@techreport{rosomakho-tls-cert-update-02, number = {draft-rosomakho-tls-cert-update-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-rosomakho-tls-cert-update/02/}, author = {Yaroslav Rosomakho and Tirumaleswar Reddy.K}, title = {{Certificate Update in TLS 1.3}}, pagetotal = 14, year = 2026, month = jun, day = 18, abstract = {This document defines a mechanism that enables TLS 1.3 endpoints to update their certificates during the lifetime of a connection using Exported Authenticators. A new extension is introduced to negotiate support for certificate update at handshake time. When negotiated, either endpoint can provide a post-handshake authenticator containing an updated certificate, delivered via a new handshake message. This mechanism allows long-lived TLS connections to remain valid across certificate rotations without requiring session termination.}, }