tls-3----Page:5
1  2  3  4  5  6 

Open Issue in Accept-Credentials
The Accept-Credentials header is sent as part of the request when needed.
Each entry within the Accept-Credentials headers has an intended proxy.
Should that proxy remove the entry intened for itself before forwarding the request?
Doing the above procedure rather then having them go end to end would:
Reduce bandwidth in requests
Slightly increase processing load
Hide earlier TLS hops from later RTSP agents
The Via header shows route, however it allows for a proxy to hide topology
Any security implications?
PPT Version