Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do agents need to support the Cookies extension (used in HelloRetryRequest)? #219

Closed
mfoltzgoogle opened this issue Sep 11, 2019 · 2 comments
Labels
security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response. v1-spec

Comments

@mfoltzgoogle
Copy link
Contributor

Do OSP agents need to support TLS cookies (used to cache renegotiation outcomes)?

It seems like there is little to renegotiate, but the TLS spec indicates it's a mandatory extension, so it might be easier to support it than turn it off.

@mfoltzgoogle mfoltzgoogle added security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response. v1-spec labels Sep 11, 2019
@mfoltzgoogle
Copy link
Contributor Author

https://www.w3.org/2019/09/15-webscreens-minutes.html#x05

ACTION: mfoltzgoogle to remove notes about the TLS profile; if you use 1.3, you can get away of specifying profile, because 1.3 gets rid of all the bad choices.

@mfoltzgoogle
Copy link
Contributor Author

Addressed by #252.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response. v1-spec
Projects
None yet
Development

No branches or pull requests

1 participant