Deprecating TLS 1.0 and TLS 1.1
RFC 8996, “Deprecating TLS 1.0 and TLS 1.1”, is a Best Current Practice document published in March 2021 by K. Moriarty, S. Farrell. It updates RFC 3261, RFC 3329, RFC 3436, RFC 3470, RFC 3501, RFC 3552, RFC 3568, RFC 3656, RFC 3749, RFC 3767, RFC 3856, RFC 3871, RFC 3887, RFC 3903, RFC 3943, RFC 3983, RFC 4097, RFC 4111, RFC 4162, RFC 4168, RFC 4217, RFC 4235, RFC 4261, RFC 4279, RFC 4497, RFC 4513, RFC 4531, RFC 4540, RFC 4582, RFC 4616, RFC 4642, RFC 4680, RFC 4681. It obsoletes RFC 5469, RFC 7507. The canonical text is published by the RFC Editor.
Abstract
This document formally deprecates Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346). Accordingly, those documents have been moved to Historic status. These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008 (subsequently being obsoleted by TLS version 1.3 in 2018), providing sufficient time to transition away from older versions. Removing support for older versions from implementations reduces the attack surface, reduces opportunity for misconfiguration, and streamlines library and product maintenance.
This document also deprecates Datagram TLS (DTLS) version 1.0 (RFC 4347) but not DTLS version 1.2, and there is no DTLS version 1.1.
This document updates many RFCs that normatively refer to TLS version 1.0 or TLS version 1.1, as described herein. This document also updates the best practices for TLS usage in RFC 7525; hence, it is part of BCP 195.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 8996 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8995 Bootstrapping Remote Secure Key Infrastructure
- RFC 8997 Deprecation of TLS 1.1 for Email Submission and Access
- RFC 8994 An Autonomic Control Plane
- RFC 8998 ShangMi Cipher Suites for TLS 1.3
- RFC 8993 A Reference Model for Autonomic Networking
- RFC 8999 Version-Independent Properties of QUIC
- RFC 8992 Autonomic IPv6 Edge Prefix Management in Large-Scale Networks
- RFC 9000 QUIC: A UDP-Based Multiplexed and Secure Transport