RFC 10015: Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2
- Security
- Infrastructure
- Standards
RFC 10015 does not deprecate TLS 1.2 itself. It narrows what counts as acceptable within TLS 1.2 and DTLS 1.2 by deprecating obsolete key exchange methods, so older deployments can keep using the protocol without carrying obviously weak options forever. That landed as a pragmatic cleanup, not a push to force everyone onto TLS 1.3 overnight.
If you still operate TLS 1.2 endpoints, audit cipher suite and key exchange settings now instead of assuming “TLS 1.2 enabled” is enough. Expect vendors and service operators to tighten defaults around this RFC, which can strand long-lived devices even if the protocol version itself remains supported.
-
rfc-editor.org
- Discuss on HN