Transport Layer Security Renegotiation Indication Extension
RFC 5746, “Transport Layer Security Renegotiation Indication Extension”, is a Proposed Standard document published in February 2010 by E. Rescorla, M. Ray, S. Dispensa, N. Oskov. It updates RFC 2246, RFC 4346, RFC 4347, RFC 4366, RFC 5246. The canonical text is published by the RFC Editor.
Abstract
Secure Socket Layer (SSL) and Transport Layer Security (TLS) renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client. The server treats the client's initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data. This specification defines a TLS extension to cryptographically tie renegotiations to the TLS connections they are being performed over, thus preventing this attack. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5746 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5747 4over6 Transit Solution Using IP Encapsulation and MP-BGP Extensions
- RFC 5748 IANA Registry Update for Support of the SEED Cipher Algorithm in Multimedia Internet KEYing
- RFC 5749 Distribution of EAP-Based Keys for Handover and Re-Authentication
- RFC 5750 Secure/Multipurpose Internet Mail Extensions Version 3.2 Certificate Handling
- RFC 5751 Secure/Multipurpose Internet Mail Extensions Version 3.2 Message Specification
- RFC 5752 Multiple Signatures in Cryptographic Message Syntax
- RFC 5739 IPv6 Configuration in Internet Key Exchange Protocol Version 2
- RFC 5753 Use of Elliptic Curve Cryptography Algorithms in Cryptographic Message Syntax