Quantcast
Channel: https – Gea-Suan Lin's BLOG
Viewing all articles
Browse latest Browse all 267

SSL 變成 TLS 名字的由來

$
0
0

Lobsters 上看到「Security Standards and Name Changes in the Browser Wars」這篇 2014 的文章,裡面提供了當初加密協定 SSL 變成 TLS 的由來。

當初 Netscape 弄出 SSLv2 後變得很熱門,但也發現了不少問題,所以微軟弄出自己的 PCT 準備競爭,不過後來 SSLv3 修掉了不少問題,加上 Netscape 當時的領先地位,IE 還是有支援 SSLv3。

接下來是大老們看到可能的分歧,找到關鍵人物開會取得共識,讓 IETF 來領隊:

And we negotiated a deal where Microsoft and Netscape would both support the IETF taking over the protocol and standardizing it in an open process, which led to me editing the RFC.

不過 SSLv3 把當時已知的問題都修掉了,但為了政治上的問題,故意小修了 SSLv3 裡面的東西,然後改名成 TLS:

As a part of the horsetrading, we had to make some changes to SSL 3.0 (so it wouldn't look the IETF was just rubberstamping Netscape's protocol), and we had to rename the protocol (for the same reason). And thus was born TLS 1.0 (which was really SSL 3.1). And of course, now, in retrospect, the whole thing looks silly.

差不多是三十年前的故事了...


Viewing all articles
Browse latest Browse all 267

Latest Images

Trending Articles