Early data can be replayed. It is only safe to use early data when the request is idempotent, like GET. You might find https://tools.ietf.org/html/rfc8470 useful reading. |
-- openssl-users mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users