Source record · tier 1 standards and regulators
RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3
- Publisher
- IETF
- URL
- https://www.rfc-editor.org/rfc/rfc8446.html
- Published
- 2018-08
- Updated
- unknown
- Accessed
- 2026-09-25
- HTTP status
- 200
- License
- IETF Trust Legal Provisions (BCP 78); no-redistribution; short excerpts and locators only
Source notes citing this source
- Because TLS 1.3 encrypts the Certificate messages, a plain packet capture of a TLS 1.3 SIP trunk cannot show whether the SBC sent its intermediates; Microsoft's capture-based check for a missing chain works directly only on TLS 1.2 sessions, and TLS 1.3 needs a key log or device-side debugs. inferred in context
- TLS defines distinct certificate alerts: bad_certificate (42), unsupported_certificate (43), certificate_revoked (44), certificate_expired (45, also sent for not-yet-valid certificates), certificate_unknown (46) and unknown_ca (48, for a chain that cannot be anchored in a trusted CA). in context
- In TLS 1.3 every handshake message after ServerHello is encrypted, including the Certificate messages. in context
- The TLS handshake_failure alert (40) means the sender could not negotiate an acceptable set of security parameters from the options offered. in context
- TLS signals an unsupported protocol version with protocol_version (70) and parameters judged too weak with insufficient_security (71); in TLS 1.3 a server that requires a client certificate and gets none sends certificate_required (116). in context
Cite this source record
APA
WarmTransfer. (n.d.). RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3. WarmTransfer. https://warmtransfer.net/knowledge/sources/rfc-8446-tls-1-3
BibTeX
@misc{warmtransfer-rfc-8446-tls-1-3,
title = {RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3},
author = {{WarmTransfer}},
year = {2018},
url = {https://warmtransfer.net/knowledge/sources/rfc-8446-tls-1-3},
note = {IETF, accessed 2026-09-25}
}