set of allowed changes to extensions (cookie, PSK binder, > key shares, early data, and padding). For the rest it says that nothing > can ch

Re: [TLS] Call for Adoption: TLS 1.3 Extension for Certificate-based Authentication with an External Pre-Shared Key

2019-02-08 Thread Eric Rescorla
I'd like to hear from some people who plan to implement and deploy this. Absent that, I'm not sure we should adopt it. Code points are free, so it doesn't need to be a TLS WG item unless the TLS WG and community are going to do substantial work on it. -Ekr On Fri, Jan 25, 2019 at 10:12 AM Christ

[TLS] [Editorial Errata Reported] RFC8446 (5627)

2019-02-08 Thread RFC Errata System
The following errata report has been submitted for RFC8446, "The Transport Layer Security (TLS) Protocol Version 1.3". -- You may review the report below and at: http://www.rfc-editor.org/errata/eid5627 -- Type: Editorial Rep

[TLS] [Errata Held for Document Update] RFC8446 (5627)

2019-02-08 Thread RFC Errata System
The following errata report has been held for document update for RFC8446, "The Transport Layer Security (TLS) Protocol Version 1.3". -- You may review the report below and at: http://www.rfc-editor.org/errata/eid5627 -- St