RFC 5746: Transport Layer Security (TLS) Renegotiation Indication Extension
In plain English — editorial summary, not part of the RFC
Secure Socket Layer (SSL) and Transport Layer Security (TLS) renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client. The server treats the client's initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data. This specification defines a TLS extension to cryptographically tie renegotiations to the TLS connections they are being performed over, thus preventing this attack. [STANDARDS-TRACK]
Document record
- Document ID
- RFC5746
- Published
- February 2010
- Authors
- E. Rescorla; M. Ray; S. Dispensa; N. Oskov
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 15
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7457Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS)Current
February 2015
- RFC 7525Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)Obsoleted
May 2015
- RFC 7568Deprecating Secure Sockets Layer Version 3.0Updated
June 2015
- RFC 7590Use of Transport Layer Security (TLS) in the Extensible Messaging and Presence Protocol (XMPP)Current
June 2015
- RFC 6797HTTP Strict Transport Security (HSTS)Current
November 2012
- RFC 5749Distribution of EAP-Based Keys for Handover and Re-AuthenticationCurrent
March 2010
- RFC 5750Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.2 Certificate HandlingObsoleted
January 2010
- RFC 5751Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.2 Message SpecificationObsoleted
January 2010
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?