Cite this RFC:TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC8996
Discuss this RFC: Send questions or comments to the mailing listtls@ietf.org
Other actions:View Errata | Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 8996
This document formally deprecates Transport Layer Security (TLS)versions 1.0 (RFC 2246) and 1.1 (RFC 4346). Accordingly, thosedocuments have been moved to Historic status. These versions lacksupport for current and recommended cryptographic algorithms andmechanisms, and various government and industry profiles ofapplications using TLS now mandate avoiding these old TLS versions.TLS version 1.2 became the recommended version for IETF protocols in2008 (subsequently being obsoleted by TLS version 1.3 in 2018),providing sufficient time to transition away from older versions.Removing support for older versions from implementations reduces theattack surface, reduces opportunity for misconfiguration, andstreamlines library and product maintenance.
This document also deprecates Datagram TLS (DTLS) version 1.0 (RFC4347) but not DTLS version 1.2, and there is no DTLS version 1.1.
This document updates many RFCs that normatively refer to TLS version1.0 or TLS version 1.1, as described herein. This document alsoupdates the best practices for TLS usage in RFC 7525; hence, it ispart of BCP 195.
For the definition ofStatus,seeRFC 2026.
For the definition ofStream, seeRFC 8729.