TLS Fallback Signaling Cipher Suite Value for Preventing Protocol Downgrade Attacks
RFC 7507, “TLS Fallback Signaling Cipher Suite Value for Preventing Protocol Downgrade Attacks”, is a Proposed Standard document published in April 2015 by B. Moeller, A. Langley. It updates RFC 2246, RFC 4346, RFC 4347, RFC 5246, RFC 6347. It has been obsoleted by RFC 8996 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
This document defines a Signaling Cipher Suite Value (SCSV) that prevents protocol downgrade attacks on the Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) protocols. It updates RFCs 2246, 4346, 4347, 5246, and 6347. Server update considerations are included.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7507 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7506 IPv6 Router Alert Option for MPLS Operations, Administration, and Maintenance
- RFC 7508 Securing Header Fields with S/MIME
- RFC 7505 A "Null MX" No Service Resource Record for Domains That Accept No Mail
- RFC 7509 RTP Control Protocol Extended Report for Post-Repair Loss Count Metrics
- RFC 7504 SMTP 521 and 556 Reply Codes
- RFC 7510 Encapsulating MPLS in UDP
- RFC 7503 OSPFv3 Autoconfiguration
- RFC 7511 Scenic Routing for IPv6