-
Notifications
You must be signed in to change notification settings - Fork 57
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
More explanatory text.. Fixes #587. Fixes #591 #602
Conversation
draft-ietf-tls-esni.md
Outdated
DNS results, if one is provided. | ||
|
||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks spurious
key not known to the server. | ||
|
||
* The server has ECH configured but the client has a ECH configuration | ||
and so is attempting ECH. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Missing a negative in 2nd bullet above?
other than the above, this change seems fine |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Any point saying that:
This makes availability of a certificate for the public name - and its associated private key - a critical component for server deployment of ECH. This certificate is used both to recover from transient misconfiguration problems and to disable ECH in the event that a server cannot continue to support the capability.
draft-ietf-tls-esni.md
Outdated
* The server has ECH configured but the client has a ECH configuration | ||
and so is attempting ECH. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
* The server has ECH configured but the client has a ECH configuration | |
and so is attempting ECH. | |
* The server does not have ECH configured but the client has a ECH configuration | |
and so is attempting ECH. |
Co-authored-by: Martin Thomson <[email protected]>
Rewrite the overview section to be a bit clearer and clarified the misconfiguration pieces.