During the Lucid 4 meeting of 13/3/2025 we were unable to definitively answer whether Level 3 security was even possible; that is the authentication of the client only without any server authentication (from a TLS perspective). It was thought that the server would always have to exchange a certificate if the client were also then to send a certificate.
We need to determine if this is the case and if so, remove the entry from the protocol specification.
During the Lucid 4 meeting of 13/3/2025 we were unable to definitively answer whether Level 3 security was even possible; that is the authentication of the client only without any server authentication (from a TLS perspective). It was thought that the server would always have to exchange a certificate if the client were also then to send a certificate.
We need to determine if this is the case and if so, remove the entry from the protocol specification.