I would like to define a flag that says "no renegotiation allowed" This has come up (for pre 1.3 of course) a couple of times, that while you can signal "defaut" or "only secure" renegotiation, you can't signal "no renegotiation" in a way that is visible purely on the wire, to things like SSLLabs ratings systems.
_______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls