Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Recommendations for what is in the cookie #5

Closed
ekr opened this issue Jun 23, 2017 · 0 comments
Closed

Recommendations for what is in the cookie #5

ekr opened this issue Jun 23, 2017 · 0 comments

Comments

@ekr
Copy link
Collaborator

ekr commented Jun 23, 2017

Copied from EKR's repo. https://github.com/ekr/dtls13-spec/issues/12
MT writees:

"The server SHOULD use information received in the ClientHello to generate its cookie,such as version, random, ciphersuites. "

This isn't really an interoperability requirement, or even a security one, since the handshake hash includes these. I think that this can be dropped.

(Also in the same paragraph, the client can now double-check the cipher suite as well as the version.)

@ekr ekr closed this as completed in ec5adec Jul 6, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant