4 ms·
This is almost all correct, but note that the new TLSv1.3 CertificateAuthoritiesExtension is optional (MAY): https://datatracker.ietf.org/doc/html/rfc8446#secti
by cipherboy 4y ago
This is almost all correct, but note that the new TLSv1.3 CertificateAuthoritiesExtension is optional (MAY): https://datatracker.ietf.org/doc/html/rfc8446#section-4.2.4 https://datatracker.ietf.org/doc/html/rfc8446#section-4.2.4
- toast0 4y agoDoes anyone actually use that extension? There was an earlier extension with the same general purpose, but AFAIK, nobody used that either. The big difference is https://datatracker.ietf.org/doc/html/rfc8446#section-4.4.2 https://datatracker.ietf.org/doc/html/rfc8446#section-4.4.2 calling out that the certificate list is unordered, and suggests that clients SHOULD be prepared to handle that in TLS 1.2 as well.