[TLS] Re: RFC 10015 on Deprecating Obsolete Key Exchange Met hods in TLS 1.2 and DTLS 1.2
Nathanael Ritz <[email protected]> Thu, 16 Jul 2026 15:07:46 -0600
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <CAHxYnaNJhZgRAwuB2doucm08E+_jspmhfMt5jS85st2B=B1tRQ@mail.gmail.com> |
Wow the RFC Editor has been on an absolute tear in recent days. The joke has been made before; and yet, it's actually an honest curiosity that I wonder how many systems relying on obsolete key exchange methods in (D)TLS 1.2 might break with yet another 10K+ RFC? Hopefully Wes's toaster has been patched already [0]. Cheers, Nathanael [0] https://mailarchive.ietf.org/arch/msg/ietf/eM_-9TVMX-SNtRxURqsWvk29498/ On Thu, 16 Jul 2026 at 14:57, <[email protected]> wrote: > A new Request for Comments is now available in online RFC libraries. > > RFC 10015 > > Title: Deprecating Obsolete Key Exchange Methods in TLS 1.2 > and DTLS 1.2 > Author: N. Aviram > Status: Proposed Standard > Stream: IETF > Date: July 2026 > Mailbox: [email protected] > Pages: 21 > Updates: RFC 4162, RFC 4279, RFC 4346, RFC 4785, RFC 5246, RFC > 5288, > RFC 5289, RFC 5469, RFC 5487, RFC 5932, RFC 6209, RFC > 6367, > RFC 6347, RFC 6655, RFC 7905, RFC 8422, RFC 9325 > > > I-D Tag: draft-ietf-tls-deprecate-obsolete-kex-08 > > URL: https://www.rfc-editor.org/info/rfc10015 > > DOI: 10.17487/RFC10015 > > For (D)TLS 1.2, this document deprecates the use of two key exchanges, > namely Diffie-Hellman (DH) over a finite field and RSA. It also discourages > the use of static Elliptic Curve Diffie-Hellman (ECDH) cipher suites. > > These prescriptions apply only to (D)TLS 1.2, since (D)TLS 1.0 and TLS 1.1 > are deprecated by RFC 8996 and (D)TLS 1.3 either does not use the affected > algorithms or does not share the relevant configuration options. (There is > no DTLS version 1.1.) > > This document updates RFCs 4162, 4279, 4346, 4785, 5246, 5288, 5289, 5469, > 5487, 5932, 6209, 6347, 6367, 6655, 7905, 8422, and 9325 to either > deprecate or discourage the use of cipher suites using the above key > exchange methods in (D)TLS 1.2 connections. > > This document is a product of the Transport Layer Security Working Group > of the IETF. > > STANDARDS TRACK: This document specifies an Internet Standards Track > protocol for the Internet community, and requests discussion and > suggestions for improvements. Distribution of this memo is unlimited. > > This announcement is sent to the IETF-Announce and rfc-dist lists. > To subscribe or unsubscribe, see > https://www.ietf.org/mailman/listinfo/ietf-announce > https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist > > For searching the RFC series, see https://www.rfc-editor.org/search/ > For downloading RFCs, see https://www.rfc-editor.org/series/rfc-download/ > > Requests for special distribution should be addressed to either the > author of the RFC in question, or to [email protected]. Unless > specifically noted otherwise on the RFC itself, all RFCs are for > unlimited distribution. > > > The RFC Editor Team > > _______________________________________________ > TLS mailing list -- [email protected] > To unsubscribe send an email to [email protected] > _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]