security1 distinct publisher
IETF Publishes Encrypted Client Hello as a Standard to Encrypt SNI, With Caveats
RFC 9849 encrypts the ClientHello, so the domain field that SNI allowlists and passive TLS logs depend on stops appearing on the wire. In return, operators inherit a key rotation duty; the spec sets no fixed interval.
Publishers:rfc-editor.org
Reality
- Evidence88
- Adoption
- Insufficient