Urgent.News

What's breaking now, across thousands of outlets.

Tech

RFC 10015: Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2

RFC 10015 addresses the deprecation of obsolete key exchange methods in TLS 1.2 and DTLS 1.2. Specifically, the document discourages the use of Diffie-Hellman (DH) over a finite field and RSA key exchanges in (D)TLS 1.2. Additionally, static Elliptic Curve Diffie-Hellman (ECDH) cipher suites are discouraged. These recommendations only apply to (D)TLS 1.2, as earlier versions (1.0, 1.1) are deprecated and (D)TLS 1.3 does not utilize these affected algorithms.

The document updates various RFCs to either deprecate or discourage the use of cipher suites employing the aforementioned key exchange methods. The problems with these key exchanges stem from a lack of forward secrecy, implementation vulnerabilities, and susceptibility to side-channel attacks.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at rfc-editor.org →

More in Tech

More from Saturday 1 August →