Re: FYI: proposal for client authentication in TLS

On Sat, Mar 08, 2014 at 03:45:23PM +0000, Martin Thomson wrote:
> On 8 March 2014 15:04, Ilari Liusvaara <ilari.liusvaara@elisanet.fi> wrote:
> 
> > I was thinking if the client could select the certificate before
> > connecting again...
> 
> As for certificate selection, I don't think that we need anything more
> than what we already have.  Today, we have zero.  With this, we would
> have realm, and extension parameters, which I don't think that we can
> sensibly define anything for.

IIRC, for certificate selection, TLS sends DNs of acceptable certificate
authorities. Of course, that won't help with self-signed client
certificate...


-Ilari

Received on Saturday, 8 March 2014 15:57:11 UTC