[TLS] Re: RFC 10015 on Deprecating Obsolete Key Exchange Met hods in TLS 1.2 and DTLS 1.2

Nathanael Ritz <[email protected]> Thu, 16 Jul 2026 15:07:46 -0600
Newsgroups gmane.ietf.tls
Message-ID <CAHxYnaNJhZgRAwuB2doucm08E+_jspmhfMt5jS85st2B=B1tRQ@mail.gmail.com>
Wow the RFC Editor has been on an absolute tear in recent days. The joke
has been made before; and yet, it's actually an honest curiosity that I
wonder how many systems relying on obsolete key exchange methods in (D)TLS
1.2 might break with yet another 10K+ RFC? Hopefully Wes's toaster has been
patched already [0].

Cheers,
Nathanael

[0] https://mailarchive.ietf.org/arch/msg/ietf/eM_-9TVMX-SNtRxURqsWvk29498/

On Thu, 16 Jul 2026 at 14:57, <[email protected]> wrote:

> A new Request for Comments is now available in online RFC libraries.
>
>         RFC 10015
>
>         Title:      Deprecating Obsolete Key Exchange Methods in TLS 1.2
> and DTLS 1.2
>         Author:     N. Aviram
>         Status:     Proposed Standard
>         Stream:     IETF
>         Date:       July 2026
>         Mailbox:    [email protected]
>         Pages:      21
>         Updates:    RFC 4162, RFC 4279, RFC 4346, RFC 4785, RFC 5246, RFC
> 5288,
>                     RFC 5289, RFC 5469, RFC 5487, RFC 5932, RFC 6209, RFC
> 6367,
>                     RFC 6347, RFC 6655, RFC 7905, RFC 8422, RFC 9325
>
>
>         I-D Tag:    draft-ietf-tls-deprecate-obsolete-kex-08
>
>         URL:        https://www.rfc-editor.org/info/rfc10015
>
>         DOI:        10.17487/RFC10015
>
> For (D)TLS 1.2, this document deprecates the use of two key exchanges,
> namely Diffie-Hellman (DH) over a finite field and RSA. It also discourages
> the use of static Elliptic Curve Diffie-Hellman (ECDH) cipher suites.
>
> These prescriptions apply only to (D)TLS 1.2, since (D)TLS 1.0 and TLS 1.1
> are deprecated by RFC 8996 and (D)TLS 1.3 either does not use the affected
> algorithms or does not share the relevant configuration options. (There is
> no DTLS version 1.1.)
>
> This document updates RFCs 4162, 4279, 4346, 4785, 5246, 5288, 5289, 5469,
> 5487, 5932, 6209, 6347, 6367, 6655, 7905, 8422, and 9325 to either
> deprecate or discourage the use of cipher suites using the above key
> exchange methods in (D)TLS 1.2 connections.
>
> This document is a product of the Transport Layer Security Working Group
> of the IETF.
>
> STANDARDS TRACK: This document specifies an Internet Standards Track
> protocol for the Internet community, and requests discussion and
> suggestions for improvements. Distribution of this memo is unlimited.
>
> This announcement is sent to the IETF-Announce and rfc-dist lists.
> To subscribe or unsubscribe, see
>   https://www.ietf.org/mailman/listinfo/ietf-announce
>   https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist
>
> For searching the RFC series, see https://www.rfc-editor.org/search/
> For downloading RFCs, see https://www.rfc-editor.org/series/rfc-download/
>
> Requests for special distribution should be addressed to either the
> author of the RFC in question, or to [email protected].  Unless
> specifically noted otherwise on the RFC itself, all RFCs are for
> unlimited distribution.
>
>
> The RFC Editor Team
>
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]