bk99.de entertain the web since 1997

RFC 9849: TLS Encrypted ClientHello

Summary

RFC 9849 encrypts most of the TLS ClientHello and thereby protects destination and negotiation data that used to be visible. Content encryption alone does not hide all metadata of a connection. More privacy changes troubleshooting and network filtering.

Ideas

  • A public ECH configuration object starts the encryption.
  • The inner ClientHello contains the actual server name.
  • The outer ClientHello stays compatible for paths without support.

Remarks

  • RFC 9849 has the status “Proposed Standard”; current errata and successor documents should also be checked.

Recommendations

  • Update DNS, CDN and TLS configuration in a coordinated way.
  • Test fallback and key rotation from different networks.

References

Read the RFC at the RFC Editor

Search the Web Archive