Movatterモバイル変換


[0]ホーム

URL:


Search RFCs

Advanced Search

RFC Editor

RFC 7711

PKIX over Secure HTTP (POSH),November 2015

File formats:
icon for text fileicon for PDFicon for HTML
Status:
PROPOSED STANDARD
Authors:
M. Miller
P. Saint-Andre
Stream:
IETF
Source:
xmpp (art)

Cite this RFC:TXT  | XML  |  BibTeX

DOI:  https://doi.org/10.17487/RFC7711

Discuss this RFC: Send questions or comments to the mailing listxmpp@ietf.org

Other actions:View Errata  | Submit Errata  | Find IPR Disclosures from the IETF  | View History of RFC 7711


Abstract

Experience has shown that it is difficult to deploy proper PKIXcertificates for Transport Layer Security (TLS) in multi-tenantedenvironments. As a result, domains hosted in such environments oftendeploy applications using certificates that identify the hostingservice, not the hosted domain. Such deployments force end users andpeer services to accept a certificate with an improper identifier,resulting in degraded security. This document defines methods thatmake it easier to deploy certificates for proper server identitychecking in non-HTTP application protocols. Although these methodswere developed for use in the Extensible Messaging and PresenceProtocol (XMPP) as a Domain Name Association (DNA) prooftype, theymight also be usable in other non-HTTP application protocols.


For the definition ofStatus,seeRFC 2026.

For the definition ofStream, seeRFC 8729.




IABIANAIETFIRTFISEISOCIETF Trust
ReportsPrivacy StatementSite MapContact Us

Advanced Search

[8]ページ先頭

©2009-2026 Movatter.jp