aws / aws/credentials-fetcher

RFC 9266: Channel Bindings for TLS 1.3 support

Open
#207 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
133
Forks
34
PR merge metrics
No merged PRs in 30d

Description

Dear @aws team,

Can you add the support of RFC 9266: Channel Bindings for TLS 1.3?
- https://datatracker.ietf.org/doc/html/rfc9266

Channel Bindings for TLS: https://datatracker.ietf.org/doc/html/rfc5929

- XEP-0388: Extensible SASL Profile: https://xmpp.org/extensions/xep-0388.html
- XEP-0440: SASL Channel-Binding Type Capability: https://xmpp.org/extensions/xep-0440.html
- XEP-0474: SASL SCRAM Downgrade Protection: https://xmpp.org/extensions/xep-0474.html
- XEP-0480: SASL Upgrade Tasks: https://xmpp.org/extensions/xep-0480.html

Little details, to know easily:
- tls-unique for TLS =< 1.2 (RFC5929)
- tls-server-end-point =< 1.2 + 1.3 (RFC5929)
- tls-exporter for TLS = 1.3 (RFC9266)

After the jabber.ru MITM, it is time to add it:
- https://notes.valdikss.org.ru/jabber.ru-mitm/
- https://snikket.org/blog/on-the-jabber-ru-mitm/
- https://www.devever.net/~hl/xmpp-incident
- https://blog.jmp.chat/b/certwatch/certwatch

Thanks in advance.

Linked to:
- Channel Binding: https://github.com/scram-sasl/info/issues/1

Contributor guide

Open the contributing guide

Research direction

Start by reading RFC 9266 alongside RFC 5929 and the listed XMPP extensions to understand the requested TLS 1.3 channel-binding behavior. Review the repository's existing authentication and TLS entry points, then use the linked scram-sasl issue for related context. Done means the project supports the requested tls-exporter binding for TLS 1.3 without regressing the existing TLS channel-binding types.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.