Re: [openssl-users] Disabling Client-Initiated TLS renegotiation

2016-11-29 Thread Wall, Stephen
lf Of Sashank Mullapudi (samullap) Sent: Monday, November 28, 2016 10:56 PM To: openssl-users@openssl.org Cc: Ram Mohan R (rmohanr) ; Nikhil Mittal (nimittal) ; Anil Kumar (anilkum) Subject: Re: [openssl-users] Disabling Client-Initiated TLS renegotiation Resending this hoping for a response from so

Re: [openssl-users] Disabling Client-Initiated TLS renegotiation

2016-11-28 Thread Sashank Mullapudi (samullap)
Resending this hoping for a response from someone who has information on disabling TLS renegotiation from the Client side. Thanks, Sashank From: samullap mailto:samul...@cisco.com>> Date: Tuesday, 22 November 2016 at 12:21 PM To: "openssl-users@openssl.org" mai

[openssl-users] Disabling Client-Initiated TLS renegotiation

2016-11-21 Thread Sashank Mullapudi (samullap)
Hi, As part of securing our web interfaces, we wanted to disable client-initiated TLS renegotiation. The reasoning for this requirement is as follows- Generally, renegotiation of TLS sessions is much more resource-intensive for the server than the client, and should therefore not be performed