%% You should probably cite rfc5746 instead of this I-D. @techreport{ietf-tls-renegotiation-03, number = {draft-ietf-tls-renegotiation-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-tls-renegotiation/03/}, author = {One Way and Marsh Ray and Steve Dispensa and Eric Rescorla}, title = {{Transport Layer Security (TLS) Renegotiation Indication Extension}}, pagetotal = 15, year = 2010, month = jan, day = 5, abstract = {Secure Socket Layer (SSL) and Transport Layer Security (TLS) renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client. The server treats the client's initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data. This specification defines a TLS extension to cryptographically tie renegotiations to the TLS connections they are being performed over, thus preventing this attack. {[}STANDARDS-TRACK{]}}, }