%% You should probably cite rfc8672 instead of this I-D. @techreport{sheffer-tls-pinning-ticket-00, number = {draft-sheffer-tls-pinning-ticket-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-sheffer-tls-pinning-ticket/00/}, author = {Yaron Sheffer}, title = {{TLS Server Identity Pinning with Tickets}}, pagetotal = 14, year = 2015, month = oct, day = 11, abstract = {Fake public-key certificates are an ongoing problem for users of TLS. Several solutions have been proposed, but none is currently in wide use. This document proposes to extend TLS with opaque tickets, similar to those being used for TLS session resumption, as a way to pin the server's identity. That is, to ensure the client that it is connecting to the right server even in the presence of corrupt certificate authorities and fake certificates. The main advantage of this solution is that no manual management actions are required.}, }