← All stories
● Covered by 1 source · 2 reportsMedium impact2 neutral

IETF Freezes TLS 1.2 Features and Deprecates Obsolete Key Exchange Methods

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • TLS 1.2 is now in a feature freeze per RFC 9851.
  • Only urgent security fixes and specific identifiers are allowed for TLS 1.2.
  • RFC 10015 deprecates DH and RSA key exchanges in TLS 1.2 and DTLS 1.2.
  • Static ECDH cipher suites are discouraged in TLS 1.2 and DTLS 1.2.
  • These changes do not apply to DTLS versions or TLS 1.3.

TLS 1.2 Enters Feature Freeze

The Internet Engineering Task Force (IETF) has published RFC 9851, which formally places TLS 1.2 into a feature freeze. This means that no new changes will be approved for TLS 1.2, with exceptions made only for urgent security fixes, new TLS Exporter Labels, and new Application-Layer Protocol Negotiation (ALPN) Protocol IDs. This freeze applies specifically to TLS 1.2 and does not affect any version of DTLS.

Deprecation of Obsolete Key Exchange Methods

In a related development, RFC 10015 has been released, deprecating the use of Diffie-Hellman (DH) over a finite field and RSA key exchanges within TLS 1.2 and DTLS 1.2. Additionally, the document discourages the use of static Elliptic Curve Diffie-Hellman (ECDH) cipher suites for these protocol versions. These prescriptions are limited to (D)TLS 1.2, as earlier versions (TLS 1.0 and TLS 1.1) are already deprecated by RFC 8996, and TLS 1.3 either does not use these algorithms or has different configuration options.

Impact on Existing RFCs

RFC 10015 updates several existing RFCs, including 4162, 4279, 4346, 4785, 5246, 5288, 5289, 5469, 5487, 5932, 6209, 6347, 6367, 6655, 7905, 8422, and 9325. These updates either deprecate or discourage the use of cipher suites that utilize the affected key exchange methods in (D)TLS 1.2 connections.

Rationale for the Changes

These actions by the IETF are intended to address known deficiencies in TLS 1.2 and to accelerate the transition to TLS 1.3. The newer TLS 1.3 protocol offers stronger security and resolves issues present in its predecessors. Both RFCs are Internet Standards Track documents, representing the consensus of the IETF community and approved for publication by the Internet Engineering Steering Group (IESG).

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Internet Engineering Task Force (IETF) has published RFC 9851, placing TLS 1.2 into a feature freeze, meaning no new changes will be approved outside of urgent security fixes and specific protocol identifiers. This decision aims to accelerate the transition to TLS 1.3, which addresses known deficiencies and offers stronger security. The freeze impacts the development of TLS but does not apply to DTLS.

The Internet Engineering Task Force (IETF) has published RFC 10015, which deprecates the use of Diffie-Hellman (DH) over a finite field and RSA key exchanges in TLS 1.2 and DTLS 1.2. This update also discourages static Elliptic Curve Diffie-Hellman (ECDH) cipher suites to enhance security for these older protocol versions.