[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Comments on TLS identity protection
Eric Rescorla wrote:
>
> Good point.
>
> However, as you say in most cases the request for client auth
> is contingent upon seeing the request and so a rehandshake is
> required here in any case. A one-pass protocol wouldn't work
> here.
Correct.
I had the same thought but completely failed to point this out.
In the not uncommon case with IIS renegotiating after having
evaluated the HTTP(S)-request, the one-pass protocol can not
be used.
-Martin
_______________________________________________
TLS mailing list
TLS@xxxxxxxxxxxxxx
https://www1.ietf.org/mailman/listinfo/tls