@techreport{rosomakho-tls-supplemental-auth-00, number = {draft-rosomakho-tls-supplemental-auth-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-rosomakho-tls-supplemental-auth/00/}, author = {Yaroslav Rosomakho and Tirumaleswar Reddy.K and Rifaat Shekh-Yusef and Hannes Tschofenig}, title = {{Supplemental Authentication in TLS 1.3}}, pagetotal = 22, year = 2026, month = jun, day = 25, abstract = {TLS 1.3 allows endpoints to authenticate using certificates during the handshake and supports optional post-handshake client authentication. However, some deployments require presenting additional certificate-based authentication statements bound to the same TLS connection, such as separate device and user identities, attestation evidence, or multiple certificate chains during cryptographic transitions. This document defines Supplemental Authentication for TLS 1.3, a mechanism that allows endpoints to present additional certificate authentication messages after the handshake while preserving the authentication semantics of TLS 1.3. Supplemental authentication reuses the existing Certificate, CertificateVerify, and Finished message structure and allows endpoints to exchange one or more additional certificate-based authentication statements before sending application data or other post-handshake TLS messages.}, }