AES Galois Counter Mode Cipher Suites for TLS
RFC 5288, “AES Galois Counter Mode Cipher Suites for TLS”, is a Proposed Standard document published in August 2008 by J. Salowey, A. Choudhury, D. McGrew. It has since been updated by RFC 9325. The canonical text is published by the RFC Editor.
Abstract
This memo describes the use of the Advanced Encryption Standard (AES) in Galois/Counter Mode (GCM) as a Transport Layer Security (TLS) authenticated encryption operation. GCM provides both confidentiality and data origin authentication, can be efficiently implemented in hardware for speeds of 10 gigabits per second and above, and is also well-suited to software implementations. This memo defines TLS cipher suites that use AES-GCM with RSA, DSA, and Diffie-Hellman-based key exchange mechanisms. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5288 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5287 Control Protocol Extensions for the Setup of Time-Division Multiplexing Pseudowires in MPLS Networks
- RFC 5289 TLS Elliptic Curve Cipher Suites with SHA-256/384 and AES Galois Counter Mode
- RFC 5286 Basic Specification for IP Fast Reroute: Loop-Free Alternates
- RFC 5290 Comments on the Usefulness of Simple Best-Effort Traffic
- RFC 5285 A General Mechanism for RTP Header Extensions
- RFC 5291 Outbound Route Filtering Capability for BGP-4
- RFC 5284 User-Defined Errors for RSVP
- RFC 5292 Address-Prefix-Based Outbound Route Filter for BGP-4