From 94eabfe82f189b7a5fb7f1ee32ac3074aa58088f Mon Sep 17 00:00:00 2001 From: Anit Gandhi Date: Tue, 27 Jun 2023 11:52:42 -0500 Subject: [PATCH] doc/go1.21: document changes in crypto/tls related to client authentication alerts For #52113 For #58645 --- doc/go1.21.html | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/doc/go1.21.html b/doc/go1.21.html index 1a39a27c85..906f29c8c6 100644 --- a/doc/go1.21.html +++ b/doc/go1.21.html @@ -583,6 +583,32 @@ Do not send CLs removing the interior tags from such phrases. The new VersionName function returns the name for a TLS version number.

+ +

+ The TLS alert codes sent from the server for client authentication failures have + been improved. Prior to Go 1.21, these failures always resulted in a "bad certificate" alert. + Starting from Go 1.21, certain failures will result in more appropriate alert codes, + as defined by RFC 5246 and RFC 8446: +

+