@techreport{dkg-tls-reject-static-dh-01, number = {draft-dkg-tls-reject-static-dh-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-dkg-tls-reject-static-dh/01/}, author = {Daniel Kahn Gillmor}, title = {{TLS clients should reject static Diffie-Hellman}}, pagetotal = 8, year = 2018, month = dec, day = 4, abstract = {This draft addresses problematic proposals that contradict the expected security properties of TLS. In particular, the ETSI "Middlebox Security Protocol" standard deliberately weakens the cryptographic guarantees of TLS unilaterally by the server, using static Diffie-Hellman keys where ephemeral keys are expected. Responsible TLS clients should avoid connecting to servers that appear to implement such a specification.}, }