>>>>> "PBK" == Patrick Ben Koetter <[email protected]> writes:

PBK> Sidenote: Ask for client certificate only if TLSA is present? I
PBK> like that.  This would safe us interop errors from clients that
PBK> can't handle being asked for a client certificate.

I like that, too, as an option.  But asking every client also should
be possible.  Admin's choice.

-JimC
--
James Cloos <[email protected]>         OpenPGP: 0x997A9F17ED7DAEA6

_______________________________________________
dane mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dane

Reply via email to