[rfc-dist] RFC 10015 on Deprecating Obsolete Key Exchange Meth ods in TLS 1.2 and DTLS 1.2

[email protected] Thu, 16 Jul 2026 20:57:40 -0000
Newsgroups gmane.ietf.rfc.announce,gmane.ietf.tls
Message-ID <[email protected]>
A new Request for Comments is now available in online RFC libraries.

        RFC 10015

        Title:      Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2
        Author:     N. Aviram
        Status:     Proposed Standard
        Stream:     IETF
        Date:       July 2026
        Mailbox:    [email protected]
        Pages:      21
        Updates:    RFC 4162, RFC 4279, RFC 4346, RFC 4785, RFC 5246, RFC 5288, 
                    RFC 5289, RFC 5469, RFC 5487, RFC 5932, RFC 6209, RFC 6367, 
                    RFC 6347, RFC 6655, RFC 7905, RFC 8422, RFC 9325


        I-D Tag:    draft-ietf-tls-deprecate-obsolete-kex-08

        URL:        https://www.rfc-editor.org/info/rfc10015

        DOI:        10.17487/RFC10015

For (D)TLS 1.2, this document deprecates the use of two key exchanges, namely Diffie-Hellman (DH) over a finite field and RSA. It also discourages the use of static Elliptic Curve Diffie-Hellman (ECDH) cipher suites.

These prescriptions apply only to (D)TLS 1.2, since (D)TLS 1.0 and TLS 1.1 are deprecated by RFC 8996 and (D)TLS 1.3 either does not use the affected algorithms or does not share the relevant configuration options. (There is no DTLS version 1.1.)

This document updates RFCs 4162, 4279, 4346, 4785, 5246, 5288, 5289, 5469, 5487, 5932, 6209, 6347, 6367, 6655, 7905, 8422, and 9325 to either deprecate or discourage the use of cipher suites using the above key exchange methods in (D)TLS 1.2 connections.

This document is a product of the Transport Layer Security Working Group of the IETF.

STANDARDS TRACK: This document specifies an Internet Standards Track
protocol for the Internet community, and requests discussion and
suggestions for improvements. Distribution of this memo is unlimited.

This announcement is sent to the IETF-Announce and rfc-dist lists.
To subscribe or unsubscribe, see
  https://www.ietf.org/mailman/listinfo/ietf-announce
  https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist

For searching the RFC series, see https://www.rfc-editor.org/search/
For downloading RFCs, see https://www.rfc-editor.org/series/rfc-download/

Requests for special distribution should be addressed to either the
author of the RFC in question, or to [email protected].  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.


The RFC Editor Team

_______________________________________________
rfc-dist mailing list -- [email protected]
To unsubscribe send an email to [email protected]
http://www.rfc-editor.org