Return-Path: <nathanritz@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1])
	by mail2.ietf.org (Postfix) with ESMTP id A9B7011814687
	for <tls@mail2.ietf.org>; Thu, 16 Jul 2026 14:07:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1;
	t=1784236079; bh=p/LLvDrk0TIt3EDVxB9CXBIThBGREKm7bzd8GfkiMA4=;
	h=References:In-Reply-To:From:Date:Subject:To;
	b=Hdy9sSh/HS+VzdEHIFblgW4vAR8uip+AIzG0/Tgh4UZ8zhL9zuJL6Vjuvy8BHsAJg
	 YvpRBMcjVAwt/UCPKrCW0hMvO/JUe/4YnxInLQ05LTvVCR8Hr9SBmmaALlOVxeeBhM
	 v+7zwHhvvGea1m2VHekr5i2HWMxGim4djPjI5gTo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.098
X-Spam-Level: 
X-Spam-Status: No, score=-1.098 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
	FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001,
	SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key)
	header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31])
	by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id vqC91fT-38dc for <tls@mail2.ietf.org>;
	Thu, 16 Jul 2026 14:07:59 -0700 (PDT)
Received: from mail-pg1-x535.google.com (mail-pg1-x535.google.com
 [IPv6:2607:f8b0:4864:20::535])
	(using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by mail2.ietf.org (Postfix) with ESMTPS id 3719811814669
	for <tls@ietf.org>; Thu, 16 Jul 2026 14:07:59 -0700 (PDT)
Received: by mail-pg1-x535.google.com with SMTP id
 41be03b00d2f7-c96c92c0980so2450448a12.3
        for <tls@ietf.org>; Thu, 16 Jul 2026 14:07:59 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784236078; cv=none;
        d=google.com; s=arc-20260327;
        b=OUT20YfbX6tvOjSR2+a3VLO24/Eyx/CGaMxuj+iMqkPqi1BsNvk12X3V4LwqPc9qhf
         4Vehc4KC6xRjbGCC7mpAKKXPTJh/g7YfscwqriTxJcv9IaH7lUU1Cl/+fMu39RR7ZsKF
         aVf03q0UQ+Rv8V12YLNdk5QvzS1zWsHC3swqBojbN4/ElkvTJSlMPQrYFcbYkqckubBm
         7gMsWUbdkgctrvt5XGswuNZbME6QzxgdAuE22P5IYd2gfUxZJksAzXGUpoP6sMaldcIW
         2ySBMVhiT2udDf3tTEECdms5R1CFYG4Ep3DdgJTtLUUZaBsEkhmu1DYb58BvyUuFTr8c
         XGPw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
 s=arc-20260327;
        h=to:subject:message-id:date:from:in-reply-to:references:mime-version
         :dkim-signature;
        bh=xsov4MKOMaa9gIdKQwqHDGwVEBdloMXyAT6cd1044ok=;
        fh=wca+bLuwiWw2LyRqga7JffJVzCondAOxdRfTbMi1CyY=;
        b=h3nMii0cniZwRWjhxJz9KehepW0AjYma6ko1RmhE4C4Gq6HGtN8i7A223m/vFAtifv
         p2F5Qr3LW6SXp7LVtyzTZOyjjZ+ii1vh3vi6cmrfT2wJeyBQoC0F9WdU9LXVSRrA40lI
         Q/MCWbflgPslcZdh7NOP0OvIajUbgPJ8cr7AN5kOa3aBNrU2B+qmALv3R8nFiZT4rL4i
         am0a8Ge37ZlQ+5u6X3uAFLdTEyDfPGpHXCiSIRtN3WyUAZMLYhl4oRRNK/E1ff+Fhuv2
         uNFYMexKxEhrErkUgmLaM/QyV8BqRmNnKJcFJqJbDA1C6hO2X8SpS9iNkdjOJHaxL9r0
         a0jA==;
        darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20251104; t=1784236078; x=1784840878; darn=ietf.org;
        h=content-type:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:from:to:cc:subject:date:message-id:reply-to
         :content-type;
        bh=xsov4MKOMaa9gIdKQwqHDGwVEBdloMXyAT6cd1044ok=;
        b=WgT/FIAGj4TBMjgS8qcPhH8uiERCqLc57pizXZpTTF/+fcBqd5EyBjTeuwiWg7m68G
         p6idSuw5PKg0n+pLwxPEZANs0SeZAgbCvV2WDt6j0D4Zw0pBDL9gYl5ECAo47iME7wxX
         2ybu9BerAEHwDlOwzfzh5jO6fQJSPxC/My9ANHwgq5bvgLWDTCmdfg+TIx7d3MRIFERD
         LVgluufp4bLIfNg5KRvehIOsvKLNoy1NbleABR6WfDJJopMQDMbCju/QfTsAkyfXPXZu
         ywy6OEE8rUO88ZovIA81XXLZeIRLZ9X38wUA5YM6T2zBezuKolq/zaTkwiRfmcil7YoW
         UJWQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20251104; t=1784236078; x=1784840878;
        h=content-type:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date
         :message-id:reply-to:content-type;
        bh=xsov4MKOMaa9gIdKQwqHDGwVEBdloMXyAT6cd1044ok=;
        b=nQq3wNSURrLuRprZomdu5e8gt5+L5Frj3m62G0B9tsY0zNsbZwgUz73xrEu9BZYVgg
         IHt+8zTFa4wnHihAt5s5TsuBm+Iz6LHIKT06AZwDM8mDaP0BksjHipg5zyaOX03bKftv
         Rv1k45yGeSoj0wY8CyET8OdMkOzvlLW0RhqS9e6lVbql9n3FvNFRdJlVtI+ZDyUYXY0q
         NIfILHq/z4Eab6nxYVtDX/uvAJXvP/A9mNY116KsoWlj3/Zs4cSjNN72aqJ+KeBGETHA
         Cm0TL7yvDViNG0nCRxaVwgXzrDMuDFqBPklyNWfGuKbWaOWL2orMCD3F6Umu2VKYAsAz
         RZAg==
X-Gm-Message-State: AOJu0YxQ9NLlU2ZMEyg8jbqZ5tuREDDriAbWrNRIR07QR18vrz+8ZsA8
	gFg/zdfgCV0hnuIXlHmYQh1gFZ3ZzbZ1r8WfBocwHIRU5ufG1VKRDDUxYU9+4psa2+YTg03Capy
	8R2GTGVxDKSPWiJKW96nflVCkL1G7qAxeljxZ14Q=
X-Gm-Gg: AfdE7clg6ALiTPQj3C5lGtjnaqTZwDixVrirHKhNSZMEjUBLBHlYWCRylfXNTB1vDn0
	ZaO6x5/PQ1AO1S3pbKArdEMFQeOhK0Acz41BA6FooH4TR2HF8omwZK3WgSWeT6ZIJuBuBiKVkAa
	oI/2SylOA9q2W1LFqtkc4nwKY6BCtSEaFfHyiDHFZz21rWDTONqfctXI9Jyk3dojg/PEbHqaelG
	jh5mN0V3oherta4ffo8OZFxtuusa3DygNgRX1j07qw/dxqSYsihus/zEZUQ8w==
X-Received: by 2002:a05:6a21:7002:b0:3c3:83e8:c210 with SMTP id
 adf61e73a8af0-3c3a5f076f6mr799414637.73.1784236078025; Thu, 16 Jul 2026
 14:07:58 -0700 (PDT)
MIME-Version: 1.0
References: <178423546035.16.1079009831577821175@rfc-editor.org>
In-Reply-To: <178423546035.16.1079009831577821175@rfc-editor.org>
From: Nathanael Ritz <nathanritz@gmail.com>
Date: Thu, 16 Jul 2026 15:07:46 -0600
X-Gm-Features: AUfX_mxOuhkZo3IahtJpOnKuzx7Ry0JqSkcEiEBWx4oxwmsMzJzWVKruBTNxYds
Message-ID: 
 <CAHxYnaNJhZgRAwuB2doucm08E+_jspmhfMt5jS85st2B=B1tRQ@mail.gmail.com>
To: TLS List <tls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000a04f680656c0d5c6"
Message-ID-Hash: 2DA4FQPEA5DN5HO3FT5VMMBHMGV2LCUD
X-Message-ID-Hash: 2DA4FQPEA5DN5HO3FT5VMMBHMGV2LCUD
X-MailFrom: nathanritz@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-tls.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5BTLS=5D_Re=3A_RFC_10015_on_Deprecating_Obsolete_Key_Exchange_Met?=
 =?utf-8?q?hods_in_TLS_1=2E2_and_DTLS_1=2E2?=
List-Id: "This is the mailing list for the Transport Layer Security working
 group of the IETF." <tls.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/tls/N4O6CxDCxXdGW2IsgvDoZ98Nx2M>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

--000000000000a04f680656c0d5c6
Content-Type: text/plain; charset="UTF-8"

Wow the RFC Editor has been on an absolute tear in recent days. The joke
has been made before; and yet, it's actually an honest curiosity that I
wonder how many systems relying on obsolete key exchange methods in (D)TLS
1.2 might break with yet another 10K+ RFC? Hopefully Wes's toaster has been
patched already [0].

Cheers,
Nathanael

[0] https://mailarchive.ietf.org/arch/msg/ietf/eM_-9TVMX-SNtRxURqsWvk29498/

On Thu, 16 Jul 2026 at 14:57, <rfc-editor@rfc-editor.org> wrote:

> A new Request for Comments is now available in online RFC libraries.
>
>         RFC 10015
>
>         Title:      Deprecating Obsolete Key Exchange Methods in TLS 1.2
> and DTLS 1.2
>         Author:     N. Aviram
>         Status:     Proposed Standard
>         Stream:     IETF
>         Date:       July 2026
>         Mailbox:    nimrod.aviram@gmail.com
>         Pages:      21
>         Updates:    RFC 4162, RFC 4279, RFC 4346, RFC 4785, RFC 5246, RFC
> 5288,
>                     RFC 5289, RFC 5469, RFC 5487, RFC 5932, RFC 6209, RFC
> 6367,
>                     RFC 6347, RFC 6655, RFC 7905, RFC 8422, RFC 9325
>
>
>         I-D Tag:    draft-ietf-tls-deprecate-obsolete-kex-08
>
>         URL:        https://www.rfc-editor.org/info/rfc10015
>
>         DOI:        10.17487/RFC10015
>
> For (D)TLS 1.2, this document deprecates the use of two key exchanges,
> namely Diffie-Hellman (DH) over a finite field and RSA. It also discourages
> the use of static Elliptic Curve Diffie-Hellman (ECDH) cipher suites.
>
> These prescriptions apply only to (D)TLS 1.2, since (D)TLS 1.0 and TLS 1.1
> are deprecated by RFC 8996 and (D)TLS 1.3 either does not use the affected
> algorithms or does not share the relevant configuration options. (There is
> no DTLS version 1.1.)
>
> This document updates RFCs 4162, 4279, 4346, 4785, 5246, 5288, 5289, 5469,
> 5487, 5932, 6209, 6347, 6367, 6655, 7905, 8422, and 9325 to either
> deprecate or discourage the use of cipher suites using the above key
> exchange methods in (D)TLS 1.2 connections.
>
> This document is a product of the Transport Layer Security Working Group
> of the IETF.
>
> STANDARDS TRACK: This document specifies an Internet Standards Track
> protocol for the Internet community, and requests discussion and
> suggestions for improvements. Distribution of this memo is unlimited.
>
> This announcement is sent to the IETF-Announce and rfc-dist lists.
> To subscribe or unsubscribe, see
>   https://www.ietf.org/mailman/listinfo/ietf-announce
>   https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist
>
> For searching the RFC series, see https://www.rfc-editor.org/search/
> For downloading RFCs, see https://www.rfc-editor.org/series/rfc-download/
>
> Requests for special distribution should be addressed to either the
> author of the RFC in question, or to rfc-editor@rfc-editor.org.  Unless
> specifically noted otherwise on the RFC itself, all RFCs are for
> unlimited distribution.
>
>
> The RFC Editor Team
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>

--000000000000a04f680656c0d5c6
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Wow the RFC Editor has been on an absolute tear in recent =
days. The joke has been made before; and yet, it&#39;s actually an honest c=
uriosity that I wonder how many systems relying on obsolete=C2=A0key exchan=
ge methods in (D)TLS 1.2 might break with yet another 10K+ RFC? Hopefully W=
es&#39;s toaster has been patched already [0].<div><br></div><div>Cheers,</=
div><div>Nathanael<br><div><br></div><div>[0]=C2=A0<a href=3D"https://maila=
rchive.ietf.org/arch/msg/ietf/eM_-9TVMX-SNtRxURqsWvk29498/">https://mailarc=
hive.ietf.org/arch/msg/ietf/eM_-9TVMX-SNtRxURqsWvk29498/</a></div></div></d=
iv><br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" cl=
ass=3D"gmail_attr">On Thu, 16 Jul 2026 at 14:57, &lt;<a href=3D"mailto:rfc-=
editor@rfc-editor.org">rfc-editor@rfc-editor.org</a>&gt; wrote:<br></div><b=
lockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-le=
ft:1px solid rgb(204,204,204);padding-left:1ex">A new Request for Comments =
is now available in online RFC libraries.<br>
<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 RFC 10015<br>
<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Title:=C2=A0 =C2=A0 =C2=A0 Deprecating Obsolete=
 Key Exchange Methods in TLS 1.2 and DTLS 1.2<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Author:=C2=A0 =C2=A0 =C2=A0N. Aviram<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Status:=C2=A0 =C2=A0 =C2=A0Proposed Standard<br=
>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Stream:=C2=A0 =C2=A0 =C2=A0IETF<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Date:=C2=A0 =C2=A0 =C2=A0 =C2=A0July 2026<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Mailbox:=C2=A0 =C2=A0 <a href=3D"mailto:nimrod.=
aviram@gmail.com" target=3D"_blank">nimrod.aviram@gmail.com</a><br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Pages:=C2=A0 =C2=A0 =C2=A0 21<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Updates:=C2=A0 =C2=A0 RFC 4162, RFC 4279, RFC 4=
346, RFC 4785, RFC 5246, RFC 5288, <br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 RFC 5=
289, RFC 5469, RFC 5487, RFC 5932, RFC 6209, RFC 6367, <br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 RFC 6=
347, RFC 6655, RFC 7905, RFC 8422, RFC 9325<br>
<br>
<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 I-D Tag:=C2=A0 =C2=A0 draft-ietf-tls-deprecate-=
obsolete-kex-08<br>
<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 URL:=C2=A0 =C2=A0 =C2=A0 =C2=A0 <a href=3D"http=
s://www.rfc-editor.org/info/rfc10015" rel=3D"noreferrer" target=3D"_blank">=
https://www.rfc-editor.org/info/rfc10015</a><br>
<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 DOI:=C2=A0 =C2=A0 =C2=A0 =C2=A0 10.17487/RFC100=
15<br>
<br>
For (D)TLS 1.2, this document deprecates the use of two key exchanges, name=
ly Diffie-Hellman (DH) over a finite field and RSA. It also discourages the=
 use of static Elliptic Curve Diffie-Hellman (ECDH) cipher suites.<br>
<br>
These prescriptions apply only to (D)TLS 1.2, since (D)TLS 1.0 and TLS 1.1 =
are deprecated by RFC 8996 and (D)TLS 1.3 either does not use the affected =
algorithms or does not share the relevant configuration options. (There is =
no DTLS version 1.1.)<br>
<br>
This document updates RFCs 4162, 4279, 4346, 4785, 5246, 5288, 5289, 5469, =
5487, 5932, 6209, 6347, 6367, 6655, 7905, 8422, and 9325 to either deprecat=
e or discourage the use of cipher suites using the above key exchange metho=
ds in (D)TLS 1.2 connections.<br>
<br>
This document is a product of the Transport Layer Security Working Group of=
 the IETF.<br>
<br>
STANDARDS TRACK: This document specifies an Internet Standards Track<br>
protocol for the Internet community, and requests discussion and<br>
suggestions for improvements. Distribution of this memo is unlimited.<br>
<br>
This announcement is sent to the IETF-Announce and rfc-dist lists.<br>
To subscribe or unsubscribe, see<br>
=C2=A0 <a href=3D"https://www.ietf.org/mailman/listinfo/ietf-announce" rel=
=3D"noreferrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo/iet=
f-announce</a><br>
=C2=A0 <a href=3D"https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist"=
 rel=3D"noreferrer" target=3D"_blank">https://mailman.rfc-editor.org/mailma=
n/listinfo/rfc-dist</a><br>
<br>
For searching the RFC series, see <a href=3D"https://www.rfc-editor.org/sea=
rch/" rel=3D"noreferrer" target=3D"_blank">https://www.rfc-editor.org/searc=
h/</a><br>
For downloading RFCs, see <a href=3D"https://www.rfc-editor.org/series/rfc-=
download/" rel=3D"noreferrer" target=3D"_blank">https://www.rfc-editor.org/=
series/rfc-download/</a><br>
<br>
Requests for special distribution should be addressed to either the<br>
author of the RFC in question, or to <a href=3D"mailto:rfc-editor@rfc-edito=
r.org" target=3D"_blank">rfc-editor@rfc-editor.org</a>.=C2=A0 Unless<br>
specifically noted otherwise on the RFC itself, all RFCs are for<br>
unlimited distribution.<br>
<br>
<br>
The RFC Editor Team<br>
<br>
_______________________________________________<br>
TLS mailing list -- <a href=3D"mailto:tls@ietf.org" target=3D"_blank">tls@i=
etf.org</a><br>
To unsubscribe send an email to <a href=3D"mailto:tls-leave@ietf.org" targe=
t=3D"_blank">tls-leave@ietf.org</a><br>
</blockquote></div>

--000000000000a04f680656c0d5c6--

