<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.2 (Ruby 3.2.2) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-tls-rfc8447bis-07" category="std" consensus="true" updates="3749, 5077, 4680, 5246, 5705, 5878, 6520, 7301, 8447" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.18.2 -->
  <front>
    <title abbrev="(D)TLS IANA Registry Updates">IANA Registry Updates for TLS and DTLS</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-tls-rfc8447bis-07"/>
    <author initials="J." surname="Salowey" fullname="Joe Salowey">
      <organization>Venafi</organization>
      <address>
        <email>joe@salowey.net</email>
      </address>
    </author>
    <author initials="S." surname="Turner" fullname="Sean Turner">
      <organization>sn3rd</organization>
      <address>
        <email>sean@sn3rd.com</email>
      </address>
    </author>
    <date year="2023" month="November" day="27"/>
    <area>Security</area>
    <workgroup>Transport Layer Security</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <?line 40?>

<t>This document updates the changes to TLS and DTLS IANA registries
made in RFC 8447. It adds a new value "D" for discouraged
to the recommended column of the selected TLS registries.</t>
      <t>This document updates the following RFCs:
3749, 5077, 4680, 5246, 5705, 5878, 6520, 7301, and 8447.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-tls-rfc8447bis/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Transport Layer Security Working Group mailing list (<eref target="mailto:tls@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/tls/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/tls/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/tlswg/rfc8447bis"/>.</t>
    </note>
  </front>
  <middle>
    <?line 49?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This document instructs IANA to make changes to a number of the IANA
registries related to Transport Layer Security (TLS) and Datagram
Transport Layer Security (DTLS). These changes update the changes made
in <xref target="RFC8447"/>.</t>
      <aside>
        <t>NOTE for IANA: This document specifies changes to the registry to update
  the changes made in <xref target="RFC8447"/>.</t>
      </aside>
      <t>This specification updates the "Recommended" column in TLS
registries to define a third value "D" for items that are discouraged.</t>
    </section>
    <section anchor="terminology">
      <name>Terminology</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="adding-recommended-column">
      <name>Adding "Recommended" Column</name>
      <t>The instructions in this document update the Recommended column,
originally added in <xref target="RFC8447"/> to add a third value, "D",
indicating that a value is "Discouraged". The permitted values
are:</t>
      <dl>
        <dt>Y:</dt>
        <dd>
          <t>Indicates that the IETF has consensus that the
  item is <bcp14>RECOMMENDED</bcp14>. This only means that the associated
  mechanism is fit for the purpose for which it was defined.
  Careful reading of the documentation for the mechanism is
  necessary to understand the applicability of that mechanism.
  The IETF could recommend mechanisms that have limited
  applicability, but will provide applicability statements that
  describe any limitations of the mechanism or necessary constraints
  on its use.</t>
        </dd>
        <dt>N:</dt>
        <dd>
          <t>Indicates that the item has not been evaluated by
  the IETF and that the IETF has made no statement about the
  suitability of the associated mechanism. This does not necessarily
  mean that the mechanism is flawed, only that no consensus exists.
  The IETF might have consensus to leave an items marked as "N" on
  the basis of it having limited applicability or usage constraints.</t>
        </dd>
        <dt>D:</dt>
        <dd>
          <t>Indicates that the item is discouraged. This marking could be used to identify
  mechanisms that might result in problems if they are used, such as
  a weak cryptographic algorithm or a mechanism that might cause
  interoperability problems in deployment. Implementers <bcp14>SHOULD</bcp14>
  consult the linked references associated with the item to
  determine the conditions under which it <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</t>
        </dd>
      </dl>
      <t>Setting a value to "Y" or "D" in the "Recommended" column requires IETF Standards
Action <xref target="RFC8126"/>.  Any state transition to or from a "Y" or "D" value requires
IESG Approval. Not all items defined in Standards Track RFCs need to be set
to "Y" or "D". Any item not otherwise specified is set to "N". The column is
blank for values that are unassigned or reserved unless specifically set.</t>
      <section anchor="rec-note">
        <name>Recommended Note</name>
        <t>Existing registries have a note on the meaning of the recommended column. For the
registries discussed in the subsequent sections this note is updated
with a sentence describing the "D" vaue as follows:</t>
        <dl>
          <dt>Note:</dt>
          <dd>
            <t>If "Recommended" column is set to "N", it does not necessarily mean
that it is flawed; rather, it indicates that the item either has not
been through the IETF consensus process, has limited applicability, or
is intended only for specific use cases.  If the "Recommended" column
is set to "D" the item is discouraged and <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</t>
          </dd>
        </dl>
      </section>
    </section>
    <section anchor="tls-extensiontype-values">
      <name>TLS ExtensionType Values</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure to:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Values with the first byte in the range 0-254 (decimal) are assigned
    via Specification Required [RFC8126].  Values with the first byte
    255 (decimal) are reserved for Private Use [RFC8126].  Setting a
    "Recommended" column value to "Y" or "D" requires Standards Action [RFC8126].
    Any state transition to or from a "Y" or "D" value requires
    IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Extension</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">4</td>
            <td align="left">truncated_hmac</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">53</td>
            <td align="left">connection_id (deprecated)</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">40</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">46</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-cipher-suites-registry">
      <name>TLS Cipher Suites Registry</name>
      <t>Several categories of ciphersuites are discouraged for general use and
are maked as "D".</t>
      <t>Ciphersuites that use NULL encryption do not provide the confidentiality
normally expected of TLS. Protocols and applications are often designed
to require confidentialy as a security property. These
ciphersuites <bcp14>MUST NOT</bcp14> be used in those cases.</t>
      <t>Ciphersuites marked as EXPORT use weak ciphers and were deprecated in
TLS 1.1 <xref target="RFC4346"/>.</t>
      <t>Cipher suites maked as anon do not provide any authentication and are
vulnerable to man-in-the-middle attacks and are deprecated in TLS 1.1
<xref target="RFC4346"/>.</t>
      <t>RC4 is a weak cipher and is deprecated in <xref target="RFC7465"/>.</t>
      <t>DES and IDEA are not considered secure for general use and are deprecated
in <xref target="RFC5469"/>.</t>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure to:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Values with the first byte in the range 0-254 (decimal) are
    assigned via Specification Required [RFC8126].  Values with the
    first byte 255 (decimal) are reserved for Private Use [RFC8126].
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries. This document does not
make any changes to the DTLS-OK column.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Cipher Suite Name</th>
            <th align="right">Recommeded</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0x00,0x01</td>
            <td align="left">TLS_RSA_WITH_NULL_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x02</td>
            <td align="left">TLS_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x03</td>
            <td align="left">TLS_RSA_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x04</td>
            <td align="left">TLS_RSA_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x05</td>
            <td align="left">TLS_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x06</td>
            <td align="left">TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x07</td>
            <td align="left">TLS_RSA_WITH_IDEA_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x08</td>
            <td align="left">TLS_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x09</td>
            <td align="left">TLS_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0B</td>
            <td align="left">TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0C</td>
            <td align="left">TLS_DH_DSS_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0E</td>
            <td align="left">TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0F</td>
            <td align="left">TLS_DH_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x11</td>
            <td align="left">TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x12</td>
            <td align="left">TLS_DHE_DSS_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x14</td>
            <td align="left">TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x15</td>
            <td align="left">TLS_DHE_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x17</td>
            <td align="left">TLS_DH_anon_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x18</td>
            <td align="left">TLS_DH_anon_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x19</td>
            <td align="left">TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1A</td>
            <td align="left">TLS_DH_anon_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1B</td>
            <td align="left">TLS_DH_anon_WITH_3DES_EDE_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1E</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x20</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x21</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x22</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x24</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x25</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x26</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x27</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x28</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x29</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2A</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2B</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2C</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2D</td>
            <td align="left">TLS_DHE_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2E</td>
            <td align="left">TLS_RSA_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x34</td>
            <td align="left">TLS_DH_anon_WITH_AES_128_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x3A</td>
            <td align="left">TLS_DH_anon_WITH_AES_256_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x3B</td>
            <td align="left">TLS_RSA_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x46</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x6C</td>
            <td align="left">TLS_DH_anon_WITH_AES_128_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x6D</td>
            <td align="left">TLS_DH_anon_WITH_AES_256_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x89</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x8A</td>
            <td align="left">TLS_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x8E</td>
            <td align="left">TLS_DHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x92</td>
            <td align="left">TLS_RSA_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x9B</td>
            <td align="left">TLS_DH_anon_WITH_SEED_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xA6</td>
            <td align="left">TLS_DH_anon_WITH_AES_128_GCM_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xA7</td>
            <td align="left">TLS_DH_anon_WITH_AES_256_GCM_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB0</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB1</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB4</td>
            <td align="left">TLS_DHE_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB5</td>
            <td align="left">TLS_DHE_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB8</td>
            <td align="left">TLS_RSA_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB9</td>
            <td align="left">TLS_RSA_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xBF</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xC5</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x01</td>
            <td align="left">TLS_ECDH_ECDSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x02</td>
            <td align="left">TLS_ECDH_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x06</td>
            <td align="left">TLS_ECDHE_ECDSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x07</td>
            <td align="left">TLS_ECDHE_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x0B</td>
            <td align="left">TLS_ECDH_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x0C</td>
            <td align="left">TLS_ECDH_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x10</td>
            <td align="left">TLS_ECDHE_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x11</td>
            <td align="left">TLS_ECDHE_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x15</td>
            <td align="left">TLS_ECDH_anon_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x16</td>
            <td align="left">TLS_ECDH_anon_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x17</td>
            <td align="left">TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x18</td>
            <td align="left">TLS_ECDH_anon_WITH_AES_128_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x19</td>
            <td align="left">TLS_ECDH_anon_WITH_AES_256_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x33</td>
            <td align="left">TLS_ECDHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x39</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x3A</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x3B</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x46</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_128_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x47</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_256_CBC_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x5A</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_128_GCM_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x5B</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_256_GCM_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x84</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_128_GCM_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x85</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_256_GCM_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0xB4</td>
            <td align="left">TLS_SHA256_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0xB5</td>
            <td align="left">TLS_SHA384_SHA384</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-supported-groups">
      <name>TLS Supported Groups</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS Supported Groups registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration policy to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Curve</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1</td>
            <td align="left">sect163k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">sect163r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">sect163r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">sect193r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">sect193r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">sect233k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">7</td>
            <td align="left">sect233r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">sect239k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">15</td>
            <td align="left">secp160k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">16</td>
            <td align="left">secp160r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">17</td>
            <td align="left">secp160r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">18</td>
            <td align="left">secp192k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">19</td>
            <td align="left">secp192r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">20</td>
            <td align="left">secp224k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">21</td>
            <td align="left">secp224r1</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-exporter-labels-registry">
      <name>TLS Exporter Labels Registry</name>
      <t>This document updates the registration procedure for the TLS Exporter
registry and updates the Recommended column allocation.
IANA <bcp14>SHALL</bcp14> update the TLS Exporter Labels Registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure from Specification Required to
Expert Review and update it to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries</t>
        </li>
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
        <li>
          <t>update the note on the role of the expert reviewer as follows.</t>
        </li>
      </ul>
      <dl>
        <dt>Note:</dt>
        <dd>
          <t>The role of the designated expert is described in <xref target="RFC8447"/>.
Even though this registry does not require a specification, the
designated expert <xref target="RFC8126"/> will strongly encourage registrants
to provide a link to a publicly available specification. An
Internet-Draft (that is posted and never published as an RFC)
or a document from another standards body, industry consortium,
university site, etc. are suitable for these purposes.
The expert may provide more in-depth reviews, but their approval
should not be taken as an endorsement of the exporter label.  The
expert also verifies that the label is a string consisting of
printable ASCII characters beginning with "EXPORTER".  IANA <bcp14>MUST</bcp14>
also verify that one label is not a prefix of any other label.
For example, labels "key" or "master secretary" are forbidden.</t>
        </dd>
      </dl>
    </section>
    <section anchor="tls-certificate-types">
      <name>TLS Certificate Types</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the the TLS Certificate Types registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure to:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Values in the range 0-223 (decimal) are assigned via Specification
    Required [RFC8126]. Values in the range 224-255 (decimal) are
    reserved for Private Use [RFC8126]. Setting a "Recommended" column
    value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries.</t>
        </li>
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-hashalgorithm-registry">
      <name>TLS HashAlgorithm Registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the TLS HashAlgorithm Registry
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS HashAlgorithm registry to add a "Recommended" column
as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">none</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">md5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">sha1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">sha224</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">sha256</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">sha384</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">sha512</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">Intrinsic</td>
            <td align="right">Y</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-signaturealgorithm-registry">
      <name>TLS SignatureAlgorithm registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the TLS SignatureAlgorithm registry
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS SignatureAlgorithm registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">anonymous</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dsa</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">ecdsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">7</td>
            <td align="left">ed25519</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">ed448</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">gostr34102012_256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">gostr34102012_512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-clientcertificatetypes-registry">
      <name>TLS ClientCertificateTypes registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the  TLS ClientCertificateTypes
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS ClientCertificateTypes registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dss_sign</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">rsa_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">dss_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">rsa_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">dss_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">20</td>
            <td align="left">fortezza_dms_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">ecdsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">rsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">66</td>
            <td align="left">ecdsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">67</td>
            <td align="left">gost_sign256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">68</td>
            <td align="left">gost_sign512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-pskkeyexchangemode-registry">
      <name>TLS PskKeyExchangeMode registry</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS PskKeyExchangeMode registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing recommended column "Y" and "N" entries.</t>
        </li>
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="adding-comment-column">
      <name>Adding "Comment" Column</name>
      <t>IANA is requested to add a "Comment" column to the following registries:</t>
      <ul spacing="normal">
        <li>
          <t>TLS ExtensionType Values</t>
        </li>
        <li>
          <t>TLS Application-Layer Protocol Negotiation (ALPN) Protocol IDs</t>
        </li>
        <li>
          <t>TLS CachedInformationType Values</t>
        </li>
        <li>
          <t>TLS Certificate Compression Algorithm IDs</t>
        </li>
        <li>
          <t>TLS Cipher Suites</t>
        </li>
        <li>
          <t>TLS ContentType</t>
        </li>
        <li>
          <t>TLS EC Point Formats</t>
        </li>
        <li>
          <t>TLS EC Curve Types</t>
        </li>
        <li>
          <t>TLS Supplemental Data Formats (SupplementalDataType)</t>
        </li>
        <li>
          <t>TLS UserMappingType Values</t>
        </li>
        <li>
          <t>TLS Authorization Data Formats</t>
        </li>
        <li>
          <t>TLS Heartbeat Message Types</t>
        </li>
        <li>
          <t>TLS Heartbeat Modes</t>
        </li>
        <li>
          <t>TLS SignatureScheme</t>
        </li>
        <li>
          <t>TLS PskKeyExchangeMode</t>
        </li>
        <li>
          <t>TLS KDF Identifiers</t>
        </li>
      </ul>
      <t>This list of registries is all registries that do not already have a
"Comment" or "Notes" column or that were not orphaned by TLS 1.3.</t>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The change to Specification Required from IETF Review lowers the amount
of review provided by the WG for cipher suites and supported groups.
This change reflects reality in that the WG essentially provided no
cryptographic review of the cipher suites or supported groups.  This
was especially true of national cipher suites.</t>
      <t>Recommended algorithms are regarded as secure for general use at the
time of registration; however, cryptographic algorithms and parameters
will be broken or weakened over time.  It is possible that the
"Recommended" status in the registry lags behind the most recent advances
in cryptanalysis.  Implementers and users need to check that the
cryptographic algorithms listed continue to provide the expected level
of security.</t>
      <t>Designated experts ensure the specification is publicly available.  They may
provide more in-depth reviews.  Their review should not be taken as an
endorsement of the cipher suite, extension, supported group, etc.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document is entirely about changes to TLS-related IANA registries.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-normative-references">
      <name>Normative References</name>
      <reference anchor="RFC8447">
        <front>
          <title>IANA Registry Updates for TLS and DTLS</title>
          <author fullname="J. Salowey" initials="J." surname="Salowey"/>
          <author fullname="S. Turner" initials="S." surname="Turner"/>
          <date month="August" year="2018"/>
          <abstract>
            <t>This document describes a number of changes to TLS and DTLS IANA registries that range from adding notes to the registry all the way to changing the registration policy. These changes were mostly motivated by WG review of the TLS- and DTLS-related registries undertaken as part of the TLS 1.3 development process.</t>
            <t>This document updates the following RFCs: 3749, 5077, 4680, 5246, 5705, 5878, 6520, and 7301.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="8447"/>
        <seriesInfo name="DOI" value="10.17487/RFC8447"/>
      </reference>
      <reference anchor="RFC2119">
        <front>
          <title>Key words for use in RFCs to Indicate Requirement Levels</title>
          <author fullname="S. Bradner" initials="S." surname="Bradner"/>
          <date month="March" year="1997"/>
          <abstract>
            <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="2119"/>
        <seriesInfo name="DOI" value="10.17487/RFC2119"/>
      </reference>
      <reference anchor="RFC8174">
        <front>
          <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <date month="May" year="2017"/>
          <abstract>
            <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="8174"/>
        <seriesInfo name="DOI" value="10.17487/RFC8174"/>
      </reference>
      <reference anchor="RFC8126">
        <front>
          <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
          <author fullname="M. Cotton" initials="M." surname="Cotton"/>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <author fullname="T. Narten" initials="T." surname="Narten"/>
          <date month="June" year="2017"/>
          <abstract>
            <t>Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
            <t>To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed. This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
            <t>This is the third edition of this document; it obsoletes RFC 5226.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="26"/>
        <seriesInfo name="RFC" value="8126"/>
        <seriesInfo name="DOI" value="10.17487/RFC8126"/>
      </reference>
      <reference anchor="RFC4346">
        <front>
          <title>The Transport Layer Security (TLS) Protocol Version 1.1</title>
          <author fullname="T. Dierks" initials="T." surname="Dierks"/>
          <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
          <date month="April" year="2006"/>
          <abstract>
            <t>This document specifies Version 1.1 of the Transport Layer Security (TLS) protocol. The TLS protocol provides communications security over the Internet. The protocol allows client/server applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="4346"/>
        <seriesInfo name="DOI" value="10.17487/RFC4346"/>
      </reference>
      <reference anchor="RFC7465">
        <front>
          <title>Prohibiting RC4 Cipher Suites</title>
          <author fullname="A. Popov" initials="A." surname="Popov"/>
          <date month="February" year="2015"/>
          <abstract>
            <t>This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections. This applies to all TLS versions. This document updates RFCs 5246, 4346, and 2246.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="7465"/>
        <seriesInfo name="DOI" value="10.17487/RFC7465"/>
      </reference>
      <reference anchor="RFC5469">
        <front>
          <title>DES and IDEA Cipher Suites for Transport Layer Security (TLS)</title>
          <author fullname="P. Eronen" initials="P." role="editor" surname="Eronen"/>
          <date month="February" year="2009"/>
          <abstract>
            <t>Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346) include cipher suites based on DES (Data Encryption Standard) and IDEA (International Data Encryption Algorithm) algorithms. DES (when used in single-DES mode) and IDEA are no longer recommended for general use in TLS, and have been removed from TLS version 1.2 (RFC 5246). This document specifies these cipher suites for completeness and discusses reasons why their use is no longer recommended. This memo provides information for the Internet community.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="5469"/>
        <seriesInfo name="DOI" value="10.17487/RFC5469"/>
      </reference>
      <reference anchor="RFC8996">
        <front>
          <title>Deprecating TLS 1.0 and TLS 1.1</title>
          <author fullname="K. Moriarty" initials="K." surname="Moriarty"/>
          <author fullname="S. Farrell" initials="S." surname="Farrell"/>
          <date month="March" year="2021"/>
          <abstract>
            <t>This document formally deprecates Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346). Accordingly, those documents have been moved to Historic status. These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008 (subsequently being obsoleted by TLS version 1.3 in 2018), providing sufficient time to transition away from older versions. Removing support for older versions from implementations reduces the attack surface, reduces opportunity for misconfiguration, and streamlines library and product maintenance.</t>
            <t>This document also deprecates Datagram TLS (DTLS) version 1.0 (RFC 4347) but not DTLS version 1.2, and there is no DTLS version 1.1.</t>
            <t>This document updates many RFCs that normatively refer to TLS version 1.0 or TLS version 1.1, as described herein. This document also updates the best practices for TLS usage in RFC 7525; hence, it is part of BCP 195.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="195"/>
        <seriesInfo name="RFC" value="8996"/>
        <seriesInfo name="DOI" value="10.17487/RFC8996"/>
      </reference>
    </references>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+0823LbRpbv+Ipe5sXeImmSIqnLZJNQJB1rLMleUU7WlUqp
mkCTxAgEEDQgmYmcb9lvmS+bc043gAYIUFRsP8yuXS6bbPa59rn1tdVqWbEb
e+KEnY0uR+xKLF0ZRxv2LnR4LCRbBBG7Pp8x7jtsAh8sPp9H4u6EPZs8x/ZK
KMsJbJ+vAakT8UXcckW8aMWebEUL+6jfP5y7stU5tGzouwyizQmTsWMlCvaE
HRz2j5ts0Dk8bLL+8KgDn3v9Ifx72BnAv0eHR002HPSg/fCg020yxGgBRweW
5YbRCYujRMa9Tue407N4JPgJa8yEnURuvGlY90F0u4yCJITW64j7MgyimJ3z
jYhY3utWbKCjA0rxYxH5Im5NUBDrTviJOLEYexwFY/EmBA00fgaKrr9kPyII
tq+560E76OMHVEw7iJbYzCN7Bc2rOA7lyYsX2Aub3DvRTru9wIYX8yi4l+IF
wL9AuKUbr5K5Qni/fJGruGFZMoZxu+Fe4AMnGxgYueZRfPNbEpCm/cAK3RP2
SxzYTSZBikgsJHzarPHDr5bFk3gVRCBwCwgx5voA9Pc2mwHGe7GhNjXOfw9E
oRWY5b77O4/dwD9hPwmfL1z6QSjp/xGIH6Tq3wb1FgjM2uw6AaVHBv6Z4L7Z
WsQv/YPIMdFL6P4DtbbtYG1ZfhCtoe8djJ3l+gvjW6vVYnwOxsvt2LKuV65k
YLzJWvgx0xbJ4pVg9or7S/wcFNxB2X+k7N8FBa+5I0AMdvVyTIbZZmcx444j
GWe+uGd33EsEa0wa5FmOK+0gifhSOBZgRkKRAI6BvCMcZgdesvZZsKBfpPCE
HUMz0s1JtnexvQg8UDKaHzAkT6yn+hbKSWIoTa1dx/GEZX2DjhEFTmLjAJQZ
gFEEH7RjqbQDgq35bUGFoItkPQd/0aJhPysXCaTzOEqK2q7xMPYM1PBcDQSP
+TLia6u+L47Vc7CrlZA5I0pRheHF4QMLYX/88T0oDCX/+BFk/5ZLF8YVnOfW
Ce79/2rMvcC+bXwHNnf55npKY4kynLCiJmQobHeBEhnCq1HWERO+KzYwYJQY
YVuMfPuCGPlOa1yjt8kNCuPeuMrNqJHaEaDDCG7oGag7YuH6AkYkXrmRU7JP
NxZrRMjBhiNhmmsbjeBaRGvXD7xguUGOBIO4yTBwSta4eDe7bjTV/6gk/Hw1
/e93Z1fTCX6evRqdn2cfLN1j9urNu/NJ/imHHL+5uJheThQwtLJCk9W4GL1v
KHttvHl7ffbmcnTeQInjwoCgFCD0HHULkT2MBJoZh4wlpB25c/gCMKfjt//8
324flP8foPxet3v88aP+ctQ97MOX+5XwFbXA9zb6Kyh+Y/EwFDxCLNzzmM1D
N+YeBFUOw7UC22ErEQnQ3n/+gpr59YR9O7fDbv873YACFxpTnRUaSWfbLVvA
SokVTRVkMm0W2kuaLvI7el/4nurdaPz2ew+tq9U9+h6MFkxm5DgYjYr2OSb7
VCaUBg+waLk9fobLXm0FyqYVRO7S9UHxG4y5ajBND6LY4zhFa2+iuTfB6x3y
JOBOGbz2BSDfmOSG36AowkI0/RiNh3pJrDQgnbw/sbBoIExCew4FuOn1S7YC
G7BBLOHLJP9NJT5wNKRkqLqtYgnZ1xrymYGNSxnYLkZIAl4LjBquJAwLNybX
xX5hEoWBFPT9fuXaK6DD7oEL5fTgxAg+BtYXiQcxidPY6Jic6lwFlxSlSUvl
Z2ELKbkOZTAaERUdis8w9EATc9fDIEx4QYIMhSJ/naoHNOw5ef7L+2nJV/xO
MM8FtWu5C+ibbJ6AcC44XRgFdxiui+SBLVAyCKTQEYbU68GTNwo1V4andZBL
C+LnkuIgQsUAIUTpAPTjAtpEomNf1pgADTGagB/EEICEzwSaDuW5uaqaMktR
CizbDuUEP8glgcolSHIjkgnwbyrbtBRD7WmSEoqXVC7X22hz4n5OvWhcHr8X
TlMZJXUBdnKTFh8gscjSsK7d5UoPnmH8AfMENnFfJxnMrRSKIbo3gECmkDmk
PBoQl7CghWojKNtXBCMALmoOD4zHZNd4oB6MpKY0g6wgGWWQYB0wsFSLgFH5
sbvYFL1O41RyRkImHpZAaIVzDyVzaSg2lHsQExTYCbgiV7bD2b3gt8yONmEc
QBUTgp9C6oB5EdT1ZHfcGAODks0Bma6aIZUFEJFSTeSkfTDx0As2aC1Qiq5D
jwwHnJSpREAIUGHINaoF4jWOA4QEyFM+WIZpQ/fAU668ONBOFFMdoCupAFSt
nIiiQR548syDUqXJLtUvjNRMxBR+08gLGm+8b2BnrEcoF9RUNpH4LXFB9cri
ZhiAOFQh1ojySJa6e0Moohgb+ToawFQR4ipxi8SA0CIK1kDfIKtYSQlYZ9PZ
j2wUYojhXptdgv9gnlc2rMMqsprxgAWsfUvlN3iasqM5FvOxVZCvTWyRXtEp
A5A1uncheKc1pIPGCmCklkudhtLKTlpzj/u3FKZVQsqrtsSHEXSXyBj8CkKI
6A4+J74Hbp/XkJg0AT0Wdt8UkivIKNgf30BgbgFn4qNlTdHPcaSMUpIcnCPv
AuOhCh1gtHlC2Z7ZtNlLlVbMmhT9MZFSqZHmPclcgvqpnha6MKCqgGi5aR3v
WGSdHDqBgYPlptFdZXShRzPBoKjnRTAhslA6+A9CxKKmaja13kRDroqcJKxF
OoceWaj8G4s4jiTBuTVBSLjYJc0NFuWGeBUFyXKVJ4A8doLtIdkmAVSGQgjQ
keVKCgykborXaBvpaKPLQQSRMH1kKHmdZ1mG9KC+mrhJ+epR9/6GJq7TD8CT
hEG83oSC/aSKJ+sMZrkRRgsghKHHjguzIW0J2yUfOl+g5j9Ni2abqhA26sQ6
ovkcrGAPLTYmouY0TZVApHcnoRkEdPzzzz8p/GlsWWhcuFABQUaPRcp2RPg6
rd6gz545MABr7j0n10wdkxDduZzNCjO6KxV1HPaLDl+/tnfRIyy9waBEJPN4
NIC3kXuHmnkH429izWIvIal0hKqgnAXePN7pmJsjJ4yfEnMRvhh3SfkwVCOq
5bNcpWbXhfkCpSA1lGmnlapzcUlDL1jWJ5ZMy6klkstJqtkEWAxobuqrlR8G
s18RYmc3UpUQTXRAKpqUQlEjVE/40RZhXqWnza5vLNdAIecJVN1ol3jK2LF+
pdmOWlyQGUoQ8YHMhT3kLsAe+fNQcLMH6+GkhX/0f4/8eTC/nABwHxDCfM7H
uOfcrNbcrqKY/pkgvcEBe4Bo56tYf+M6aM8wUycUzytB+h32cJWaea1cRZDh
U0FyczGTXMV6nTIa8SFW088sceJKUhoGx26IMX8GJTsMfbqAjjXQHdRxuHBA
a+NoF5A+beotVefSSgzZ0VL4BIZhHcwNZ6O06KYKaqguLGts4qAEhJ0v34EB
gXFh+YnG4QSU2dIplK7oFqry5Zhc1GIqVgviQ6gWJIFDkKkNwSWIA1CCJJPX
KUklbGQoWIAJYlZWMY9CPbl4gQTFY8zieu0upNI23ujVO6ugi3KaUSE3yJJb
Sex8kjH9n7dvrq5JBar+Vt2I8XuBGs5MDnBaOGTddldXkv2D/pBGU49ihl0j
5/62JnGGicvpKKQO76SkSFh3iYejBw6v1kr9luu3oGdLLbcyHsdQQsq0f5E1
plmzSqxdjfuYpbkpHmHA+FFAoAAP+8MBAU6mann7bDIdETmUAqsPkAJzEQ2M
qLK6EnNWhnvQHx4T7v+faV7N89Ia/K+lecJh0PxLaZ6Q5LOsT8jyKqeXM/2T
sryqeQqZ/muW/0tZvrTpkE5PaKvxVkWe0vYDboe03rxOp2FQJrC0TjATE7vk
a1FfKTCjWCjUCnsWC5VVAxYNrPOh02nCP11NBNi9uZqNbn4+u351gynr5mIy
2ErVE8ZM4F4tMCj0EdiDEqxKFwoFRNabfkdz8KCqiQywX0UUIbq9ozLTFXQH
u8AfZ3u4k+3ezfh0nLNuIJqYSA6reMBsQOCPM3G0gwlILkB/PzzHVXwAgj3B
TzXoBIBms7/MxdjgQqN6IiPTIoZPUcnLIpoqRh7KQN1ugf70U7TR7VXgepo6
uv0Sik/QR3dQgWsHOxUYDgsYbrByq3f2ejRHFWie5vrd40c4eYpeRnXs7K2X
0zoMB4hiOpnuh8a0/ddXp4MnGkuvUwm/d0DsdSvh9w9mvV4lglSAR0e116+E
39sqeoNK+EyAIoIK+GEZvmRSaUogTZSSWe9wF7CRTxC4DHu0G7afEdX9itDH
e7Kt5S+Dj/ZkvAb8dA/eEbQMN9Ywb2evS9VGuefECFqP954aWfDR3gf9Krcd
gc7Q4lKrLwON6oB6g2Et0CkrZeeUJwAqd8b1lm0K49HF9Pz8bLSLt+F4D4Eq
KA4ne8hUAXd0vJPTHQo5Mu0uGygzWpUBirXBdC+g43JhuxfQaZVQs+l0UifM
qHLAUrX/OL6oUd/ocJfaNdzBUb8Md9qpUt4Oizrt7gKootCv0vQuCoNdAFUU
jnZ5KlKoinanx7ugqsi83NeXKoQaD/Y17yLwWM/IFPB0DODwz9a8qgxgGmsZ
qNpex3oqk8NM96J0WKI03ZfUqcne9kyx3H1clqhyolaC6nYKnD1KpVC1l2B2
kRmYjOXDW0tmWBZmu3StAjusBtkqDstwR9Vw5ey0VRWMdYlcC10dlQns4GBL
lY9ETAV2XA9mrCKUoUa7ISp86uB0N0gxAIzrk+noatv5q/TYr47QV0XvR7JV
0IPqUiGlbSSGSujKPJTRrkwPBHhUWdYUYl5lTlLAj8e8espZ2lC4a0hkuUIh
KeL6THtHautoloR4xhlg6ErBl989LxOsXVI31lmLS+qB59p0QND1bS9xhLGu
/nU5+v/acnRhNTmJ7vD/rS1l/KvWeqGiwGM93eHBbTdzqh580q1R3npgtPay
1n7aemz2HRited+hbu0dmNQO81YDw1HWemz07WrEYXfYMZuHebOBo3toNOds
dI/S5uOeieQ4bzaQ9Dq6udfrmzrq5s1Z788SaNKTOuT1ETvnYHbmJnX9fZOa
nbTU6ky0Vh5FwFRNJDsDVXvn/l81x0/f+qPwULNLR8cegZSIYmi8c8W9IQGe
8/oa51Sc00GqMkRVjHFF1Po85twy7aSAJ/BEejpRqAGNaEBxqzwzmXZ6SPCE
jlyaQOosA22ka3jaXTeukuijp/r+zvSOjvbpk32ukUmzM4XpkQhevN1Dt0us
bXrm0VZ1+h3QBf4Sj2f4+ohIZuR4Xh1GMTuSQId91X2sMJlDjsbDF3d48RDP
IhToo5FZxduQ7Jk67ighv1NywsHz8fyKwiZX6WkIPP363KKjzJnxKMP06Zwr
k9npsXngbJp4UjIhteC5A3BpN1k3rcR3Abeks/xuLJpMxHabtr7VwXcvizMy
u/oAg3edD+6abzLh10GEO/ctB7LiSg+7VJcIlKly7Q+WXNE5cHVsH3LkLYyh
EgssMIikOoqfm5EKQR6GoDadg7c0ee7JgIEI6kZYdgaUeqqzGngElg6egxMr
PwkWVghtSrzRbHx2hlUB3lbE0ypzGFifztiS/TfUOuX0qoGnOjFM4vkYK6er
D+0HvkEV5YLxBxd2P6AUuF2sRkWJYOEZXfGB49nxpmqTrHErNiqirLlEcSEP
RSLmEbRyFfDnLpQHfl62jkEFypwgWG/CL3zqM00JW1Q/83mQ8tmP3kHNEc/t
cx+EpursRxVqyPGtrTMfhGGf4527k4+REr4moGICan/WmdsrLlej7GqHWU9R
RlAnuTrEQ3rgrHwWTcf742OI903dq0eB36JLjXQWi056B2vQmLsWbfZkN7O2
3YzVV101Uj15kmj42df6qaSpbT2bN4jVlcYa1y6oP5+ZTaBKkZGrTn1Wn/ll
rHSOZ+t0L8OZiY/p5IG9Z3o2x9bOIF/3oZncipcmcSsOAa04g4MmWlV5n0/f
VlwtobzP524rPuj2siacRuFNdBcGzdatWvOfYZ2FSi0wyG2l/7u77C7Rvvrt
Z/bbHcqucV6LZYVOwXmf4LvlI3jVrotroZt1kMgHdpm5byR55mDoag59v8yc
V9iO0QMXOIQDpQktXuRuKZx+/yj3XXTjJUwTooN+t9PrdHs3ytsV2uFg62fl
5pefxaF1Aeq5MHpGQVisB/+dfXqHfF/9+XP78yN2VOfTlR79lHS8h09r973B
KUfJh2XamDsy9oRJn3BunFX2Q1/33vphoCFEuIIZb8Q9+PHmajqbXv00nRQW
WBF8dy9a0VzgRPn33/mNs5YViPppqClKMxwUOIceOYvDYQZT9euhDjKEsBB+
jsxfPn/keStvX4vN9INy9YvAEUbU+cKbNztof40IX2JiWWEhX25imT+oMiaw
OH9MhUyClhh/S4TUrynpwJR11iT0tYB8Jyi/j02WUXtxV/00ym96tdTLS+lN
MHYplkHsKjt6Njp/e/k8/+1skiIYc3slnLP0Za4qGuZCDrAPmVjSbca8qDLQ
mZfr0rYAL0PHiDgVaMzeBi6M9kuiKvNmtWul0mcr2wJVTydwj96bSoHYM/Mn
/AXBnmuwd1JEFzwMQaUVWqPH1fQjZgWkusMrwaN4LnjMLvCa+bLIkvErOHXG
aFpszmwMwLp1OwjoH15PXrIz9aqFKyKpt3ZwsxGXAo1b+bg86XlmC60k6ktu
3MPHYzb6EQArty/0TFw8l5mp0QotQFJFRS8dRCFwRY+g6ELqgAw7e7xrrO+e
qZuE6pUgWy/WBXWbNBQd6OK83qLBt+Yitb/EoeL1Y4sEpN/0mjCxgB1+/pFq
N7twuw8dWGY74fQAIK0uu+njXhgr8IU2dDm6Kalit17lBZwwiOqKo7fJSfqB
VXz7Q/Ok15OLPGBBWWaB0fUfC5/1EbRkT/jjKKFdCp/0ghdKTUR4P9AINNlz
I1LfJFtCSFaL93W3/dSrM1jYGoZCtP7GVqDqO3zzoOZRE6XLkEd8jU+HAO+4
bwF18zwKcHEdXysSuMyOV0txO0HVz/iSntpskC7dlUwfUCqmHUwXSb56muY6
jy9xvXzl6reJ1pDuMdrSMzrOHcenTvDGIvHMQWMb6dLjCOabKbTPJ/FT+pQH
eJl9m7NSK7Hev7chCrm+yofmHdvsKq0HmvPQNNP7r3gjs7zrAyPtS8rHq9I2
DSloaytHbUNscP/D2rn/oTq6UWqEtVsfVsXWh2lhTeBUp4tm2WTVxg0ts1CO
2vbvwmOCKGwMPo0C0XNHxacYW+lbgaWXGJEArmHNuX1r/QuKbkEU51QAAA==

-->

</rfc>
