Prohibiting RC4 Cipher Suites
RFC 7465, “Prohibiting RC4 Cipher Suites”, is a Proposed Standard document published in February 2015 by A. Popov. It updates RFC 2246, RFC 4346, RFC 5246. It has since been updated by RFC 8996. The canonical text is published by the RFC Editor.
Abstract
This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections. This applies to all TLS versions. This document updates RFCs 5246, 4346, and 2246.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7465 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7464 JavaScript Object Notation Text Sequences
- RFC 7466 An Optimization for the Mobile Ad Hoc Network Neighborhood Discovery Protocol
- RFC 7463 Shared Appearances of a Session Initiation Protocol Address of Record
- RFC 7467 URN Namespace for the North Atlantic Treaty Organization
- RFC 7462 URNs for the Alert-Info Header Field of the Session Initiation Protocol
- RFC 7468 Textual Encodings of PKIX, PKCS, and CMS Structures
- RFC 7461 Energy Object Context MIB
- RFC 7469 Public Key Pinning Extension for HTTP