Uploaded image for project: 'WildFly Elytron'
  1. WildFly Elytron
  2. ELY-621

Client Cert authentication trigger SSLSession renegotiation?

    • Icon: Feature Request Feature Request
    • Resolution: Done
    • Icon: Blocker Blocker
    • 1.1.0.Beta29
    • None
    • HTTP
    • None

      This could be an option to enable demanding client verification for an established connection but depending on the application being accessed.

            [ELY-621] Client Cert authentication trigger SSLSession renegotiation?

            Yeah not overly excited about adding this one either but the current Undertow mechs support it so for migration we probably should.

            Darran Lofthouse added a comment - Yeah not overly excited about adding this one either but the current Undertow mechs support it so for migration we probably should.

            David Lloyd added a comment -

            Bear in mind that session renegotiation will likely be completely gone in TLS 1.3.

            David Lloyd added a comment - Bear in mind that session renegotiation will likely be completely gone in TLS 1.3.

            We will need to also ensure that renegotiation can be disabled.

            Darran Lofthouse added a comment - We will need to also ensure that renegotiation can be disabled.

              darran.lofthouse@redhat.com Darran Lofthouse
              darran.lofthouse@redhat.com Darran Lofthouse
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: