[TLS] Re: RFC 10015 on Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2
Nathanael Ritz <nathanritz@gmail.com> Thu, 16 July 2026 21:07 UTC
Return-Path: <nathanritz@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A9B7011814687 for <tls@mail2.ietf.org>; Thu, 16 Jul 2026 14:07:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784236079; bh=p/LLvDrk0TIt3EDVxB9CXBIThBGREKm7bzd8GfkiMA4=; h=References:In-Reply-To:From:Date:Subject:To; b=Hdy9sSh/HS+VzdEHIFblgW4vAR8uip+AIzG0/Tgh4UZ8zhL9zuJL6Vjuvy8BHsAJg YvpRBMcjVAwt/UCPKrCW0hMvO/JUe/4YnxInLQ05LTvVCR8Hr9SBmmaALlOVxeeBhM v+7zwHhvvGea1m2VHekr5i2HWMxGim4djPjI5gTo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.098
X-Spam-Level:
X-Spam-Status: No, score=-1.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vqC91fT-38dc for <tls@mail2.ietf.org>; Thu, 16 Jul 2026 14:07:59 -0700 (PDT)
Received: from mail-pg1-x535.google.com (mail-pg1-x535.google.com [IPv6:2607:f8b0:4864:20::535]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 3719811814669 for <tls@ietf.org>; Thu, 16 Jul 2026 14:07:59 -0700 (PDT)
Received: by mail-pg1-x535.google.com with SMTP id 41be03b00d2f7-c96c92c0980so2450448a12.3 for <tls@ietf.org>; Thu, 16 Jul 2026 14:07:59 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784236078; cv=none; d=google.com; s=arc-20260327; b=OUT20YfbX6tvOjSR2+a3VLO24/Eyx/CGaMxuj+iMqkPqi1BsNvk12X3V4LwqPc9qhf 4Vehc4KC6xRjbGCC7mpAKKXPTJh/g7YfscwqriTxJcv9IaH7lUU1Cl/+fMu39RR7ZsKF aVf03q0UQ+Rv8V12YLNdk5QvzS1zWsHC3swqBojbN4/ElkvTJSlMPQrYFcbYkqckubBm 7gMsWUbdkgctrvt5XGswuNZbME6QzxgdAuE22P5IYd2gfUxZJksAzXGUpoP6sMaldcIW 2ySBMVhiT2udDf3tTEECdms5R1CFYG4Ep3DdgJTtLUUZaBsEkhmu1DYb58BvyUuFTr8c XGPw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=xsov4MKOMaa9gIdKQwqHDGwVEBdloMXyAT6cd1044ok=; fh=wca+bLuwiWw2LyRqga7JffJVzCondAOxdRfTbMi1CyY=; b=h3nMii0cniZwRWjhxJz9KehepW0AjYma6ko1RmhE4C4Gq6HGtN8i7A223m/vFAtifv p2F5Qr3LW6SXp7LVtyzTZOyjjZ+ii1vh3vi6cmrfT2wJeyBQoC0F9WdU9LXVSRrA40lI Q/MCWbflgPslcZdh7NOP0OvIajUbgPJ8cr7AN5kOa3aBNrU2B+qmALv3R8nFiZT4rL4i am0a8Ge37ZlQ+5u6X3uAFLdTEyDfPGpHXCiSIRtN3WyUAZMLYhl4oRRNK/E1ff+Fhuv2 uNFYMexKxEhrErkUgmLaM/QyV8BqRmNnKJcFJqJbDA1C6hO2X8SpS9iNkdjOJHaxL9r0 a0jA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784236078; x=1784840878; darn=ietf.org; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=xsov4MKOMaa9gIdKQwqHDGwVEBdloMXyAT6cd1044ok=; b=WgT/FIAGj4TBMjgS8qcPhH8uiERCqLc57pizXZpTTF/+fcBqd5EyBjTeuwiWg7m68G p6idSuw5PKg0n+pLwxPEZANs0SeZAgbCvV2WDt6j0D4Zw0pBDL9gYl5ECAo47iME7wxX 2ybu9BerAEHwDlOwzfzh5jO6fQJSPxC/My9ANHwgq5bvgLWDTCmdfg+TIx7d3MRIFERD LVgluufp4bLIfNg5KRvehIOsvKLNoy1NbleABR6WfDJJopMQDMbCju/QfTsAkyfXPXZu ywy6OEE8rUO88ZovIA81XXLZeIRLZ9X38wUA5YM6T2zBezuKolq/zaTkwiRfmcil7YoW UJWQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784236078; x=1784840878; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xsov4MKOMaa9gIdKQwqHDGwVEBdloMXyAT6cd1044ok=; b=nQq3wNSURrLuRprZomdu5e8gt5+L5Frj3m62G0B9tsY0zNsbZwgUz73xrEu9BZYVgg IHt+8zTFa4wnHihAt5s5TsuBm+Iz6LHIKT06AZwDM8mDaP0BksjHipg5zyaOX03bKftv Rv1k45yGeSoj0wY8CyET8OdMkOzvlLW0RhqS9e6lVbql9n3FvNFRdJlVtI+ZDyUYXY0q NIfILHq/z4Eab6nxYVtDX/uvAJXvP/A9mNY116KsoWlj3/Zs4cSjNN72aqJ+KeBGETHA Cm0TL7yvDViNG0nCRxaVwgXzrDMuDFqBPklyNWfGuKbWaOWL2orMCD3F6Umu2VKYAsAz RZAg==
X-Gm-Message-State: AOJu0YxQ9NLlU2ZMEyg8jbqZ5tuREDDriAbWrNRIR07QR18vrz+8ZsA8 gFg/zdfgCV0hnuIXlHmYQh1gFZ3ZzbZ1r8WfBocwHIRU5ufG1VKRDDUxYU9+4psa2+YTg03Capy 8R2GTGVxDKSPWiJKW96nflVCkL1G7qAxeljxZ14Q=
X-Gm-Gg: AfdE7clg6ALiTPQj3C5lGtjnaqTZwDixVrirHKhNSZMEjUBLBHlYWCRylfXNTB1vDn0 ZaO6x5/PQ1AO1S3pbKArdEMFQeOhK0Acz41BA6FooH4TR2HF8omwZK3WgSWeT6ZIJuBuBiKVkAa oI/2SylOA9q2W1LFqtkc4nwKY6BCtSEaFfHyiDHFZz21rWDTONqfctXI9Jyk3dojg/PEbHqaelG jh5mN0V3oherta4ffo8OZFxtuusa3DygNgRX1j07qw/dxqSYsihus/zEZUQ8w==
X-Received: by 2002:a05:6a21:7002:b0:3c3:83e8:c210 with SMTP id adf61e73a8af0-3c3a5f076f6mr799414637.73.1784236078025; Thu, 16 Jul 2026 14:07:58 -0700 (PDT)
MIME-Version: 1.0
References: <178423546035.16.1079009831577821175@rfc-editor.org>
In-Reply-To: <178423546035.16.1079009831577821175@rfc-editor.org>
From: Nathanael Ritz <nathanritz@gmail.com>
Date: Thu, 16 Jul 2026 15:07:46 -0600
X-Gm-Features: AUfX_mxOuhkZo3IahtJpOnKuzx7Ry0JqSkcEiEBWx4oxwmsMzJzWVKruBTNxYds
Message-ID: <CAHxYnaNJhZgRAwuB2doucm08E+_jspmhfMt5jS85st2B=B1tRQ@mail.gmail.com>
To: TLS List <tls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000a04f680656c0d5c6"
Message-ID-Hash: 2DA4FQPEA5DN5HO3FT5VMMBHMGV2LCUD
X-Message-ID-Hash: 2DA4FQPEA5DN5HO3FT5VMMBHMGV2LCUD
X-MailFrom: nathanritz@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: RFC 10015 on Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/N4O6CxDCxXdGW2IsgvDoZ98Nx2M>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Wow the RFC Editor has been on an absolute tear in recent days. The joke has been made before; and yet, it's actually an honest curiosity that I wonder how many systems relying on obsolete key exchange methods in (D)TLS 1.2 might break with yet another 10K+ RFC? Hopefully Wes's toaster has been patched already [0]. Cheers, Nathanael [0] https://mailarchive.ietf.org/arch/msg/ietf/eM_-9TVMX-SNtRxURqsWvk29498/ On Thu, 16 Jul 2026 at 14:57, <rfc-editor@rfc-editor.org> wrote: > A new Request for Comments is now available in online RFC libraries. > > RFC 10015 > > Title: Deprecating Obsolete Key Exchange Methods in TLS 1.2 > and DTLS 1.2 > Author: N. Aviram > Status: Proposed Standard > Stream: IETF > Date: July 2026 > Mailbox: nimrod.aviram@gmail.com > Pages: 21 > Updates: RFC 4162, RFC 4279, RFC 4346, RFC 4785, RFC 5246, RFC > 5288, > RFC 5289, RFC 5469, RFC 5487, RFC 5932, RFC 6209, RFC > 6367, > RFC 6347, RFC 6655, RFC 7905, RFC 8422, RFC 9325 > > > I-D Tag: draft-ietf-tls-deprecate-obsolete-kex-08 > > URL: https://www.rfc-editor.org/info/rfc10015 > > DOI: 10.17487/RFC10015 > > For (D)TLS 1.2, this document deprecates the use of two key exchanges, > namely Diffie-Hellman (DH) over a finite field and RSA. It also discourages > the use of static Elliptic Curve Diffie-Hellman (ECDH) cipher suites. > > These prescriptions apply only to (D)TLS 1.2, since (D)TLS 1.0 and TLS 1.1 > are deprecated by RFC 8996 and (D)TLS 1.3 either does not use the affected > algorithms or does not share the relevant configuration options. (There is > no DTLS version 1.1.) > > This document updates RFCs 4162, 4279, 4346, 4785, 5246, 5288, 5289, 5469, > 5487, 5932, 6209, 6347, 6367, 6655, 7905, 8422, and 9325 to either > deprecate or discourage the use of cipher suites using the above key > exchange methods in (D)TLS 1.2 connections. > > This document is a product of the Transport Layer Security Working Group > of the IETF. > > STANDARDS TRACK: This document specifies an Internet Standards Track > protocol for the Internet community, and requests discussion and > suggestions for improvements. Distribution of this memo is unlimited. > > This announcement is sent to the IETF-Announce and rfc-dist lists. > To subscribe or unsubscribe, see > https://www.ietf.org/mailman/listinfo/ietf-announce > https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist > > For searching the RFC series, see https://www.rfc-editor.org/search/ > For downloading RFCs, see https://www.rfc-editor.org/series/rfc-download/ > > Requests for special distribution should be addressed to either the > author of the RFC in question, or to rfc-editor@rfc-editor.org. Unless > specifically noted otherwise on the RFC itself, all RFCs are for > unlimited distribution. > > > The RFC Editor Team > > _______________________________________________ > TLS mailing list -- tls@ietf.org > To unsubscribe send an email to tls-leave@ietf.org >
- [TLS] RFC 10015 on Deprecating Obsolete Key Excha… rfc-editor
- [TLS] Re: RFC 10015 on Deprecating Obsolete Key E… Nathanael Ritz