Open
Description
Can you add the support of RFC 9266: Channel Bindings for TLS 1.3?
Little details, to know easily:
- tls-unique for TLS =< 1.2
- tls-server-end-point
- tls-exporter for TLS = 1.3
I think that you have seen the jabber.ru MITM and Channel Binding is the solution:
- https://notes.valdikss.org.ru/jabber.ru-mitm/
- https://snikket.org/blog/on-the-jabber-ru-mitm/
- https://www.devever.net/~hl/xmpp-incident
- https://blog.jmp.chat/b/certwatch
Thanks in advance.
Linked to:
- Feature request: Add support for SCRAM-SHA-256 password authentication #817
- Use a safe implementation of SCRAM. #914
- Support scram password generation #941
- Add support for SCRAM-SHA-256 authentication. #608
- Inform user of unsupported scram auth method #621
- Support for SCRAM-SHA-256 authentication #788
- Add SCRAM-SHA-256 authentication to this library #833
- State of Play scram-sasl/info#1
Metadata
Metadata
Assignees
Labels
No labels