Properties
ServerCertificate | o | Read only | Immutable | |
Hostname | s | Read only | Immutable | |
ReferenceIdentities | as | Read only | Immutable |
Description
A channel type that carries a TLS certificate between a server and a client connecting to it.
Channels of this kind always have Requested = False, TargetHandleType = None and TargetHandle = 0, and cannot be requested with methods such as CreateChannel. Also, they SHOULD be dispatched while the Connection owning them is in the CONNECTING state.
In this case, handlers SHOULD accept or reject the certificate, using the relevant methods on the provided object, or MAY just Close the channel before doing so, to fall back to a non-interactive verification process done inside the CM.
For example, channels of this kind can pop up while a client is connecting to an XMPP server.
Properties
ServerCertificate — o
A TLSCertificate containing the certificate chain as sent by the server, and other relevant information.
Hostname — s
The hostname or domain that the user expects to connect to. Clients SHOULD use the ReferenceIdentities property to verify the identity of the certificate. Clients MAY display this hostname to the user as the expected identity. Clients SHOULD use this property to lookup pinned certificates or other user preferences for the connection.
ReferenceIdentities — as
The identities of the server we expect ServerCertificate to certify; clients SHOULD verify that ServerCertificate matches one of these identities when checking its validity.
This property MUST NOT be the empty list; it MUST contain the value of the Hostname property. All other identities included in this property MUST be derived from explicit user input or choices, such as Parameters passed to RequestConnection.