TCP-ENO: Encryption Negotiation Option
暂无分享,去创建一个
Despite growing adoption of TLS [RFC5246], a significant fraction of
TCP traffic on the Internet remains unencrypted. The persistence of
unencrypted traffic can be attributed to at least two factors. First,
some legacy protocols lack a signaling mechanism (such as a "STARTTLS"
command) by which to convey support for encryption, making incremental
deployment impossible. Second, legacy applications themselves cannot
always be upgraded, requiring a way to implement encryption
transparently entirely within the transport layer. The TCP Encryption
Negotiation Option (TCP-ENO) addresses both of these problems through
a new TCP option kind providing out-of-band, fully backward-compatible
negotiation of encryption.