An implementation may claim conformance to one or more Secure Transport Connection Profiles.
A Secure Transport Connection Profile includes the following information:
Description of the protocol framework and negotiation mechanisms
Description of the entity authentication an implementation shall support
The identity of the entities being authenticated
The mechanism by which entities are authenticated
Any special considerations for audit log support
Description of the encryption mechanism an implementation shall support
The method of distributing session keys
The encryption protocol and relevant parameters
Description of the integrity check mechanism an implementation shall support
Secure Transport Connection Profiles are specified in Annex B.