[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[TLS] server auth on renegoiate
We disagreed earlier on whether the spec required that a
(std) RSA cipersuite MUST send a certificate. I argued that it
wasn't necessary for the case of renegotiate given the DAO
of the confidentiality service; and we disagreed on that rationale,
even.
So, I've been attempting to accommodate:-
which would the list prefer:-
(a) a self-signed (static) cert
(b) an unsigned (static) cert
(c) a message with no content
I feel very comfortable with (a) for re-negotiation scenarios, within a
decent ciphersuite. I can quote Eric's book (p.220), at least: "However, its
is of course possible to use self-signed (and hence unverified) certificates
and get the effect of an anonymous connection with any SSL mode."
If I recall, TLS-PSK also mentions the self-signed cert practice.
_______________________________________________
TLS mailing list
TLS@xxxxxxxxxxxxxx
https://www1.ietf.org/mailman/listinfo/tls