Hi,

I think Section 6.1 Closure Alerts is a bit unclear:

First it is stated the user_canceled SHOULD be followed by close_notify

   "This alert SHOULD be followed by a "close_notify"." 

Then it is stated that it MUST be followed by close_notify

   "Each party MUST send a "close_notify" alert before closing its write side 
of the connection,
   unless it has already sent some error alert."

And in the same section is is stated that any data folloing user_canceled MUST 
be ignored.

   "Any data received after a closure alert has been received MUST be ignored."

This seems quite contradicting to me. I don't know what the correct behavior 
would be,
but unless I misunderstood something, it looks like it should be addressed in 
rfc8446bis.

Cheers,
John

_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to