csosto-pk / tls-suppress-intermediates

Suppress intermediate certificates in TLS
Other
0 stars 0 forks source link

Nit from Ilari #5

Closed csosto-pk closed 2 years ago

csosto-pk commented 2 years ago

Section 3.2: "To prevent a failed TLS connection, a client could chose to not send its intermediates regardless of the flag from the server, if it has a reason to believe the issuing CAs do not exist in the server ICA list."

... Shouldn't the client send its intermediates if it thinks the server does not have them.

csosto-pk commented 2 years ago

Addressed in https://github.com/csosto-pk/tls-suppress-intermediates/commit/c4295a28b4402800fec054a7af68a9425d535be7