@@ -1617,7 +1617,8 @@
In this document, the TLS handshake is considered confirmed at the server when
-the handshake completes. At the client, the handshake is considered confirmed
+the handshake completes. The server MUST send a HANDSHAKE_DONE frame as soon as
+the handshake is complete. At the client, the handshake is considered confirmed
when a HANDSHAKE_DONE frame is received.¶
A client MAY consider the handshake to be confirmed when it receives an
acknowledgment for a 1-RTT packet. This can be implemented by recording the
@@ -2118,8 +2119,7 @@
An endpoint MUST discard its handshake keys when the TLS handshake is confirmed
-(Section 4.1.2). The server MUST send a HANDSHAKE_DONE frame as soon
-as it completes the handshake.¶
+(
Section 4.1.2).
¶