%% You should probably cite draft-dkg-tls-reject-static-dh-01 instead of this revision. @techreport{dkg-tls-reject-static-dh-00, number = {draft-dkg-tls-reject-static-dh-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-dkg-tls-reject-static-dh/00/}, author = {Daniel Kahn Gillmor}, title = {{TLS clients should reject static Diffie-Hellman}}, pagetotal = 7, year = ** No value found for 'doc.pub_date.year' **, month = ** No value found for 'doc.pub_date' **, day = ** No value found for 'doc.pub_date.day' **, abstract = {This draft addresses problematic proposals that contradict the expected security properties of TLS. In particular, the ETSI "Middlebox Security Protocol" standard deliberately weakens the cryptographic guarantees of TLS unilaterally by the server, using static Diffie-Hellman keys where ephemeral keys are expected. Responsible TLS clients should avoid connecting to servers that appear to implement such a specification.}, }