RFC 7627-2015

Transport Layer Security (TLS) Session Hash and Extended Master Secret Extension


 

 

非常抱歉,我们暂时无法提供预览,您可以试试: 免费下载 RFC 7627-2015 前三页,或者稍后再访问。

如果您需要购买此标准的全文,请联系:

点击下载后,生成下载文件时间比较长,请耐心等待......

 

标准号
RFC 7627-2015
发布日期
2015年09月01日
实施日期
2015年10月08日
废止日期
中国标准分类号
/
国际标准分类号
/
发布单位
IETF - Internet Engineering Task Force
引用标准
15
适用范围
The Transport Layer Security (TLS) master secret is not cryptographically bound to important session parameters such as the server certificate. Consequently@ it is possible for an active attacker to set up two sessions@ one with a client and another with a server@ such that the master secrets on the two sessions are the same. Thereafter@ any mechanism that relies on the master secret for authentication@ including session resumption@ becomes vulnerable to a man-in-the-middle attack@ where the attacker can simply forward messages back and forth between the client and server. This specification defines a TLS extension that contextually binds the master secret to a log of the full handshake that computes it@ thus preventing such attacks.




Copyright ©2007-2022 ANTPEDIA, All Rights Reserved
京ICP备07018254号 京公网安备1101085018 电信与信息服务业务经营许可证:京ICP证110310号