Last Call: <draft-hallambaker-tlsfeature-09.txt> (X.509v3 TLS Feature Extension) to Proposed Standard

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The IESG has received a request from an individual submitter to consider
the following document:
- 'X.509v3 TLS Feature Extension'
  <draft-hallambaker-tlsfeature-09.txt> as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2015-05-05. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the
beginning of the Subject line to allow automated sorting.

Abstract


   The purpose of the TLS feature extension is to prevent downgrade
   attacks that are not otherwise prevented by the TLS protocol. In
   particular, the TLS feature extension may be used to mandate support
   for revocation checking features in the TLS protocol such as OCSP
   stapling.  Informing clients that an OCSP status response will always
   be stapled permits an immediate failure in the case that the response
   is not stapled. This in turn prevents a denial of service attack that
   might otherwise be possible.

The file can be obtained via
http://datatracker.ietf.org/doc/draft-hallambaker-tlsfeature/

IESG discussion can be tracked via
http://datatracker.ietf.org/doc/draft-hallambaker-tlsfeature/ballot/

No IPR declarations have been submitted directly on this I-D.

This draft has previously been (briefly) discussed on the TLS WG list
but is not a working group item. The WG seemed fine with progressing
an earlier version at that time.






[Index of Archives]     [IETF]     [IETF Discussion]     [Linux Kernel]

  Powered by Linux