<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.rosomakho-tls-supplemental-auth" target="https://datatracker.ietf.org/doc/html/draft-rosomakho-tls-supplemental-auth-00">
   <front>
      <title>Supplemental Authentication in TLS 1.3</title>
      <author initials="Y." surname="Rosomakho" fullname="Yaroslav Rosomakho">
         <organization>Zscaler</organization>
      </author>
      <author initials="T." surname="Reddy.K" fullname="Tirumaleswar Reddy.K">
         <organization>Nokia</organization>
      </author>
      <author initials="R." surname="Shekh-Yusef" fullname="Rifaat Shekh-Yusef">
         <organization>Ciena</organization>
      </author>
      <author initials="H." surname="Tschofenig" fullname="Hannes Tschofenig">
         <organization>University of the Bundeswehr Munich</organization>
      </author>
      <date month="June" day="25" year="2026" />
      <abstract>
	 <t>   TLS 1.3 allows endpoints to authenticate using certificates during
   the handshake and supports optional post-handshake client
   authentication.  However, some deployments require presenting
   additional certificate-based authentication statements bound to the
   same TLS connection, such as separate device and user identities,
   attestation evidence, or multiple certificate chains during
   cryptographic transitions.

   This document defines Supplemental Authentication for TLS 1.3, a
   mechanism that allows endpoints to present additional certificate
   authentication messages after the handshake while preserving the
   authentication semantics of TLS 1.3.  Supplemental authentication
   reuses the existing Certificate, CertificateVerify, and Finished
   message structure and allows endpoints to exchange one or more
   additional certificate-based authentication statements before sending
   application data or other post-handshake TLS messages.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-rosomakho-tls-supplemental-auth-00" />
   
</reference>
