3 ms·
I didn't see anything about renegotiation. If clients present their certificates during first handshake, it will lead to security concerns. Attackers could obse
by defiancedigital 10y ago
I didn't see anything about renegotiation. If clients present their certificates during first handshake, it will lead to security concerns. Attackers could observe client's certificates (extract meta-data, de-ano clients ...). If renegotiation is used it will drastically reduce "Bonus DDOS mitigation"