%% You should probably cite draft-ietf-tls-renegotiation instead of this I-D. @techreport{rescorla-tls-renegotiation-01, number = {draft-rescorla-tls-renegotiation-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-rescorla-tls-renegotiation/01/}, author = {Eric Rescorla and Marsh Ray and Steve Dispensa and One Way}, title = {{Transport Layer Security (TLS) Renegotiation Indication Extension}}, pagetotal = 10, year = 2009, month = nov, day = 17, abstract = {SSL and TLS renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client. The server treats the client's initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data. This draft defines a TLS extension to cryptographically tie renegotiations to the TLS connections they are being performed over, thus preventing this attack.}, }