RFC 9849. TLS Encrypted Client Hello
rfc-editor.org
RFC 9849. TLS Encrypted Client Hello
1–10 of 159 posts
Re: RFC 9849. TLS Encrypted Client Hello
#2Re: RFC 9849. TLS Encrypted Client Hello
#3Will this have an impact on Loadbalancers? Like does one have to do client side load balancing like in gRPC?
Re: RFC 9849. TLS Encrypted Client Hello
#4In addition to the main RFC 9849, there is also RFC 9848 - "Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings": https://datatracker.ietf.org/doc/rfc9848/
There's an example of how it's used in the article.
Re: RFC 9849. TLS Encrypted Client Hello
#5Will this have an impact on Loadbalancers? Like does one have to do client side load balancing like in gRPC?
Re: RFC 9849. TLS Encrypted Client Hello
#6Will this have an impact on Loadbalancers? Like does one have to do client side load balancing like in gRPC?
Re: RFC 9849. TLS Encrypted Client Hello
#7I wrote about ECH a couple of months ago, when the specs were still in draft but already approved for publication. It's a short read, if you're not already familiar with ECH and its history: https://www.feistyduck.com/newsletter/issue_127_encrypted_cl... In addition to the main RFC 9849, there is also RFC 9848 - "Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings": https://datatracker.ietf.org/doc/rfc9…
Now we need to get Qualys to cap SSL Labs ratings at B for servers that don't support ECH. Also those that don't have HSTS and HSTS Preload while we're at it.
Re: RFC 9849. TLS Encrypted Client Hello
#8Re: RFC 9849. TLS Encrypted Client Hello
#9Re: RFC 9849. TLS Encrypted Client Hello
#10I wrote about ECH a couple of months ago, when the specs were still in draft but already approved for publication. It's a short read, if you're not already familiar with ECH and its history: https://www.feistyduck.com/newsletter/issue_127_encrypted_cl... In addition to the main RFC 9849, there is also RFC 9848 - "Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings": https://datatracker.ietf.org/doc/rfc9…
Thanks for the writeup, Ivan, I am a great fan of your work! Now we need to get Qualys to cap SSL Labs ratings at B for servers that don't support ECH. Also those that don't have HSTS and HSTS Preload while we're at it.