Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security
RFC 7919, “Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security”, is a Proposed Standard document published in August 2016 by D. Gillmor. It updates RFC 2246, RFC 4346, RFC 4492, RFC 5246. The canonical text is published by the RFC Editor.
Abstract
Traditional finite-field-based Diffie-Hellman (DH) key exchange during the Transport Layer Security (TLS) handshake suffers from a number of security, interoperability, and efficiency shortcomings. These shortcomings arise from lack of clarity about which DH group parameters TLS servers should offer and clients should accept. This document offers a solution to these shortcomings for compatible peers by using a section of the TLS "Supported Groups Registry" (renamed from "EC Named Curve Registry" by this document) to establish common finite field DH parameters with known structure and a mechanism for peers to negotiate support for these groups.
This document updates TLS versions 1.0 (RFC 2246), 1.1 (RFC 4346), and 1.2 (RFC 5246), as well as the TLS Elliptic Curve Cryptography (ECC) extensions (RFC 4492).
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7919 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7918 Transport Layer Security False Start
- RFC 7920 Problem Statement for the Interface to the Routing System
- RFC 7917 Advertising Node Administrative Tags in IS-IS
- RFC 7921 An Architecture for the Interface to the Routing System
- RFC 7916 Operational Management of Loop-Free Alternates
- RFC 7922 Interface to the Routing System Traceability: Framework and Information Model
- RFC 7915 IP/ICMP Translation Algorithm
- RFC 7923 Requirements for Subscription to YANG Datastores