Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

According to the post the server cert is not sent in the server hello, but later in the handshake, after encryption has been established.


Section 4.4 of the rfc[1] makes it clear the cert is sent encrypted. [1] https://tools.ietf.org/html/rfc8446#section-4.4




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: