Using Early Data in HTTP
RFC 8470, “Using Early Data in HTTP”, is a Proposed Standard document published in September 2018 by M. Thomson, M. Nottingham, W. Tarreau. The canonical text is published by the RFC Editor.
Abstract
Using TLS early data creates an exposure to the possibility of a replay attack. This document defines mechanisms that allow clients to communicate with servers about HTTP requests that are sent in early data. Techniques are described that use these mechanisms to mitigate the risk of replay.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8470 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8469 Recommendation to Use the Ethernet Control Word
- RFC 8471 The Token Binding Protocol Version 1.0
- RFC 8468 IPv4, IPv6, and IPv4-IPv6 Coexistence: Updates for the IP Performance Metrics Framework
- RFC 8472 Transport Layer Security Extension for Token Binding Protocol Negotiation
- RFC 8467 Padding Policies for Extension Mechanisms for DNS (EDNS )
- RFC 8473 Token Binding over HTTP
- RFC 8466 A YANG Data Model for Layer 2 Virtual Private Network Service Delivery
- RFC 8474 IMAP Extension for Object Identifiers