Skip to content

RFC 9266: Channel Bindings for TLS 1.3 support #115193

Closed as not planned
Closed as not planned
@Neustradamus

Description

@Neustradamus

Bug report

Bug description:

Dear @python team,

Can you add the support of RFC 9266: Channel Bindings for TLS 1.3?

Little details, to know easily:

  • tls-unique for TLS =< 1.2
  • tls-server-end-point
  • tls-exporter for TLS = 1.3

A best SCRAM SASL and Channel Binding explanation:

An announcement has been done by Slixmpp team here about the security problem:

I think that you have seen the jabber.ru MITM:

Can you add "tls-server-end-point" from RFC5929 too?

It is needed for all SCRAM-SHA-*-PLUS (several RFCs) and specified in:

All links about it:

cc: @davidben, @wingel, @eighthave, @jchampio, @gst, @lowinger42, @ezio-melotti, @AlexWaygood, @njsmith, @zooba, @tlocke, @agronholm, @oberstet.

Thanks in advance.

Linked to:

CPython versions tested on:

CPython main branch

Operating systems tested on:

Other

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions