Re: Working Group Last Call for Using Early Data in HTTP

On Fri, Dec 1, 2017 at 2:47 PM, Willy Tarreau <w@1wt.eu> wrote:

> That's exactly why it's requested that all servers are configured
> consistently. As you demonstrated, as long as "all of them" is granted
> regardless of the decision, the processing is safe. What is important
> is that you can't end up in a situation whose starts with "some servers".
>
> Willy
>
>
That's what I thought.  But Martin's email makes it sound like there is a
reason to discard early data when it's received after handshake completion,
instead of treating it as replay-secure.

Received on Monday, 4 December 2017 00:54:21 UTC