Re: [TLS] A flags extension

2019-03-30 Thread Yoav Nir
I think I only allow the server to set bits that had been set by the client. A server that supports this extension and also supports at least one of the flag-type features that use this extension and that were declared by the ClientHello extension SHALL send this extension with the

Re: [TLS] More issues with current ESNIKEYS DNS approach

2019-03-30 Thread Stephen Farrell
Hiya, On 29/03/2019 21:44, Erik Nygren wrote: > Following the discussion this week I realized some other major issues we'll > need to make sure we cover: > > 1) Handling proxies here is going to be tricky. The CONNECTi generally > needs to specify the hostname which needs to go to the server

Re: [TLS] I-D Action: draft-ietf-tls-certificate-compression-04.txt

2019-03-30 Thread John Mattsson
Two short comments: - Would be good to mention that the document does not specify any preset dictionaries. - Would be good to mention the reason to have the uncompressed length. Reading the document I had the same thought that EKR earlier expressed on the list: that it was some