Re: [TLS] TLS renegotiation issue
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] TLS renegotiation issue



I expect that EKR will be posting some details soon.

Martin Rex wrote:
>
> Technically there is no
> limit on the number of renegotiations, so a simple pointer
> only one TLS session into the past does not seem sufficient
> for that purpose.

I agree, the concept of "first handshake on the socket" is a bit
nebulous from the perspective of the TLS spec.

The approach our proposal took was to work off of the "most recent
previous finished message" over the underlying transport.

- Marsh

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.