Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Flood a TLS server during post-handshake authentication #6

Open
artem-smotrakov opened this issue Oct 6, 2019 · 0 comments
Open

Flood a TLS server during post-handshake authentication #6

artem-smotrakov opened this issue Oct 6, 2019 · 0 comments

Comments

@artem-smotrakov
Copy link
Owner

From https://tools.ietf.org/html/rfc8446#section-4.6.2

   Note: Because client authentication could involve prompting the user,
   servers MUST be prepared for some delay, including receiving an
   arbitrary number of other messages between sending the
   CertificateRequest and receiving a response.

A malicious client can try to send other messages without sending authentication messages in a hope that the server crashes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant