[gnutls-devel] GnuTLS | Add setting for requiring use of EMS in TLS 1.2 (#1445)

Read-only notification of GnuTLS library development activities gnutls-devel at lists.gnutls.org
Tue Jan 3 18:08:04 CET 2023



Hubert Kario (@mention me if you need reply) created an issue: https://gitlab.com/gnutls/gnutls/-/issues/1445



## Description of the feature:
The [FIPS 140-3 I.G.](https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf) will require use of EMS KDF for TLS 1.2 after 16th of May 2023.

GnuTLS should have a way to requiring use of EMS for connections that have negotiated TLS 1.2.

## Applications that this feature may be relevant to:
All applications using TLS in FIPS mode.

## Is this feature implemented in other libraries (and which)
`requireExtendedMasterSecret` is a setting in tlslite-ng, not aware of others

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/issues/1445
You're receiving this email because of your account on gitlab.com.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnutls-devel/attachments/20230103/511f61f4/attachment-0001.html>


More information about the Gnutls-devel mailing list