Skip to content

RFC 5929: Channel Bindings for TLS: tls-server-end-point support #10506

@Neustradamus

Description

@Neustradamus

Suggested enhancement

Dear @Mbed-TLS team, @davidhorstmann-arm, @gilles-peskine-arm, @tom-cosgrove-arm, @waleed-elmelegy-arm, @gowthamsk-arm and @mfil (who has added "tls-exporter", RFC 9266),

Can you add the missing "tls-server-end-point" support of RFC 5929: Channel Bindings for TLS?

Recently, @simo5 explains why it is needed here: https://mailarchive.ietf.org/arch/msg/kitten/-hhno2IUJQwXOyJT3-CTaKxoOuA/

Little details, to know easily:

  • tls-unique for TLS =< 1.2 (RFC5929)
  • tls-server-end-point =< 1.2 + 1.3 (RFC5929)
  • tls-exporter for TLS = 1.3 (RFC9266)

After the jabber.ru MITM, it is time to add it:

Thanks in advance.

Linked to:

Justification

Mbed TLS needs this because it is supported by several companies, projects/softwares and it does not work with Mbed TLS.

Metadata

Metadata

Assignees

No one assigned

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions