RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3 (opens in a new window)
The protocol behind mTLS point-to-point encryption, including the handshake flow and the reasoning behind forward secrecy.
rfc-editor.org
Resources
These links point to public material from government agencies, standards bodies and non-profit organisations. They are not owned by Kunan Technology; the publishing body is authoritative.
9 references
The protocol behind mTLS point-to-point encryption, including the handshake flow and the reasoning behind forward secrecy.
rfc-editor.org
Concrete guidance on which cipher suites to enable and which versions to disable — more directly applicable to configuration than the protocol document itself.
rfc-editor.org
The rules for chain validation, validity periods and revocation — the foundation for designing a device identity certificate hierarchy.
rfc-editor.org
Defines authenticator assurance levels, and is the original source for modern practices such as not forcing periodic password rotation.
pages.nist.gov
An authorisation model that adds contextual attributes on top of RBAC — the next reference when service-level segmentation policy needs finer granularity.
csrc.nist.gov
The full control catalogue, commonly used to map contractual security clauses and client audit items back to something specific.
csrc.nist.gov
A checkable list of application security requirements, well suited to being written into acceptance criteria for outsourced development.
owasp.org
The open methodology for penetration testing — useful for checking whether the scope of an engagement you commissioned is actually complete.
owasp.org
The scoring standard for vulnerability severity. Reading the vector string is what tells you whether a high score is actually high risk in your environment.
first.org