Skip to content

Check if Extended Master Secret is supported in TLSv1.2  #1541

@JakubOnderka

Description

@JakubOnderka

Extended Master Secret (EMS, RFC 7627) is extension for TLSv1.2 that prevents Triple Handshakes man-in-the-middle attacks.

After May 16, 2023, using EMS is mandatory by FIPS 140-3 IG, so FIPS enabled clients will reject connecting to TLSv1.2 servers that do not support EMS.

EMS support is also required by Recommendations for Secure Use of Transport Layer Security (RFC 9325).

It would be nice if Internet.nl checks if EMS is supported in HTTPS and also e-mail check.

Metadata

Metadata

Assignees

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions