RFC 9849: TLS Encrypted ClientHello
Summary
RFC 9849 encrypts most of the TLS ClientHello and thereby protects destination and negotiation data that used to be visible. Content encryption alone does not hide all metadata of a connection. More privacy changes troubleshooting and network filtering.
Ideas
- A public ECH configuration object starts the encryption.
- The inner ClientHello contains the actual server name.
- The outer ClientHello stays compatible for paths without support.
Remarks
- RFC 9849 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Update DNS, CDN and TLS configuration in a coordinated way.
- Test fallback and key rotation from different networks.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.