[TLS] Implementation survey: Client Certificate URL extension
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[TLS] Implementation survey: Client Certificate URL extension
Hi,
We currently have two open technical issues for 4366bis,
both related to the Client Certificate URL extension (#45
about making the hash mandatory; and #46 on how to do
algorithm agility).
The proposal in IETF71 was to make including the hash a MUST
(regardless of TLS version number), and handle algorithm agility
with a new extension number later (if it turns out something
actually needs to be done).
However, making the hash mandatory has some potential for interop
problems (if there are old implementations which don't send it).
If you have implemented, or have heard of someone implementing,
the client_certificate_url extension, please send email.
Additional details (is this a client, server, or both; do you
send the hash, etc.) are welcome but not required.
Best regards,
Pasi
_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.