RFC 8470: Using Early Data in HTTP
In plain English — editorial summary, not part of the RFC
Using TLS early data creates an exposure to the possibility of a replay attack. This document defines mechanisms that allow clients to communicate with servers about HTTP requests that are sent in early data. Techniques are described that use these mechanisms to mitigate the risk of replay.
Document record
- Document ID
- RFC8470
- Published
- September 2018
- Authors
- M. Thomson; M. Nottingham; W. Tarreau
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- wit
- Pages
- 12
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7538The Hypertext Transfer Protocol Status Code 308 (Permanent Redirect)Obsoleted
April 2015
- RFC 8471The Token Binding Protocol Version 1.0Current
October 2018
- RFC 8472Transport Layer Security (TLS) Extension for Token Binding Protocol NegotiationCurrent
October 2018
- RFC 8473Token Binding over HTTPCurrent
October 2018
- RFC 7238The Hypertext Transfer Protocol Status Code 308 (Permanent Redirect)Obsoleted
June 2014
- RFC 9916Updates to the Usage of TLS to Provide a Secure Transport for the Path Computation Element Communication Protocol (PCEP)Current
July 2026
- RFC 2817Upgrading to TLS Within HTTP/1.1Updated
May 2000
- RFC 8336The ORIGIN HTTP/2 FrameCurrent
March 2018
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?