%% You should probably cite rfc7366 instead of this I-D. @techreport{ietf-tls-encrypt-then-mac-03, number = {draft-ietf-tls-encrypt-then-mac-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-tls-encrypt-then-mac/03/}, author = {Peter Gutmann}, title = {{Encrypt-then-MAC for Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)}}, pagetotal = 7, year = 2014, month = jul, day = 22, abstract = {This document describes a means of negotiating the use of the encrypt-then-MAC security mechanism in place of the existing MAC-then-encrypt mechanism in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS). The MAC-then-encrypt mechanism has been the subject of a number of security vulnerabilities over a period of many years.}, }