Tue Jan 3 18:08:04 CET 2023

Hubert Kario (@mention me if you need reply) created an issue: https://gitlab.com/gnutls/gnutls/-/issues/1445

## Description of the feature:
The [FIPS 140-3 I.G.](https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf) will require use of EMS KDF for TLS 1.2 after 16th of May 2023.

GnuTLS should have a way to requiring use of EMS for connections that have negotiated TLS 1.2.

## Applications that this feature may be relevant to:
All applications using TLS in FIPS mode.

## Is this feature implemented in other libraries (and which)
`requireExtendedMasterSecret` is a setting in tlslite-ng, not aware of others

Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/issues/1445
