Deprecating Secure Sockets Layer Version 3.0
RFC 7568, “Deprecating Secure Sockets Layer Version 3.0”, is a Proposed Standard document published in June 2015 by R. Barnes, M. Thomson, A. Pironti, A. Langley. It updates RFC 5246. It has since been updated by RFC 8996. The canonical text is published by the RFC Editor.
Abstract
The Secure Sockets Layer version 3.0 (SSLv3), as specified in RFC 6101, is not sufficiently secure. This document requires that SSLv3 not be used. The replacement versions, in particular, Transport Layer Security (TLS) 1.2 (RFC 5246), are considerably more secure and capable protocols.
This document updates the backward compatibility section of RFC 5246 and its predecessors to prohibit fallback to SSLv3.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7568 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7567 IETF Recommendations Regarding Active Queue Management
- RFC 7569 Registry Specification for Mandatory Access Control Security Label Formats
- RFC 7566 Enumservice Registration for 'acct' URI
- RFC 7570 Label Switched Path Attribute in the Explicit Route Object
- RFC 7565 The 'acct' URI Scheme
- RFC 7571 GMPLS RSVP-TE Extensions for Lock Instruct and Loopback
- RFC 7564 PRECIS Framework: Preparation, Enforcement, and Comparison of Internationalized Strings in Application Protocols
- RFC 7572 Interworking between the Session Initiation Protocol and the Extensible Messaging and Presence Protocol : Instant Messaging