After a bit of back and forth over my *two* previous SecDir requests, I'm afraid that my original comment has not yet been fully addressed. The IANA considerations section (Sec. 8.1) adds server_name as a possible extension for CertificateRequest. This would be a non-backward compatible change to TLS. IMO what we needed to do is both to clarify the allowed extensions for what Nick called "the CR-like structure" (almost done in Sec. 4, though the last sentence should by changed to include CertificateRequest) and undo the change to the TLS ExtensionType registry (not done, would require to remove Sec. 8.1). * Nit: this sentence is repeated almost verbatim in Sec. 4 and Sec. 5, and in both cases is mangled. Old: The application layer protocol used to send the authenticator request SHOULD use a secure with equivalent security to TLS, such as QUIC [QUIC-TLS], as its as its underlying transport to keep the request confidential. New: The application layer protocol used to send the authenticator request SHOULD use a secure *channel* with equivalent security to TLS, such as QUIC [QUIC-TLS], as its ~~as its~~ underlying transport to keep the request confidential.