RFC 10015: Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2

Aug 02, 2026 06:44 AM - 1 day ago 50

1. Introduction

(D)TLS 1.2 supports a assortment of cardinal speech algorithms, including RSA, Diffie-Hellman (DH) over a finite field, and Elliptic Curve Diffie-Hellman (ECDH).¶

DH cardinal exchange, complete immoderate group, comes successful ephemeral and non-ephemeral varieties. Non-ephemeral DH algorithms usage fixed DH nationalist keys included in the authenticating peer's certificate; spot [RFC4492] for discussion. In contrast, ephemeral DH algorithms usage ephemeral DH nationalist keys sent successful the handshake and authenticated by the peer's certificate. Ephemeral and non-ephemeral finite section DH algorithms are called DHE and DH (or FFDHE and FFDH), respectively, and ephemeral and non-ephemeral elliptic curve DH algorithms are called ECDHE and ECDH, respectively [RFC4492]

In general, non-ephemeral cipher suites are not recommended owed to their deficiency of forward secrecy. Moreover, arsenic demonstrated by the Raccoon onslaught [RACCOON] connected finite section DH, nationalist cardinal reuse (either via non-ephemeral cipher suites aliases reused keys with ephemeral cipher suites) tin lead to timing broadside channels that whitethorn leak connection secrets. For ECDH, invalid curve attacks likewise utilization secret reuse successful bid to break information [ICA], further demonstrating the consequence of reusing public keys. While some broadside channels tin beryllium avoided successful implementations, experience shows that successful practice, implementations whitethorn neglect to thwart specified attacks owed to the complexity and number of the required mitigations.¶

Additionally, RSA cardinal speech suffers from information problems that are independent of implementation choices arsenic good arsenic problems that stem purely from the difficulty of implementing information countermeasures correctly.¶

At a unsmooth glance, the problems affecting FFDHE successful (D)TLS 1.2 are arsenic follows:¶

  1. FFDHE suffers from interoperability problems because location is nary system for negotiating the group, and immoderate implementations only support mini group sizes (see [RFC7919], Section 1).¶

  2. FFDHE groups whitethorn person mini subgroups, which enables respective attacks [SUBGROUPS]. When presented pinch a custom, non-standardized FFDHE group, a handshaking customer cannot practically verify that the group chosen by the server does not suffer from this problem. There is besides nary system for specified handshakes to autumn backmost to different cardinal speech parameters that are acceptable to the client. Custom FFDHE groups are wide (as a consequence of proposal based connected [WEAK-DH]). Therefore, clients cannot simply cull handshakes that coming custom, and frankincense perchance dangerous, groups.¶

  3. In practice, immoderate operators usage 1024-bit FFDHE groups since this is the maximum size that ensures wide support (see [RFC7919], Section 1). This size leaves only a mini information separator versus the existent discrete log record, which stands astatine 795 bits [DLOG795]

  4. Expanding connected the erstwhile point, conscionable a fistful of very ample computations allow an attacker to cheaply decrypt a comparatively ample fraction of FFDHE traffic (namely, postulation encrypted utilizing peculiar standardized groups) [WEAK-DH]

  5. When secrets are not afloat ephemeral, FFDHE suffers from the Raccoon side-channel onslaught [RACCOON]. (Note that FFDH is inherently susceptible to the Raccoon attack unless constant-time mitigations are employed.)¶

The problems affecting RSA cardinal speech successful (D)TLS 1.2 are arsenic follows:¶

  1. RSA cardinal speech offers nary guardant secrecy, by construction.¶

  2. RSA cardinal speech whitethorn beryllium susceptible to Bleichenbacher's onslaught [BLEI]. Experience shows that variants of this onslaught originate each fewer years because implementing the applicable countermeasure correctly is difficult (see [ROBOT], [NEW-BLEI], and [DROWN]).¶

  3. In summation to the supra point, location is nary convenient system successful (D)TLS 1.2 for the domain separation of keys. Therefore, a azygous endpoint that is susceptible to Bleichenbacher's onslaught would impact each endpoints sharing the aforesaid RSA cardinal (see [XPROT] and [DROWN]).¶

This archive updates [RFC4162], [RFC4279], [RFC4346], [RFC4785], [RFC5246], [RFC5288], [RFC5289], [RFC5469], [RFC5487], [RFC5932], [RFC6209], [RFC6347], [RFC6367], [RFC6655], [RFC7905], [RFC8422], and [RFC9325] to remediate the supra problems, by deprecating and discouraging the usage of affected cipher suites, arsenic listed successful Sections 5.2, 5.3, 5.4, and 5.5.¶

BCP 195 [RFC8996] [RFC9325] contains the latest IETF recommendations for users of the (D)TLS protocol (and specifically, (D)TLS 1.2), and this document updates [RFC9325] successful respective points. Section 6 specifications the nonstop differences. All different recommendations successful the BCP documents stay valid.¶

1.1. Requirements Language

The cardinal words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" successful this archive are to be interpreted arsenic described successful BCP 14 [RFC2119] [RFC8174] when, and only when, they look successful each capitals, as shown here.¶

9. References

9.1. Normative References

[RFC2119] Bradner, S., "Key words for usage successful RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, <https://www.rfc-editor.org/info/rfc2119>. [RFC4162] Lee, H.J., Yoon, J.H., and J.I. Lee, "Addition of SEED Cipher Suites to Transport Layer Security (TLS)", RFC 4162, DOI 10.17487/RFC4162, September 2005, <https://www.rfc-editor.org/info/rfc4162>. [RFC4279] Eronen, P., Ed. and H. Tschofenig, Ed., "Pre-Shared Key Ciphersuites for Transport Layer Security (TLS)", RFC 4279, DOI 10.17487/RFC4279, December 2005, <https://www.rfc-editor.org/info/rfc4279>. [RFC4346] Dierks, T. and E. Rescorla, "The Transport Layer Security (TLS) Protocol Version 1.1", RFC 4346, DOI 10.17487/RFC4346, April 2006, <https://www.rfc-editor.org/info/rfc4346>. [RFC4785] Blumenthal, U. and P. Goel, "Pre-Shared Key (PSK) Ciphersuites pinch NULL Encryption for Transport Layer Security (TLS)", RFC 4785, DOI 10.17487/RFC4785, January 2007, <https://www.rfc-editor.org/info/rfc4785>. [RFC5246] Dierks, T. and E. Rescorla, "The Transport Layer Security (TLS) Protocol Version 1.2", RFC 5246, DOI 10.17487/RFC5246, August 2008, <https://www.rfc-editor.org/info/rfc5246>. [RFC5288] Salowey, J., Choudhury, A., and D. McGrew, "AES Galois Counter Mode (GCM) Cipher Suites for TLS", RFC 5288, DOI 10.17487/RFC5288, August 2008, <https://www.rfc-editor.org/info/rfc5288>. [RFC5289] Rescorla, E., "TLS Elliptic Curve Cipher Suites pinch SHA-256/384 and AES Galois Counter Mode (GCM)", RFC 5289, DOI 10.17487/RFC5289, August 2008, <https://www.rfc-editor.org/info/rfc5289>. [RFC5469] Eronen, P., Ed., "DES and IDEA Cipher Suites for Transport Layer Security (TLS)", RFC 5469, DOI 10.17487/RFC5469, February 2009, <https://www.rfc-editor.org/info/rfc5469>. [RFC5487] Badra, M., "Pre-Shared Key Cipher Suites for TLS pinch SHA-256/384 and AES Galois Counter Mode", RFC 5487, DOI 10.17487/RFC5487, March 2009, <https://www.rfc-editor.org/info/rfc5487>. [RFC5932] Kato, A., Kanda, M., and S. Kanno, "Camellia Cipher Suites for TLS", RFC 5932, DOI 10.17487/RFC5932, June 2010, <https://www.rfc-editor.org/info/rfc5932>. [RFC6209] Kim, W., Lee, J., Park, J., and D. Kwon, "Addition of the ARIA Cipher Suites to Transport Layer Security (TLS)", RFC 6209, DOI 10.17487/RFC6209, April 2011, <https://www.rfc-editor.org/info/rfc6209>. [RFC6347] Rescorla, E. and N. Modadugu, "Datagram Transport Layer Security Version 1.2", RFC 6347, DOI 10.17487/RFC6347, January 2012, <https://www.rfc-editor.org/info/rfc6347>. [RFC6367] Kanno, S. and M. Kanda, "Addition of the Camellia Cipher Suites to Transport Layer Security (TLS)", RFC 6367, DOI 10.17487/RFC6367, September 2011, <https://www.rfc-editor.org/info/rfc6367>. [RFC6655] McGrew, D. and D. Bailey, "AES-CCM Cipher Suites for Transport Layer Security (TLS)", RFC 6655, DOI 10.17487/RFC6655, July 2012, <https://www.rfc-editor.org/info/rfc6655>. [RFC7905] Langley, A., Chang, W., Mavrogiannopoulos, N., Strombergson, J., and S. Josefsson, "ChaCha20-Poly1305 Cipher Suites for Transport Layer Security (TLS)", RFC 7905, DOI 10.17487/RFC7905, June 2016, <https://www.rfc-editor.org/info/rfc7905>. [RFC7919] Gillmor, D., "Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS)", RFC 7919, DOI 10.17487/RFC7919, August 2016, <https://www.rfc-editor.org/info/rfc7919>. [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase successful RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, <https://www.rfc-editor.org/info/rfc8174>. [RFC8422] Nir, Y., Josefsson, S., and M. Pegourie-Gonnard, "Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS) Versions 1.2 and Earlier", RFC 8422, DOI 10.17487/RFC8422, August 2018, <https://www.rfc-editor.org/info/rfc8422>. [RFC8996] Moriarty, K. and S. Farrell, "Deprecating TLS 1.0 and TLS 1.1", BCP 195, RFC 8996, DOI 10.17487/RFC8996, March 2021, <https://www.rfc-editor.org/info/rfc8996>. [RFC9147] Rescorla, E., Tschofenig, H., and N. Modadugu, "The Datagram Transport Layer Security (DTLS) Protocol Version 1.3", RFC 9147, DOI 10.17487/RFC9147, April 2022, <https://www.rfc-editor.org/info/rfc9147>. [RFC9325] Sheffer, Y., Saint-Andre, P., and T. Fossati, "Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)", BCP 195, RFC 9325, DOI 10.17487/RFC9325, November 2022, <https://www.rfc-editor.org/info/rfc9325>. [RFC9846] Rescorla, E., "The Transport Layer Security (TLS) Protocol Version 1.3", RFC 9846, DOI 10.17487/RFC9846, July 2026, <https://www.rfc-editor.org/info/rfc9846>. [RFC9847] Salowey, J. and S. Turner, "IANA Registry Updates for TLS and DTLS", RFC 9847, DOI 10.17487/RFC9847, December 2025, <https://www.rfc-editor.org/info/rfc9847>.

9.2. Informative References

[BLEI] Bleichenbacher, D., "Chosen Ciphertext Attacks against Protocols Based connected the RSA Encryption Standard PKCS #1", Advances successful Cryptology -- CRYPTO'98, Lecture Notes successful Computer Science, vol. 1462, pp. 1-12, DOI 10.1007/BFb0055716, 1998, <https://doi.org/10.1007/BFb0055716>. [DLOG795] Boudot, F., Gaudry, P., Guillevic, A., Heninger, N., Thomé, E., and P. Zimmermann, "Comparing the trouble of factorization and discrete logarithm: a 240-digit experiment", Cryptology ePrint Archive, Paper 2020/697, DOI 10.1007/978-3-030-56880-1_3, 17 August 2020, <https://eprint.iacr.org/2020/697>. [DROWN] Aviram, N., Schinzel, S., Somorovsky, J., Heninger, N., Dankel, M., Steube, J., Valenta, L., Adrian, D., Halderman, J. A., Dukhovni, V., Käsper, E., Cohney, S., Engels, S., Paar, C., and Y. Shavitt, "DROWN: Breaking TLS utilizing SSLv2", Proceedings of the 25th USENIX Security Symposium, August 2016, <https://drownattack.com/drown-attack-paper.pdf>. [ICA] Jager, T., Schwenk, J., and J. Somorovsky, "Practical invalid curve attacks connected TLS-ECDH", ESORICS 2015, Part I, Lecture Notes successful Computer Science, vol. 9326, pp. 407-425, DOI 10.1007/978-3-319-24174-6_21, 21 September 2015, <https://link.springer.com/content/pdf/10.1007/978-3-319-24174-6_21.pdf>. [MAY4] Genkin, D., Valenta, L., and Y. Yarom, "May the Fourth Be With You: A Microarchitectural Side Channel Attack connected Several Real-World Applications of Curve25519", Proceedings of the 2017 ACM SIGSAC Conference connected Computer and Communications Security, DOI 10.1145/3133956.3134029, 30 October 2017, <https://dl.acm.org/doi/pdf/10.1145/3133956.3134029>. [NEW-BLEI] Meyer, C., Somorovsky, J., Weiss, E., Schwenk, J., Schinzel, S., and E. Tews, "Revisiting SSL/TLS Implementations: New Bleichenbacher Side Channels and Attacks", Proceedings of the 23rd USENIX Security Symposium, August 2014, <https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-meyer.pdf>. [PARIS256] Devlin, S. and F. Valsorda, "The PARIS256 Attack", 8 August 2018, <https://i.blackhat.com/us-18/Wed-August-8/us-18-Valsorda-Squeezing-A-Key-Through-A-Carry-Bit-wp.pdf>. [RACCOON] Merget, R., Brinkmann, M., Aviram, N., Somorovsky, J., Mittmann, J., and J. Schwenk, "Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles successful TLS-DH(E)", 9 September 2020, <https://raccoon-attack.com/RacoonAttack.pdf>. [RFC4492] Blake-Wilson, S., Bolyard, N., Gupta, V., Hawk, C., and B. Moeller, "Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS)", RFC 4492, DOI 10.17487/RFC4492, May 2006, <https://www.rfc-editor.org/info/rfc4492>. [ROBOT] Boeck, H., Somorovsky, J., and C. Young, "Return Of Bleichenbacher's Oracle Threat (ROBOT)", Proceedings of the 27th USENIX Security Symposium, August 2018, <https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-bock.pdf>. [SUBGROUPS] Valenta, L., Adrian, D., Sanso, A., Cohney, S., Fried, J., Hastings, M., Halderman, J. A., and N. Heninger, "Measuring mini subgroup attacks against Diffie-Hellman", Cryptology ePrint Archive, Paper 2016/995, 17 October 2016, <https://eprint.iacr.org/2016/995/20161017:193515>. [TLS-REGISTRY] IANA, "Transport Layer Security (TLS) Parameters", <https://www.iana.org/assignments/tls-parameters>. [WEAK-DH] Adrian, D., Bhargavan, K., Durumeric, Z., Gaudry, P., Green, M., Halderman, J. A., Heninger, N., Springall, D., Thomé, E., Valenta, L., VanderSloot, B., Wustrow, E., Zanella-Béguelin, S., and P. Zimmermann, "Weak Diffie-Hellman and the Logjam Attack", October 2015, <https://weakdh.org/>. [XPROT] Jager, T., Schwenk, J., and J. Somorovsky, "On the Security of TLS 1.3 and QUIC Against Weaknesses successful PKCS#1 v1.5 Encryption", Proceedings of the 22nd ACM SIGSAC Conference connected Computer and Communications Security, pp. 1185-1196, DOI 10.1145/2810103.2813657, October 2015, <https://doi.org/10.1145/2810103.2813657>.
More