haussli / draft-dahm-opsawg-tacacs-security

IETF draft for new tacacs+ security features
1 stars 1 forks source link

TLS amusement #44

Closed haussli closed 2 years ago

haussli commented 2 years ago

As discussed on our last call, this PR is a consolidation of PR #30's remaining to-do items.

Following RFC7589, we still must address Sections: 4 Certificate Validation 5 Server Identity 6 Client Identity

We will still largely follow rfc5425 for the content of these, as:

haussli commented 2 years ago

We discussed certificate validation with fingerprints; we will change the FP requirement to MUST -> SHOULD .

haussli commented 2 years ago

Addressed on tls branches and merged at 29ec578e6eb.