transport layer security (tls) extensions: extension definitions draft-ietf-tls-rfc4366-bis-00

5
Transport Layer Security (TLS) Extensions: Extension Definitions draft-ietf-tls-rfc4366-bis-00

Upload: libby-roberts

Post on 31-Dec-2015

20 views

Category:

Documents


0 download

DESCRIPTION

Transport Layer Security (TLS) Extensions: Extension Definitions draft-ietf-tls-rfc4366-bis-00. #42 Clarify Server Name Indication with IDNs. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Transport Layer Security (TLS) Extensions: Extension Definitions draft-ietf-tls-rfc4366-bis-00

Transport Layer Security (TLS) Extensions: Extension Definitions

draft-ietf-tls-rfc4366-bis-00

Page 2: Transport Layer Security (TLS) Extensions: Extension Definitions draft-ietf-tls-rfc4366-bis-00

#42 Clarify Server Name Indication with IDNs

• When using IDNs, does the server_name extension contain“xn--tmonesimerkki-bfbb.example.net” or “tämäonesimerkki.example.net” in UTF-8? Or are both allowed?

• Proposal: find out what IE7 and Firefox do

Page 3: Transport Layer Security (TLS) Extensions: Extension Definitions draft-ietf-tls-rfc4366-bis-00

#45 Mandate certificate_url hash

• “If the optional hash is not included with the client certificate URL, the server has no way to verify the name under which the private key in the certificate was used, since the certificate will not appear in the generation of the finished message.”

Page 4: Transport Layer Security (TLS) Extensions: Extension Definitions draft-ietf-tls-rfc4366-bis-00

#46 Hash agility for certificate_url

• Currently just SHA-1

• Is this needed?

Page 5: Transport Layer Security (TLS) Extensions: Extension Definitions draft-ietf-tls-rfc4366-bis-00

Next steps

• Discuss open issues

• Editorial clean-up

• WGLC?