RFC 7366: Encrypt-then-MAC for Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)
In plain English — editorial summary, not part of the RFC
This document describes a means of negotiating the use of the encrypt-then-MAC security mechanism in place of the existing MAC-then-encrypt mechanism in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS). The MAC-then-encrypt mechanism has been the subject of a number of security vulnerabilities over a period of many years.
Document record
- Document ID
- RFC7366
- Published
- September 2014
- Authors
- P. Gutmann
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 7
- Also known as
- —
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7360Datagram Transport Layer Security (DTLS) as a Transport Layer for RADIUSUpdated
September 2014
- RFC 7383Internet Key Exchange Protocol Version 2 (IKEv2) Message FragmentationCurrent
November 2014
- RFC 7321Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)Obsoleted
August 2014
- RFC 7427Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)Current
January 2015
- RFC 7301Transport Layer Security (TLS) Application-Layer Protocol Negotiation ExtensionUpdated
July 2014
- RFC 7296Internet Key Exchange Protocol Version 2 (IKEv2)Updated
October 2014
- RFC 7457Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS)Current
February 2015
- RFC 7268RADIUS Attributes for IEEE 802 NetworksUpdated
July 2014
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?