<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.sullivan-tls-signed-ech-updates" target="https://datatracker.ietf.org/doc/html/draft-sullivan-tls-signed-ech-updates-02">
   <front>
      <title>Authenticated ECH Config Distribution and Rotation</title>
      <author initials="N." surname="Sullivan" fullname="Nick Sullivan">
         <organization>Cryptography Consulting LLC</organization>
      </author>
      <author initials="D." surname="Jackson" fullname="Dennis Jackson">
         <organization>Mozilla</organization>
      </author>
      <author initials="A." surname="Ghedini" fullname="Alessandro Ghedini">
         <organization>Cloudflare</organization>
      </author>
      <date month="July" day="6" year="2026" />
      <abstract>
	 <t>   Encrypted ClientHello (ECH) requires clients to have the server&#x27;s ECH
   configuration before connecting.  Currently, when ECH fails, servers
   can send updated configurations but clients cannot authenticate them
   unless the server has a valid certificate for the public name,
   limiting deployment flexibility.

   This document specifies a new mechanism for authenticating ECH
   configurations.  Servers include additional information in their
   initial ECH configurations, which enables clients to authenticate
   updated configurations without relying on a valid certificate for the
   public name.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-sullivan-tls-signed-ech-updates-02" />
   
</reference>
