[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] =?utf-8?b?wqBFeHRlbnNpb25zwqBhbmTCoHNlc3Npb27CoHJlc3VtcHRp?==?utf-8?q?on?=



badra@xxxxxxxx wrote:

> In [RFC4366] section 3:
> 
>       If the resumption request is denied, the use of the extensions
>       is negotiated as normal.
> 
>       If, on the other hand, the older session is resumed, then the
>       server MUST ignore the extensions and send a server hello
>       containing none of the extension types.  In this case, the
>       functionality of these extensions negotiated during the
>       original session initiation is applied to the resumed session.

The preceeding paragraph is quite important in this context:

        Note also that all the extensions defined in this section are
        relevant only when a session is initiated.  When a client
        includes one or more of the defined extension types in an
        extended client hello while requesting session resumption:

Thus, it's possible to define extensions that are relevant also 
when resuming a session, and the text "server MUST ignore..." 
does not apply to those. (We already have one such extension,
RFC 5077).

Best regards,
Pasi
_______________________________________________
TLS mailing list
TLS@xxxxxxxx
https://www.ietf.org/mailman/listinfo/tls