| 115 |
CRL refresh clarifications |
|
Approval (Future Improvement) |
19 |
6.4.4.4.2 |
5th |
25 Jun 25 |
06 Oct 25 |
S. Fries |
| 102 |
Session Key Update timer clarification |
|
Approval (Future Improvement) |
33 |
8.4 |
2 |
06 Feb 25 |
09 Oct 25 |
S. Pini |
| 93 |
Clarification request: does the detection of a revoked X509 lead to TLS session retirement? |
|
Approval (Future Improvement) |
19 |
6.4.4.4.1 |
2 |
19 Dec 24 |
07 Feb 25 |
C. Gordon |
| 89 |
The case of a not-yet-valid CRL is not handled |
|
Approval (Future Improvement) |
20 |
6.4.4.4.2 |
1 |
04 Dec 24 |
07 Feb 25 |
C. Gordon |
| 87 |
6.4.4.4.1 contains two alarm definitions but only one appears in Table A.1 |
|
Approval (Future Improvement) |
19 |
6.4.4.4.1 |
8 and 9 |
03 Dec 24 |
07 Feb 25 |
C. Gordon |
| 81 |
Triple Handshake (CVE-2014-1295) |
|
Approval (Future Improvement) |
26 |
7.5.2 |
1 |
02 Dec 24 |
16 Jun 25 |
C. Cattaneo |
| 80 |
Verification based upon individual certificates - mandatory |
|
Approval (Future Improvement) |
18 |
6.4.4.3 |
1 |
25 Nov 24 |
07 Feb 25 |
S. Pini |
| 65 |
IEC 62351-3 X509, CRL, OCSP requirements vs. IEC 62351-9 |
|
Approval (Future Improvement) |
18 |
6.4.4.1 |
1 |
04 Nov 24 |
07 Feb 25 |
C. Gordon |
| 63 |
Section 7.4.5 does not specify a maximum wait time for response to HelloRequest |
|
Approval (Future Improvement) |
26 |
7.4.5 |
7 |
22 Oct 24 |
09 Oct 25 |
C. Gordon |
| 62 |
Is the use of not-yet-valid certificates forbidden? |
|
Approval (Future Improvement) |
20 |
6.4.4.5 |
1 |
15 Oct 24 |
07 Feb 25 |
C. Gordon |
| 59 |
Failure in finding a matching cipher suite |
|
Approval (Future Improvement) |
15 |
6 |
0 |
12 Sep 24 |
08 Jan 25 |
C. Cattaneo |
| 50 |
Add mandatory support for extended master secret extension (RFC 7627) to TLS 1.2 |
|
Approval (Future Improvement) |
1 |
1 |
1 |
05 Jul 24 |
07 Feb 25 |
C. Gordon |
| 49 |
"Session renegotiation shall be aligned with CRL update period" is ambiguous |
|
Approval (Future Improvement) |
25 |
7.4.5 |
4 |
01 Jul 24 |
07 Feb 25 |
C. Gordon |
| 45 |
TLS 1.2 mandates support for an ECC cipher suite, but does not mandate support for the corresponding |
|
Approval (Future Improvement) |
21 |
7.2 |
Table 1 |
22 Jun 24 |
07 Feb 25 |
C. Gordon |
| 44 |
TLS 1.2 Server status_request ambiguity |
|
Approval (Future Improvement) |
28 |
7.5.5.2 |
4-5 |
21 Jun 24 |
08 Jan 25 |
C. Gordon |
| 29 |
TLS cipher suite support |
|
Approval (Future Improvement) |
21 |
7.2 |
Table 1 |
17 Jul 23 |
19 Oct 23 |
S. Fries |
| 28 |
Support of minimum path len in certificate hierarchy |
|
Approval (Future Improvement) |
18 |
6.4.4 |
new subsection |
17 Jul 23 |
19 Oct 23 |
S. Fries |
| 27 |
Problem in session resumption report |
|
Approval (Future Improvement) |
35 |
8.6 |
1 |
17 Jul 23 |
19 Oct 23 |
M. Lacroix |
| 26 |
Add security event non-encrypting cipher suites is used |
|
Approval (Future Improvement) |
16 |
6.3 |
1 |
17 Jul 23 |
19 Oct 23 |
M. Lacroix |