<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.huitema-tls-sni-encryption" target="https://datatracker.ietf.org/doc/html/draft-huitema-tls-sni-encryption-02">
   <front>
      <title>SNI Encryption in TLS Through Tunneling</title>
      <author initials="C." surname="Huitema" fullname="Christian Huitema">
         <organization>Private Octopus Inc.</organization>
      </author>
      <author initials="E." surname="Rescorla" fullname="Eric Rescorla">
         <organization>RTFM, Inc.</organization>
      </author>
      <date month="July" day="3" year="2017" />
      <abstract>
	 <t>   This draft describes the general problem of encryption of the Server
   Name Identification (SNI) parameter.  The proposed solutions hide a
   Hidden Service behind a Fronting Service, only disclosing the SNI of
   the Fronting Service to external observers.  The draft starts by
   listing known attacks against SNI encryption, discusses the current
   &quot;co-tenancy fronting&quot; solution, and then presents two potential TLS
   layer solutions that might mitigate these attacks.
   The first solution is based on TLS in TLS &quot;quasi tunneling&quot;, and the
   second solution is based on &quot;combined tickets&quot;.  These solutions only
   require minimal extensions to the TLS protocol.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-huitema-tls-sni-encryption-02" />
   
</reference>
