RFC 3620:The TUNNEL Profile
RFC-Ref

TLS


Click on the red underlined text to get to the source

... initiating and terminating machines perform a "tuning reset," not unlike the way starting a TLS negotiation discards cached session state ...
... BEEP framing. The two endpoint machines may therefore negotiate TLS between them, passing certificates appropriate to the endpoints ...


... closes the other. [4] This greeting may include the TLS profile, allowing initial and final to communicate without proxy1 understanding or interfering ...


... If a transport security layer (such as TLS) has been negotiated over the session, the semantics ...


... 538 Encryption already enabled (E.g., TLS already negotiated, or a SASL that provides encryption ...


... Negotiation of a TLS profile in an end-to-end manner after a TUNNEL ...
... has been established will prevent intermediate proxies from observing or modifying the cleartext information exchanged, but only if TLS certificates are properly configured during the negotiation ...



Google
Web
RFC-Ref