Re: [TLS] Would removal of upper bounds of common certificate attributes break TLS?

2022-02-02 Thread Salz, Rich
>It should perhaps be noted that best practice is to not bother with a subject DN at all (setting it to an empty sequence) when an appropriate SAN is included in the certificate. And for TLS purposes, this is exactly what the 6125-bis draft says, being discussed in the UTA working gro

Re: [TLS] Implementations of draft-ietf-tls-flags and draft-ietf-tls-cross-sni-resumption

2022-02-02 Thread Christopher Wood
Hi Jens, > On Jan 28, 2022, at 9:14 AM, Jens Guballa wrote: > > Am 27.01.22 um 17:35 schrieb Christopher Wood: >> In preparing to move draft-ietf-tls-flags and >> draft-ietf-tls-cross-sni-resumption forward in the process, I’m curious if >> anyone is aware of implementations of either specific