Hacker News new | past | comments | ask | show | jobs | submit login
TLS clients should reject static Diffie-Hellman (ietf.org)
2 points by based2 on Dec 7, 2018 | hide | past | favorite | 1 comment



"We have recently become aware of the publication of the "Middlebox Security Protocol, Part 3: Profile for enterprise network and data centre access control" by ETSI TC CYBER (https://www.etsi.org/deliver/etsi_ts/103500_103599/10352303/...), which specifies what it calls "enterprise TLS" or "eTLS." We are writing to express serious concerns about the publication of this specification. This work appears to be related to the previous "mcTLS" work about which we also expressed concerns (https://datatracker.ietf.org/liaison/1538/), and our foremost concern remains the use of a name that implies the aegis of Transport Layer Security (TLS), a well-known protocol which has been developed by the IETF for over twenty years."

https://datatracker.ietf.org/liaison/1616/

https://www.heise.de/security/meldung/IETF-an-ETSI-Finger-we...




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: