Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2
RFC 9155, “Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2”, is a Proposed Standard document published in December 2021 by L. Velvindron, K. Moriarty, A. Ghedini. It updates RFC 5246. The canonical text is published by the RFC Editor.
Abstract
The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digital signatures. However, this document does not deprecate SHA-1 with Hashed Message Authentication Code (HMAC), as used in record protection. This document updates RFC 5246.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9155 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9154 Extensible Provisioning Protocol Secure Authorization Information for Transfer
- RFC 9156 DNS Query Name Minimisation to Improve Privacy
- RFC 9157 Revised IANA Considerations for DNSSEC
- RFC 9158 Update to the Object Identifier Registry for the PKIX Working Group
- RFC 9159 IPv6 Mesh over BLUETOOTH Low Energy Using the Internet Protocol Support Profile
- RFC 9160 Export of MPLS Segment Routing Label Type Information in IP Flow Information Export
- RFC 9162 Certificate Transparency Version 2.0
- RFC 9164 Concise Binary Object Representation Tags for IPv4 and IPv6 Addresses and Prefixes