I find #IETF 's idea that everyone needs to register their #ALPN with #IANA a bit wishful thinking. It would make much more sense to provide for test names, a bit like DNS' .test domains. Why not have a "test/" prefix reserved? Or maybe also an "experimental/<your-tld-here>" prefix?

RFC 8737: Automated Certificate Management Environment (ACME) TLS Application-Layer Protocol Negotiation (ALPN) Challenge Extension

Ce court #RFC normalise un mécanisme d'authentification lors d'une session #ACME, permettant de prouver, via #TLS et #ALPN, qu'on contrôle effectivement le domaine pour lequel on demande un certificat.

https://www.bortzmeyer.org/8737.html

Ping @aeris @Keltounet

Blog Stéphane Bortzmeyer: RFC 8737: Automated Certificate Management Environment (ACME) TLS Application-Layer Protocol Negotiation (ALPN) Challenge Extension

Dites, les experts #ACME. Quelqu'un a t-il utilisé le type de défi tls-alpn-01 (Let's Encrypt l'accepte.)

Si oui, avec quel client ? Ça a marché ? Vous voulez que je vous cite sur mon blog ?

#TLS #ALPN

Funny reading of the day: #RFC 451. Written in 1973, and we still do not have a similar protocol (#ALPN does it partially).
So you can have a #TLS server where an external adversary cannot tell if it provides #HTTPS or #DNS. (Does not work with #ALPN, though.) #privacy #IETF99