[TLS] Re: [Technical Errata Reported] RFC9846 (9040)

Deb Cooley <[email protected]> Tue, 28 Jul 2026 05:50:40 -0400
Newsgroups gmane.ietf.tls
Message-ID <CAGgd1OdOfHfB4=EDJk7dA3ysSxUcRV_DmoY6w0tdhLJx_bFUag@mail.gmail.com>
--===============4075764908922290212==
Content-Type: multipart/alternative; boundary="0000000000003859390657a8c643"

--0000000000003859390657a8c643
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

It is in my queue to handle.  I assume, 'verified' is the proper marking.

Deb

On Mon, Jul 27, 2026 at 4:37=E2=80=AFPM <[email protected]> wrote:

> The following errata report has been submitted for RFC9846,
> "The Transport Layer Security (TLS) Protocol Version 1.3"
>
> --------------------------------------
> You may review the report below and at:
> https://errata.rfc-editor.org/eid9040/
>
> --------------------------------------
> Type: Technical
> Reported by: Eric Rescorla <[email protected]>
>
> Section E.2 says:
>
> Original Text
> -------------
> A TLS server can also receive a ClientHello indicating a version
>    number smaller than its highest supported version.  If the
>    "supported_versions" extension is present, the server MUST negotiate
>    using that extension as described in Section 4.3.1.  If the
>    "supported_versions" extension is not present, the server MUST
>    negotiate the minimum of ClientHello.legacy_version and TLS 1.2.  For
>    example, if the server supports TLS 1.0, 1.1, and 1.2, and
>    legacy_version is TLS 1.0, the server will proceed with a TLS 1.0
>    ServerHello.  If the "supported_versions" extension is absent and the
>    server only supports versions greater than
>    ClientHello.legacy_version, the server MUST abort the handshake with
>    a "protocol_version" alert.
>
> Corrected Text
> --------------
> TLS server can also receive a ClientHello indicating a version
>    number smaller than its highest supported version.  If the
>    "supported_versions" extension is present, the server MUST
>    negotiate using that extension as described in Section 4.3.1. If
>    the "supported_versions" extension is absent and the
>    ClientHello.legacy_version is TLS 1.2, then the server MUST proceed
>    with TLS 1.2. Otherwise, the server MUST abort the handshake with a
>    "protocol_version" alert.
>
> Notes
> -----
> We no longer support < TLS 1.2.
>
> Issue originally reported by Jaime Gomez Garcia
>
> Instructions:
> -------------
> This erratum is currently posted as "Reported". Please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party
> will log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC9846 (draft-ietf-tls-rfc8446bis)
> --------------------------------------
> Title               : The Transport Layer Security (TLS) Protocol Version
> 1.3
> Publication Date    : July 2026
> Author(s)           : E. Rescorla
> Category            : Proposed Standard
> Source              : tls (sec)
> Stream              : IETF
> Verifying Party     : IESG
>

--0000000000003859390657a8c643
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>It is in my queue to handle.=C2=A0 I assume, &#39;ver=
ified&#39; is the proper marking.</div><div><br></div><div>Deb</div></div><=
br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=
=3D"gmail_attr">On Mon, Jul 27, 2026 at 4:37=E2=80=AFPM &lt;<a href=3D"mail=
to:[email protected]">[email protected]</a>&gt; wrote:<br><=
/div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bo=
rder-left:1px solid rgb(204,204,204);padding-left:1ex">The following errata=
 report has been submitted for RFC9846,<br>
&quot;The Transport Layer Security (TLS) Protocol Version 1.3&quot;<br>
<br>
--------------------------------------<br>
You may review the report below and at:<br>
<a href=3D"https://errata.rfc-editor.org/eid9040/" rel=3D"noreferrer" targe=
t=3D"_blank">https://errata.rfc-editor.org/eid9040/</a><br>
<br>
--------------------------------------<br>
Type: Technical<br>
Reported by: Eric Rescorla &lt;<a href=3D"mailto:[email protected]" target=3D"_b=
lank">[email protected]</a>&gt;<br>
<br>
Section E.2 says:<br>
<br>
Original Text<br>
-------------<br>
A TLS server can also receive a ClientHello indicating a version<br>
=C2=A0 =C2=A0number smaller than its highest supported version.=C2=A0 If th=
e<br>
=C2=A0 =C2=A0&quot;supported_versions&quot; extension is present, the serve=
r MUST negotiate<br>
=C2=A0 =C2=A0using that extension as described in Section 4.3.1.=C2=A0 If t=
he<br>
=C2=A0 =C2=A0&quot;supported_versions&quot; extension is not present, the s=
erver MUST<br>
=C2=A0 =C2=A0negotiate the minimum of ClientHello.legacy_version and TLS 1.=
2.=C2=A0 For<br>
=C2=A0 =C2=A0example, if the server supports TLS 1.0, 1.1, and 1.2, and<br>
=C2=A0 =C2=A0legacy_version is TLS 1.0, the server will proceed with a TLS =
1.0<br>
=C2=A0 =C2=A0ServerHello.=C2=A0 If the &quot;supported_versions&quot; exten=
sion is absent and the<br>
=C2=A0 =C2=A0server only supports versions greater than<br>
=C2=A0 =C2=A0ClientHello.legacy_version, the server MUST abort the handshak=
e with<br>
=C2=A0 =C2=A0a &quot;protocol_version&quot; alert.<br>
<br>
Corrected Text<br>
--------------<br>
TLS server can also receive a ClientHello indicating a version<br>
=C2=A0 =C2=A0number smaller than its highest supported version.=C2=A0 If th=
e<br>
=C2=A0 =C2=A0&quot;supported_versions&quot; extension is present, the serve=
r MUST<br>
=C2=A0 =C2=A0negotiate using that extension as described in Section 4.3.1. =
If<br>
=C2=A0 =C2=A0the &quot;supported_versions&quot; extension is absent and the=
<br>
=C2=A0 =C2=A0ClientHello.legacy_version is TLS 1.2, then the server MUST pr=
oceed<br>
=C2=A0 =C2=A0with TLS 1.2. Otherwise, the server MUST abort the handshake w=
ith a<br>
=C2=A0 =C2=A0&quot;protocol_version&quot; alert.<br>
<br>
Notes<br>
-----<br>
We no longer support &lt; TLS 1.2.<br>
<br>
Issue originally reported by Jaime Gomez Garcia<br>
<br>
Instructions:<br>
-------------<br>
This erratum is currently posted as &quot;Reported&quot;. Please<br>
use &quot;Reply All&quot; to discuss whether it should be verified or<br>
rejected. When a decision is reached, the verifying party=C2=A0 <br>
will log in to change the status and edit the report, if necessary.<br>
<br>
--------------------------------------<br>
RFC9846 (draft-ietf-tls-rfc8446bis)<br>
--------------------------------------<br>
Title=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0: The Transport=
 Layer Security (TLS) Protocol Version 1.3<br>
Publication Date=C2=A0 =C2=A0 : July 2026<br>
Author(s)=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0: E. Rescorla<br>
Category=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 : Proposed Standard<br>
Source=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 : tls (sec)<br>
Stream=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 : IETF<br>
Verifying Party=C2=A0 =C2=A0 =C2=A0: IESG<br>
</blockquote></div>

--0000000000003859390657a8c643--


--===============4075764908922290212==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp
bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0
bHMtbGVhdmVAaWV0Zi5vcmcK

--===============4075764908922290212==--