Internet Engineering Task Force (IETF)M. Thomson
Request for Comments: 8470Mozilla
Category: Standards TrackM. Nottingham
ISSN: 2070-1721Fastly
W. Tarreau
HAProxy Technologies
September 2018

Using Early Data in HTTP

Abstract

Using TLS early data creates an exposure to the possibility of a replay attack. This document defines mechanisms that allow clients to communicate with servers about HTTP requests that are sent in early data. Techniques are described that use these mechanisms to mitigate the risk of replay.