HeadlinesBriefing favicon HeadlinesBriefing.com

RFC 9851: TLS 1.2 Feature Freeze

Hacker News •
×

RFC 9851 declares TLS 1.3 as the growing standard and freezes TLS 1.2 for changes, allowing only urgent security fixes. The memo clarifies that no extensions will be approved for TLS 1.2 outside these exceptions, and explicitly states the rule does not apply to DTLS.

The document discusses post‑quantum cryptography (PQC) and the threat quantum computers pose to RSA, finite‑field Diffie‑Hellman, and elliptic‑curve algorithms. It notes that NIST has released PQC standards such as ML‑KEM and ML‑DSA, but the IETF’s TLS working group is focused solely on TLS 1.3 or later, meaning PQC for TLS 1.2 will never be specified.

IANA registryIENs are updated to restrict new entries to TLS 1.3+, with a note that any entry added after RFC 9851’s publication should indicate “For TLS 1.3 or later.” This ensures clarity for developers and vendors.

In sum, the freeze pushes the industry toward TLS 1.3, providing robust security proofs and aligning with emerging quantum‑safe standards, while leaving DTLS unaffected.