RFC 8672: TLS Server Identity Pinning with Tickets
In plain English — editorial summary, not part of the RFC
Misissued public-key certificates can prevent TLS clients from appropriately authenticating the TLS server. Several alternatives have been proposed to detect this situation and prevent a client from establishing a TLS session with a TLS end point authenticated with an illegitimate public-key certificate. These mechanisms are either not widely deployed or limited to public web browsing. This document proposes experimental extensions to TLS with opaque pinning tickets as a way to pin the server's identity. During an initial TLS session, the server provides an original encrypted pinning ticket. In subsequent TLS session establishment, upon receipt of the pinning ticket, the server proves its ability to decrypt the pinning ticket and thus the ownership of the pinning protection key. The client can now safely conclude that the TLS session is established with the same TLS server as the original TLS session. One of the important properties of this proposal is that no manual management actions are required.
Document record
- Document ID
- RFC8672
- Published
- October 2019
- Authors
- Y. Sheffer; D. Migault
- Status
- EXPERIMENTAL
- Stream
- INDEPENDENT
- Area
- —
- Pages
- 22
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7562Transport Layer Security (TLS) Authorization Using Digital Transmission Content Protection (DTCP) CertificatesUpdated
July 2015
- RFC 9289Towards Remote Procedure Call Encryption by DefaultCurrent
September 2022
- RFC 7919Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS)Current
August 2016
- RFC 7633X.509v3 Transport Layer Security (TLS) Feature ExtensionCurrent
October 2015
- RFC 7590Use of Transport Layer Security (TLS) in the Extensible Messaging and Presence Protocol (XMPP)Current
June 2015
- RFC 7525Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)Obsoleted
May 2015
- RFC 7465Prohibiting RC4 Cipher SuitesUpdated
February 2015
- RFC 7457Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS)Current
February 2015
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?