RFC 8672 · EXPERIMENTAL · 2019

TLS Server Identity Pinning with Tickets

Overview

RFC 8672, “TLS Server Identity Pinning with Tickets”, is an Experimental document published in October 2019 by Y. Sheffer, D. Migault. The canonical text is published by the RFC Editor.

Abstract

Misissued public-key certificates can prevent TLS clients from appropriately authenticating the TLS server. Several alternatives have been proposed to detect this situation and prevent a client from establishing a TLS session with a TLS end point authenticated with an illegitimate public-key certificate. These mechanisms are either not widely deployed or limited to public web browsing.

This document proposes experimental extensions to TLS with opaque pinning tickets as a way to pin the server's identity. During an initial TLS session, the server provides an original encrypted pinning ticket. In subsequent TLS session establishment, upon receipt of the pinning ticket, the server proves its ability to decrypt the pinning ticket and thus the ownership of the pinning protection key. The client can now safely conclude that the TLS session is established with the same TLS server as the original TLS session. One of the important properties of this proposal is that no manual management actions are required.

Abstract as published in the RFC, via rfc-editor.org.

What “Experimental” means

Describes a specification that is part of a research or development effort, published so the community can gain experience with it.

Read this RFC

The canonical text of RFC 8672 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2019

Who Is Online

In total there are 81 users online: 0 registered, 75 guests and 6 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Other Bot Other Crawler SemrushBot Sogou

Users active in the past 15 minutes. Total registered members: 354