On Sep 18, 2017, at 8:49 PM, Lyndon Nerenberg <lyndon@xxxxxxxxxx> wrote:
- Although it is entirely an implementation decision, it is recommended that certificates used for server authentication of the TLS session contain the server identification information in a similar manner to those used for http servers (see [RFC-2818]). Whatevs, Saruman. :) (In case that was too flippant, my point is that RFC 4217 is really what we now call opportunistic security, and any kind of actual authentication of the endpoint is addressed in the document with a handwave.) |