Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-8350899

Add support for Encrypted Client Hello

XMLWordPrintable

    • Icon: Enhancement Enhancement
    • Resolution: Unresolved
    • Icon: P4 P4
    • None
    • None
    • security-libs
    • None

      An internet draft is gaining traction to make TLSv1.3 Client Hellos encrypted.

      https://datatracker.ietf.org/doc/draft-ietf-tls-esni/
      https://blog.cloudflare.com/encrypted-client-hello/
      https://blog.cloudflare.com/encrypted-sni/

      There seems to be lots of interest in this enhancement, as it solves some of the TLSv1.3 confidentiality issues by having fields such as SNI/ALPN no longer communicated in the clear.

      We should add support for this when it has been issued as an RFC.

            wetmore Bradford Wetmore
            wetmore Bradford Wetmore
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: