-
Notifications
You must be signed in to change notification settings - Fork 172
Open
Description
I stumbled across https://datatracker.ietf.org/doc/draft-ietf-tls-dtls13/ today. Looks like it's on its way now.
I took a stroll through the spec, and https://tools.ietf.org/html/draft-ietf-tls-dtls13-34#section-12 has the changed compared to DTLS v1.2. I'm copying it here for good meassure:
- New handshake pattern, which leads to a shorter message exchange
- Only AEAD ciphers are supported. Additional data calculation has
been simplified. - Removed support for weaker and older cryptographic algorithms
- HelloRetryRequest of TLS 1.3 used instead of HelloVerifyRequest
- More flexible ciphersuite negotiation
- New session resumption mechanism
- PSK authentication redefined
- New key derivation hierarchy utilizing a new key derivation
construct - Improved version negotiation
- Optimized record layer encoding and thereby its size
- Added CID functionality
- Sequence numbers are encrypted
Seems there's quite a bit of change. It might prove a fairly decent headache to support that.
eabase, tonisole, darkrift, 24icewolf42 and hayden-pan
Metadata
Metadata
Assignees
Labels
No labels