Recommendations for Secure Use of Transport Layer Security and Datagram Transport Layer Security
RFC 7525, “Recommendations for Secure Use of Transport Layer Security and Datagram Transport Layer Security”, is a Best Current Practice document published in May 2015 by Y. Sheffer, R. Holz, P. Saint-Andre. It has since been updated by RFC 8996. It has been obsoleted by RFC 9325 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) are widely used to protect data exchanged over application protocols such as HTTP, SMTP, IMAP, POP, SIP, and XMPP. Over the last few years, several serious attacks on TLS have emerged, including attacks on its most commonly used cipher suites and their modes of operation. This document provides recommendations for improving the security of deployed services that use TLS and DTLS. The recommendations are applicable to the majority of use cases.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 7525 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7524 Inter-Area Point-to-Multipoint Segmented Label Switched Paths
- RFC 7526 Deprecating the Anycast Prefix for 6to4 Relay Routers
- RFC 7523 JSON Web Token Profile for OAuth 2.0 Client Authentication and Authorization Grants
- RFC 7527 Enhanced Duplicate Address Detection
- RFC 7522 Security Assertion Markup Language 2.0 Profile for OAuth 2.0 Client Authentication and Authorization Grants
- RFC 7528 A Uniform Resource Name Namespace for the Hybrid Broadcast Broadband TV Association
- RFC 7521 Assertion Framework for OAuth 2.0 Client Authentication and Authorization Grants
- RFC 7529 Non-Gregorian Recurrence Rules in the Internet Calendaring and Scheduling Core Object Specification