vix.ing · top · new · best · stats

Transport Layer Security (TLS) Renegotiation Indication Extension

2010/02/01 by Eric Rescorla, Mallar Ray, Stephen Dispensa +1 · 102 citations
Engineering · Computer Science · #IPv6, Mobility, Handover, Networks, Security #Advanced Authentication Protocols Security #Internet Traffic Analysis and Secure E-voting #Extension (predicate logic) #Transport Layer Security #Computer science #Layer (electronics) #Computer security #Programming language #Materials science #Encryption #Nanotechnology

paper · doi:10.17487/rfc5746

openalex publication_date 2010/02/01 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/22

Abstract

Secure Socket Layer (SSL) and Transport Layer Security (TLS) renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client. The server treats the client’s initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data. This specification defines a TLS extension to cryptographically tie renegotiations to the TLS connections they are being performed over, thus preventing this attack. Status of This Memo This is an Internet Standards Track document. This document is a product of the Internet Engineering Task Force (IETF). It represents the consensus of the IETF community. It has received public review and has been approved for publication by the

Citations

Cited by

Related