<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-tls-renegotiation" target="https://datatracker.ietf.org/doc/html/draft-ietf-tls-renegotiation-03">
   <front>
      <title>Transport Layer Security (TLS) Renegotiation Indication Extension</title>
      <author initials="O." surname="Way" fullname="One Way">
         <organization>Microsoft</organization>
      </author>
      <author initials="M." surname="Ray" fullname="Marsh Ray">
         <organization>PhoneFactor</organization>
      </author>
      <author initials="S." surname="Dispensa" fullname="Steve Dispensa">
         <organization>PhoneFactor</organization>
      </author>
      <author initials="E." surname="Rescorla" fullname="Eric Rescorla">
         <organization>RTFM, Inc.</organization>
      </author>
      <date month="January" day="5" year="2010" />
      <abstract>
	 <t>Secure Socket Layer (SSL) and Transport Layer Security (TLS) renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client.  The server treats the client&#x27;s initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data.  This specification defines a TLS extension to cryptographically tie renegotiations to the TLS connections they are being performed over, thus preventing this attack. [STANDARDS-TRACK]
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-tls-renegotiation-03" />
   
</reference>
