Re: Requiring TLS 1.3 as alternative to HTTP/2 section 9.2.2

> On Oct 28, 2014, at 1:03 PM, Erik Nygren <erik@nygren.org> wrote:
> 
> Another option might be to add an ALPN token for h2-requiring-tls-1.3 
> that would be added in by client implementations when they add TLS/1.3 support
> with h2-15 or whatever it is being dropped at some point subsequently?

I don’t think that would be necessary. A TLS 1.3 client is supposed to request 
the most recent version, and the server is likewise required to support the
most recent version requested that it has the ability to do so.

--
Jason T. Greene
WildFly Lead / JBoss EAP Platform Architect
JBoss, a division of Red Hat

Received on Tuesday, 28 October 2014 18:58:32 UTC