#rfc

6 posts · Last used 15d

Back to Timeline
Wulfy—Speaker to the machines @n_dimension@infosec.exchange · Jul 30, 2026
Replying to @sjvn@mastodon.social
0
0
0
RFC Editor @rfceditor@mastodon.online · Jul 15, 2026
RFC 9954: Hybrid Key Exchange in TLS 1.3, D. Stebila, et al., https://www.rfc-editor.org/info/rfc9954 #RFC Hybrid key exchange refers to using multiple key exchange algorithms simultaneously and combining the result with the goal of providing security even if a way is found to defeat the encryption for all but one of the component algorithms. It is motivated by the transition to post-quantum 1/2
0
0
1
RFC Editor @rfceditor@mastodon.online · Jul 17, 2026
RFC 9852: New Protocols Using TLS Must Require TLS 1.3, R. Salz, et al., https://www.rfc-editor.org/info/rfc9852 #RFC TLS 1.3 is widely used, has had comprehensive security proofs, and improves both security and privacy deficiencies in TLS 1.2. Therefore, new protocols that use TLS must require TLS 1.3. As DTLS 1.3 is not widely available or deployed, this prescription does not pertain to 1/2
2
1
3
julian @julian@activitypub.space · Jul 21, 2026

NodeBB and RFC 9421

<p>I've been working (admittedly, with AI assistance) on HTTP signatures RFC 9421 support.</p> <p>The work will be done in stages. The first step is ensuring NodeBB can handle receipt of activities signed under the new standard (with adequate fallback to draft <code>cavage-12</code>).</p> <p>Afterwards NodeBB will begin sending out activities signed with both methods.</p> <p>Question re: double knock for AP devs who have implemented... is there a specific reason 9421-signed is sent first, and then cavage-12? [...]</p> Hover or focus to reveal Sensitive
I've been working (admittedly, with AI assistance) on HTTP signatures RFC 9421 support. The work will be done in stages. The first step is ensuring NodeBB can handle receipt of activities signed under the new standard (with adequate fallback to draft cavage-12). Afterwards NodeBB will begin sending out activities signed with both methods. Question re: double knock for AP devs who have implemented... is there a specific reason 9421-signed is sent first, and then cavage-12? My understanding is the headers are separate — Signature-Input vs Signature, though there are two of the latter. It seems possible to send both signatures at once.
0
4
1
RFC Editor @rfceditor@mastodon.online · Jul 15, 2026
RFC 9851: TLS 1.2 is in Feature Freeze, R. Salz, et al., https://www.rfc-editor.org/info/rfc9851 #RFC Use of TLS 1.3, which fixes some known deficiencies in TLS 1.2, is growing. This document specifies that no changes will be approved for TLS 1.2 outside of urgent security fixes (as determined by TLS Working Group consensus), new TLS Exporter Labels, and new Application-Layer Protocol 1/2
0
0
0

You've seen all posts