RFC 9266: Channel Bindings for TLS 1.3 support
- Dominant language
- Rust
- Stars
- 7
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
Dear @duesee,
Can you add the support of RFC 9266: Channel Bindings for TLS 1.3?
- https://datatracker.ietf.org/doc/html/rfc9266
Channel Bindings for TLS: https://datatracker.ietf.org/doc/html/rfc5929
- XEP-0388: Extensible SASL Profile: https://xmpp.org/extensions/xep-0388.html
- XEP-0440: SASL Channel-Binding Type Capability: https://xmpp.org/extensions/xep-0440.html
- XEP-0474: SASL SCRAM Downgrade Protection: https://xmpp.org/extensions/xep-0474.html
- XEP-0480: SASL Upgrade Tasks: https://xmpp.org/extensions/xep-0480.html
Little details, to know easily:
- tls-unique for TLS =< 1.2 (RFC5929)
- tls-server-end-point =< 1.2 + 1.3 (RFC5929)
- tls-exporter for TLS = 1.3 (RFC9266)
After the jabber.ru MITM, it is time to add it:
- https://notes.valdikss.org.ru/jabber.ru-mitm/
- https://snikket.org/blog/on-the-jabber-ru-mitm/
- https://www.devever.net/~hl/xmpp-incident
- https://blog.jmp.chat/b/certwatch/certwatch
Thanks in advance.
Linked to:
- Channel Binding: https://github.com/scram-sasl/info/issues/1
- https://github.com/duesee/smtp-codec/issues/17
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading RFC 9266 alongside RFC 5929 and the linked XMPP SASL specifications, then review the related Channel Binding issue and smtp-codec issue 17. Done means the project supports the TLS 1.3 tls-exporter channel-binding type alongside the stated TLS version rules.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100