Re: [TLS] Confirming consensus about one
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Confirming consensus about one



Martin Rex wrote:
Nelson B Bolyard wrote:

What you wrote sounds more like you were expecting "old renegotiation" to
succeed.

Correct, I am expecting that.

That is a configuration option that implementations (hotfixes into
installed base, early during the transition) are likely required
to offer.

In my code, I added three boolean configuration options
which all default to false:

    AllowUnsafeInitialConnect
    AllowRenegotiation
    AllowUnsafeRenegotiation

Hopefully this will make it obvious to people that choosing
the Unsafe options are just that (though the first one will
be needed for a while yet).

Mike

Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.