Re: [TLS] draft-rescorla-tls-renegotiate and MITM resistance
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] draft-rescorla-tls-renegotiate and MITM resistance



David-Sarah Hopwood wrote:
> 
> Martin Rex wrote:
> > There may be SSLv3 servers out there that choke on extension data
> > in the ClientHello.  But that doesn't mean that one could not
> > upgrade SSLv3 servers to support TLS extensions.  The more interesting
> > question is IMHO -- which TLS clients will choke when an SSLv3 server
> > returns a ServerHello extension?  spec-wise, a ServerHello extension
> > is as unusual to SSLv3 as it is to TLSv1.0.
> 
> Why would that situation arise? For that to happen, an SSL server
> library would have to be upgraded to support extensions but not to
> support TLS. Are there any SSL-only libraries being actively
> maintained?

Yes, there are.

But the issues do also affect TLS-capable servers and clients that
talk to peers which are limited to SSLv3 only (through either
configuration or implementation constraints).

-Martin

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.