RFC 8744: Issues and Requirements for Server Name Identification (SNI) Encryption in TLS
In plain English — editorial summary, not part of the RFC
This document describes the general problem of encrypting the Server Name Identification (SNI) TLS parameter. The proposed solutions hide a hidden service behind a fronting service, only disclosing the SNI of the fronting service to external observers. This document lists known attacks against SNI encryption, discusses the current "HTTP co-tenancy" solution, and presents requirements for future TLS-layer solutions. In practice, it may well be that no solution can meet every requirement and that practical solutions will have to make some compromises.
Document record
- Document ID
- RFC8744
- Published
- July 2020
- Authors
- C. Huitema
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- sec
- Pages
- 13
- Also known as
- —
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8747Proof-of-Possession Key Semantics for CBOR Web Tokens (CWTs)Current
March 2020
- RFC 8739Support for Short-Term, Automatically Renewed (STAR) Certificates in the Automated Certificate Management Environment (ACME)Current
March 2020
- RFC 8750Implicit Initialization Vector (IV) for Counter-Based Ciphers in Encapsulating Security Payload (ESP)Current
March 2020
- RFC 8738Automated Certificate Management Environment (ACME) IP Identifier Validation ExtensionCurrent
February 2020
- RFC 8737Automated Certificate Management Environment (ACME) TLS Application-Layer Protocol Negotiation (ALPN) Challenge ExtensionCurrent
February 2020
- RFC 8732Generic Security Service Application Program Interface (GSS-API) Key Exchange with SHA-2Current
February 2020
- RFC 8731Secure Shell (SSH) Key Exchange Method Using Curve25519 and Curve448Current
February 2020
- RFC 8758Deprecating RC4 in Secure Shell (SSH)Current
April 2020
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?