RFC 10015 Deprecates Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2

RFC 10015: Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2

This document deprecates Diffie-Hellman and RSA key exchanges in TLS 1.2 and DTLS 1.2 due to critical security flaws like the Raccoon attack and lack of forward secrecy. It also discourages static Elliptic Curve Diffie-Hellman suites. These updates address interoperability issues and timing side channels that threaten connection security, urging the industry to adopt safer cryptographic standards.

Experience shows that in practice, implementations may fail to thwart such attacks due to the complexity and number of the required mitigations.
  1. Sha1rholder

    I don't see much necessity. TLS1.3 is not something that hard or costly to support. I'd suggest just mark TLS1.2 as legacy and make some practical constraints to TLS1.3 applications/implementations to avoid replay attacks.

  2. nektro

    better url https://datatracker.ietf.org/doc/html/rfc10015

  3. sidewndr46

    Couldn't folks just use TLS 1.3?

More from this day

2026-08-02