RFC 7627: Transport Layer Security (TLS) Session Hash and Extended Master Secret Extension
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 9846.
Current document in this lineage: RFC 6066 — Transport Layer Security (TLS) Extensions: Extension Definitions; RFC 9846 — The Transport Layer Security (TLS) Protocol Version 1.3
In plain English — editorial summary, not part of the RFC
The Transport Layer Security (TLS) master secret is not cryptographically bound to important session parameters such as the server certificate. Consequently, it is possible for an active attacker to set up two sessions, one with a client and another with a server, such that the master secrets on the two sessions are the same. Thereafter, any mechanism that relies on the master secret for authentication, including session resumption, becomes vulnerable to a man-in-the-middle attack, where the attacker can simply forward messages back and forth between the client and server. This specification defines a TLS extension that contextually binds the master secret to a log of the full handshake that computes it, thus preventing such attacks.
Document record
- Document ID
- RFC7627
- Published
- September 2015
- Authors
- K. Bhargavan; A. Delignat-Lavaud; A. Pironti; A. Langley; M. Ray
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 15
- Also known as
- —
Standards lineage
This document is one revision in a chain of 15 RFCs, each formally replacing the one before it.
- RFC 2246 (1999)
- RFC 3268 (2002)
- RFC 3546 (2003)
- RFC 4346 (2006)
- RFC 4366 (2006)
- RFC 4492 (2006)
- RFC 4507 (2006)
- RFC 5077 (2008)
- RFC 5246 (2008)
- RFC 6066 (2011)
- RFC 6961 (2013)
- RFC 7627 (2015)
- RFC 8422 (2018)
- RFC 8446 (2018)
- RFC 9846 (2026) ✓
Read the full history of The Transport Layer Security (TLS) Protocol Version 1.3 →
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7628A Set of Simple Authentication and Security Layer (SASL) Mechanisms for OAuthCurrent
August 2015
- RFC 7632Endpoint Security Posture Assessment: Enterprise Use CasesCurrent
September 2015
- RFC 7634ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol (IKE) and IPsecCurrent
August 2015
- RFC 7619The NULL Authentication Method in the Internet Key Exchange Protocol Version 2 (IKEv2)Current
August 2015
- RFC 7636Proof Key for Code Exchange by OAuth Public ClientsCurrent
September 2015
- RFC 7617The 'Basic' HTTP Authentication SchemeCurrent
September 2015
- RFC 7638JSON Web Key (JWK) ThumbprintCurrent
September 2015
- RFC 7616HTTP Digest Access AuthenticationCurrent
September 2015
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?