<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.20 (Ruby 3.3.3) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-tls-rfc8447bis-10" category="std" consensus="true" updates="3749, 5077, 4680, 5246, 5705, 5878, 6520, 7301, 8447" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.24.0 -->
  <front>
    <title abbrev="(D)TLS IANA Registry Updates">IANA Registry Updates for TLS and DTLS</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-tls-rfc8447bis-10"/>
    <author initials="J." surname="Salowey" fullname="Joe Salowey">
      <organization>Venafi</organization>
      <address>
        <email>joe@salowey.net</email>
      </address>
    </author>
    <author initials="S." surname="Turner" fullname="Sean Turner">
      <organization>sn3rd</organization>
      <address>
        <email>sean@sn3rd.com</email>
      </address>
    </author>
    <date year="2024" month="November" day="03"/>
    <area>Security</area>
    <workgroup>Transport Layer Security</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <?line 40?>

<t>This document updates the changes to TLS and DTLS IANA registries
made in RFC 8447. It adds a new value "D" for discouraged
to the recommended column of the selected TLS registries and
adds a "Comments" column to all active registries.</t>
      <t>This document updates the following RFCs:
3749, 5077, 4680, 5246, 5705, 5878, 6520, 7301, and 8447.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-tls-rfc8447bis/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Transport Layer Security Working Group mailing list (<eref target="mailto:tls@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/tls/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/tls/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/tlswg/rfc8447bis"/>.</t>
    </note>
  </front>
  <middle>
    <?line 50?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This document instructs IANA to make changes to a number of the IANA
registries related to Transport Layer Security (TLS) and Datagram
Transport Layer Security (DTLS). These changes update the changes made
in <xref target="RFC8447"/>.</t>
      <aside>
        <t>NOTE for IANA: This document specifies changes to the registry to update
  the changes made in <xref target="RFC8447"/>.</t>
      </aside>
      <t>This specification updates the "Recommended" column in TLS
registries to define a third value "D" for items that are discouraged.</t>
    </section>
    <section anchor="terminology">
      <name>Terminology</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="adding-recommended-column">
      <name>Adding "Recommended" Column</name>
      <t>The instructions in this document update the Recommended column,
originally added in <xref target="RFC8447"/> to add a third value, "D",
indicating that a value is "Discouraged". The permitted values
are:</t>
      <dl>
        <dt>Y:</dt>
        <dd>
          <t>Indicates that the IETF has consensus that the
  item is <bcp14>RECOMMENDED</bcp14>. This only means that the associated
  mechanism is fit for the purpose for which it was defined.
  Careful reading of the documentation for the mechanism is
  necessary to understand the applicability of that mechanism.
  The IETF could recommend mechanisms that have limited
  applicability, but will provide applicability statements that
  describe any limitations of the mechanism or necessary constraints
  on its use.</t>
        </dd>
        <dt>N:</dt>
        <dd>
          <t>Indicates that the item has not been evaluated by
  the IETF and that the IETF has made no statement about the
  suitability of the associated mechanism. This does not necessarily
  mean that the mechanism is flawed, only that no consensus exists.
  The IETF might have consensus to leave an items marked as "N" on
  the basis of it having limited applicability or usage constraints.</t>
        </dd>
        <dt>D:</dt>
        <dd>
          <t>Indicates that the item is discouraged. This marking could be used to identify
  mechanisms that might result in problems if they are used, such as
  a weak cryptographic algorithm or a mechanism that might cause
  interoperability problems in deployment. Implementers <bcp14>SHOULD</bcp14>
  consult the linked references associated with the item to
  determine the conditions under which it <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</t>
        </dd>
      </dl>
      <t>Setting a value to "Y" or "D" in the "Recommended" column requires IETF Standards
Action <xref target="RFC8126"/>.  Any state transition to or from a "Y" or "D" value requires
IESG Approval. Not all items defined in Standards Track RFCs need to be set
to "Y" or "D". Any item not otherwise specified is set to "N". The column is
blank for values that are unassigned or reserved unless specifically set.</t>
      <section anchor="rec-note">
        <name>Recommended Note</name>
        <t>Existing registries have a note on the meaning of the recommended column. For the
registries discussed in the subsequent sections this note is updated
with a sentence describing the "D" vaue as follows:</t>
        <dl>
          <dt>Note:</dt>
          <dd>
            <t>If "Recommended" column is set to "N", it does not necessarily mean
that it is flawed; rather, it indicates that the item either has not
been through the IETF consensus process, has limited applicability, or
is intended only for specific use cases.  If the "Recommended" column
is set to "D" the item is discouraged and <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</t>
          </dd>
        </dl>
      </section>
    </section>
    <section anchor="tls-extensiontype-values">
      <name>TLS ExtensionType Values</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure to:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Values with the first byte in the range 0-254 (decimal) are assigned
    via Specification Required [RFC8126].  Values with the first byte
    255 (decimal) are reserved for Private Use [RFC8126].  Setting a
    "Recommended" column value to "Y" or "D" requires Standards Action [RFC8126].
    Any state transition to or from a "Y" or "D" value requires
    IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Extension</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">4</td>
            <td align="left">truncated_hmac</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">53</td>
            <td align="left">connection_id (deprecated)</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">40</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">46</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-cipher-suites-registry">
      <name>TLS Cipher Suites Registry</name>
      <t>Several categories of ciphersuites are discouraged for general use and
are maked as "D".</t>
      <t>Ciphersuites that use NULL encryption do not provide the confidentiality
normally expected of TLS. Protocols and applications are often designed
to require confidentialy as a security property. These
ciphersuites <bcp14>MUST NOT</bcp14> be used in those cases.</t>
      <t>Ciphersuites marked as EXPORT use weak ciphers and were deprecated in
TLS 1.1 <xref target="RFC4346"/>.</t>
      <t>Cipher suites maked as anon do not provide any authentication and are
vulnerable to man-in-the-middle attacks and are deprecated in TLS 1.1
<xref target="RFC4346"/>.</t>
      <t>RC4 is a weak cipher and is deprecated in <xref target="RFC7465"/>.</t>
      <t>DES and IDEA are not considered secure for general use and are deprecated
in <xref target="RFC5469"/>.</t>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure to:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Values with the first byte in the range 0-254 (decimal) are
    assigned via Specification Required [RFC8126].  Values with the
    first byte 255 (decimal) are reserved for Private Use [RFC8126].
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries. This document does not
make any changes to the DTLS-OK column.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Cipher Suite Name</th>
            <th align="right">Recommeded</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0x00,0x01</td>
            <td align="left">TLS_RSA_WITH_NULL_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x02</td>
            <td align="left">TLS_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x03</td>
            <td align="left">TLS_RSA_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x04</td>
            <td align="left">TLS_RSA_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x05</td>
            <td align="left">TLS_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x06</td>
            <td align="left">TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x07</td>
            <td align="left">TLS_RSA_WITH_IDEA_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x08</td>
            <td align="left">TLS_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x09</td>
            <td align="left">TLS_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0B</td>
            <td align="left">TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0C</td>
            <td align="left">TLS_DH_DSS_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0E</td>
            <td align="left">TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0F</td>
            <td align="left">TLS_DH_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x11</td>
            <td align="left">TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x12</td>
            <td align="left">TLS_DHE_DSS_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x14</td>
            <td align="left">TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x15</td>
            <td align="left">TLS_DHE_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x17</td>
            <td align="left">TLS_DH_anon_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x18</td>
            <td align="left">TLS_DH_anon_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x19</td>
            <td align="left">TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1A</td>
            <td align="left">TLS_DH_anon_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1B</td>
            <td align="left">TLS_DH_anon_WITH_3DES_EDE_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1E</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x20</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x21</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x22</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x24</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x25</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x26</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x27</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x28</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x29</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2A</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2B</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2C</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2D</td>
            <td align="left">TLS_DHE_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2E</td>
            <td align="left">TLS_RSA_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x34</td>
            <td align="left">TLS_DH_anon_WITH_AES_128_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x3A</td>
            <td align="left">TLS_DH_anon_WITH_AES_256_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x3B</td>
            <td align="left">TLS_RSA_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x46</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x6C</td>
            <td align="left">TLS_DH_anon_WITH_AES_128_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x6D</td>
            <td align="left">TLS_DH_anon_WITH_AES_256_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x89</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x8A</td>
            <td align="left">TLS_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x8E</td>
            <td align="left">TLS_DHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x92</td>
            <td align="left">TLS_RSA_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x9B</td>
            <td align="left">TLS_DH_anon_WITH_SEED_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xA6</td>
            <td align="left">TLS_DH_anon_WITH_AES_128_GCM_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xA7</td>
            <td align="left">TLS_DH_anon_WITH_AES_256_GCM_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB0</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB1</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB4</td>
            <td align="left">TLS_DHE_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB5</td>
            <td align="left">TLS_DHE_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB8</td>
            <td align="left">TLS_RSA_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB9</td>
            <td align="left">TLS_RSA_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xBF</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xC5</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x01</td>
            <td align="left">TLS_ECDH_ECDSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x02</td>
            <td align="left">TLS_ECDH_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x06</td>
            <td align="left">TLS_ECDHE_ECDSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x07</td>
            <td align="left">TLS_ECDHE_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x0B</td>
            <td align="left">TLS_ECDH_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x0C</td>
            <td align="left">TLS_ECDH_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x10</td>
            <td align="left">TLS_ECDHE_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x11</td>
            <td align="left">TLS_ECDHE_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x15</td>
            <td align="left">TLS_ECDH_anon_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x16</td>
            <td align="left">TLS_ECDH_anon_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x17</td>
            <td align="left">TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x18</td>
            <td align="left">TLS_ECDH_anon_WITH_AES_128_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x19</td>
            <td align="left">TLS_ECDH_anon_WITH_AES_256_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x33</td>
            <td align="left">TLS_ECDHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x39</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x3A</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x3B</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x46</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_128_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x47</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_256_CBC_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x5A</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_128_GCM_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x5B</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_256_GCM_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x84</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_128_GCM_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x85</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_256_GCM_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0xB4</td>
            <td align="left">TLS_SHA256_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0xB5</td>
            <td align="left">TLS_SHA384_SHA384</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-supported-groups">
      <name>TLS Supported Groups</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS Supported Groups registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration policy to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Curve</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1</td>
            <td align="left">sect163k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">sect163r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">sect163r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">sect193r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">sect193r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">sect233k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">7</td>
            <td align="left">sect233r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">sect239k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">15</td>
            <td align="left">secp160k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">16</td>
            <td align="left">secp160r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">17</td>
            <td align="left">secp160r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">18</td>
            <td align="left">secp192k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">19</td>
            <td align="left">secp192r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">20</td>
            <td align="left">secp224k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">21</td>
            <td align="left">secp224r1</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
        <li>
          <t>Replace the registry range table note column for the 0-255, 512-65535
range with "Unallocated".</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-exporter-labels-registry">
      <name>TLS Exporter Labels Registry</name>
      <t>This document updates the registration procedure for the TLS Exporter
registry and updates the Recommended column allocation.
IANA <bcp14>SHALL</bcp14> update the TLS Exporter Labels Registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure from Specification Required to
Expert Review and update it to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries</t>
        </li>
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
        <li>
          <t>update the note on the role of the expert reviewer as follows.</t>
        </li>
      </ul>
      <dl>
        <dt>Note:</dt>
        <dd>
          <t>The role of the designated expert is described in <xref section="17" sectionFormat="comma" target="RFC8447"/>.
Even though this registry does not require a specification, the
designated expert <xref target="RFC8126"/> will strongly encourage registrants
to provide a link to a publicly available specification. An
Internet-Draft (that is posted and never published as an RFC)
or a document from another standards body, industry consortium,
university site, etc. are suitable for these purposes.
The expert may provide more in-depth reviews, but their approval
should not be taken as an endorsement of the exporter label.  The
expert also verifies that the label is a string consisting of
printable ASCII characters beginning with "EXPORTER".  IANA <bcp14>MUST</bcp14>
also verify that one label is not a prefix of any other label.
For example, labels "key" or "master secretary" are forbidden.</t>
        </dd>
      </dl>
    </section>
    <section anchor="tls-certificate-types">
      <name>TLS Certificate Types</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the the TLS Certificate Types registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure to:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Values in the range 0-223 (decimal) are assigned via Specification
    Required [RFC8126]. Values in the range 224-255 (decimal) are
    reserved for Private Use [RFC8126]. Setting a "Recommended" column
    value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries.</t>
        </li>
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-hashalgorithm-registry">
      <name>TLS HashAlgorithm Registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the TLS HashAlgorithm Registry
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS HashAlgorithm registry to add a "Recommended" column
as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">none</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">md5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">sha1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">sha224</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">sha256</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">sha384</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">sha512</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">Intrinsic</td>
            <td align="right">Y</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-signaturealgorithm-registry">
      <name>TLS SignatureAlgorithm registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the TLS SignatureAlgorithm registry
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS SignatureAlgorithm registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">anonymous</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dsa</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">ecdsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">7</td>
            <td align="left">ed25519</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">ed448</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">gostr34102012_256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">gostr34102012_512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-clientcertificatetypes-registry">
      <name>TLS ClientCertificateTypes registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the  TLS ClientCertificateTypes
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS ClientCertificateTypes registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dss_sign</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">rsa_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">dss_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">rsa_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">dss_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">20</td>
            <td align="left">fortezza_dms_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">ecdsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">rsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">66</td>
            <td align="left">ecdsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">67</td>
            <td align="left">gost_sign256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">68</td>
            <td align="left">gost_sign512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-pskkeyexchangemode-registry">
      <name>TLS PskKeyExchangeMode registry</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS PskKeyExchangeMode registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing recommended column "Y" and "N" entries.</t>
        </li>
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-signaturescheme-registry">
      <name>TLS SignatureScheme registry</name>
      <t>IANA is requested to add a reference to this document under the reference heading.</t>
    </section>
    <section anchor="adding-comment-column">
      <name>Adding "Comment" Column</name>
      <t>IANA is requested to add a "Comment" column to the following registries:</t>
      <ul spacing="normal">
        <li>
          <t>TLS ExtensionType Values</t>
        </li>
        <li>
          <t>TLS Application-Layer Protocol Negotiation (ALPN) Protocol IDs</t>
        </li>
        <li>
          <t>TLS CachedInformationType Values</t>
        </li>
        <li>
          <t>TLS Certificate Compression Algorithm IDs</t>
        </li>
        <li>
          <t>TLS Cipher Suites</t>
        </li>
        <li>
          <t>TLS ContentType</t>
        </li>
        <li>
          <t>TLS EC Point Formats</t>
        </li>
        <li>
          <t>TLS EC Curve Types</t>
        </li>
        <li>
          <t>TLS Supplemental Data Formats (SupplementalDataType)</t>
        </li>
        <li>
          <t>TLS UserMappingType Values</t>
        </li>
        <li>
          <t>TLS Authorization Data Formats</t>
        </li>
        <li>
          <t>TLS Heartbeat Message Types</t>
        </li>
        <li>
          <t>TLS Heartbeat Modes</t>
        </li>
        <li>
          <t>TLS SignatureScheme</t>
        </li>
        <li>
          <t>TLS PskKeyExchangeMode</t>
        </li>
        <li>
          <t>TLS KDF Identifiers</t>
        </li>
      </ul>
      <t>This list of registries is all registries that do not already have a
"Comment" or "Notes" column or that were not orphaned by TLS 1.3.</t>
    </section>
    <section anchor="expert-review-of-current-and-potential-ietf-and-irtf-documents">
      <name>Expert Review of Current and Potential IETF and IRTF Documents</name>
      <t>The intent of the Specification Required standard for TLS code points
is to allow for easy registration for code points associated with
protocols and algorithms that are not being actively developed inside
IETF or IRTF. When TLS-based technologies are being developed inside
the IRTF/IETF they should be done in coordination with the TLS WG in
order to provide appropriate review. For this reason, unless the TLS WG
chairs indicate otherwise via email, designated
experts should decline code point registrations for documents which
have already been adopted or are being proposed for adoption by IETF
working groups or IRTF research groups.</t>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The change to Specification Required from IETF Review lowers the amount
of review provided by the WG for cipher suites and supported groups.
This change reflects reality in that the WG essentially provided no
cryptographic review of the cipher suites or supported groups.  This
was especially true of national cipher suites.</t>
      <t>Recommended algorithms are regarded as secure for general use at the
time of registration; however, cryptographic algorithms and parameters
will be broken or weakened over time.  It is possible that the
"Recommended" status in the registry lags behind the most recent advances
in cryptanalysis.  Implementers and users need to check that the
cryptographic algorithms listed continue to provide the expected level
of security.</t>
      <t>Designated experts ensure the specification is publicly available.  They may
provide more in-depth reviews.  Their review should not be taken as an
endorsement of the cipher suite, extension, supported group, etc.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document is entirely about changes to TLS-related IANA registries.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-normative-references">
      <name>Normative References</name>
      <reference anchor="RFC8447">
        <front>
          <title>IANA Registry Updates for TLS and DTLS</title>
          <author fullname="J. Salowey" initials="J." surname="Salowey"/>
          <author fullname="S. Turner" initials="S." surname="Turner"/>
          <date month="August" year="2018"/>
          <abstract>
            <t>This document describes a number of changes to TLS and DTLS IANA registries that range from adding notes to the registry all the way to changing the registration policy. These changes were mostly motivated by WG review of the TLS- and DTLS-related registries undertaken as part of the TLS 1.3 development process.</t>
            <t>This document updates the following RFCs: 3749, 5077, 4680, 5246, 5705, 5878, 6520, and 7301.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="8447"/>
        <seriesInfo name="DOI" value="10.17487/RFC8447"/>
      </reference>
      <reference anchor="RFC2119">
        <front>
          <title>Key words for use in RFCs to Indicate Requirement Levels</title>
          <author fullname="S. Bradner" initials="S." surname="Bradner"/>
          <date month="March" year="1997"/>
          <abstract>
            <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="2119"/>
        <seriesInfo name="DOI" value="10.17487/RFC2119"/>
      </reference>
      <reference anchor="RFC8174">
        <front>
          <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <date month="May" year="2017"/>
          <abstract>
            <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="8174"/>
        <seriesInfo name="DOI" value="10.17487/RFC8174"/>
      </reference>
      <reference anchor="RFC8126">
        <front>
          <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
          <author fullname="M. Cotton" initials="M." surname="Cotton"/>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <author fullname="T. Narten" initials="T." surname="Narten"/>
          <date month="June" year="2017"/>
          <abstract>
            <t>Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
            <t>To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed. This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
            <t>This is the third edition of this document; it obsoletes RFC 5226.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="26"/>
        <seriesInfo name="RFC" value="8126"/>
        <seriesInfo name="DOI" value="10.17487/RFC8126"/>
      </reference>
      <reference anchor="RFC4346">
        <front>
          <title>The Transport Layer Security (TLS) Protocol Version 1.1</title>
          <author fullname="T. Dierks" initials="T." surname="Dierks"/>
          <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
          <date month="April" year="2006"/>
          <abstract>
            <t>This document specifies Version 1.1 of the Transport Layer Security (TLS) protocol. The TLS protocol provides communications security over the Internet. The protocol allows client/server applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="4346"/>
        <seriesInfo name="DOI" value="10.17487/RFC4346"/>
      </reference>
      <reference anchor="RFC7465">
        <front>
          <title>Prohibiting RC4 Cipher Suites</title>
          <author fullname="A. Popov" initials="A." surname="Popov"/>
          <date month="February" year="2015"/>
          <abstract>
            <t>This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections. This applies to all TLS versions. This document updates RFCs 5246, 4346, and 2246.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="7465"/>
        <seriesInfo name="DOI" value="10.17487/RFC7465"/>
      </reference>
      <reference anchor="RFC5469">
        <front>
          <title>DES and IDEA Cipher Suites for Transport Layer Security (TLS)</title>
          <author fullname="P. Eronen" initials="P." role="editor" surname="Eronen"/>
          <date month="February" year="2009"/>
          <abstract>
            <t>Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346) include cipher suites based on DES (Data Encryption Standard) and IDEA (International Data Encryption Algorithm) algorithms. DES (when used in single-DES mode) and IDEA are no longer recommended for general use in TLS, and have been removed from TLS version 1.2 (RFC 5246). This document specifies these cipher suites for completeness and discusses reasons why their use is no longer recommended. This memo provides information for the Internet community.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="5469"/>
        <seriesInfo name="DOI" value="10.17487/RFC5469"/>
      </reference>
      <reference anchor="RFC8996">
        <front>
          <title>Deprecating TLS 1.0 and TLS 1.1</title>
          <author fullname="K. Moriarty" initials="K." surname="Moriarty"/>
          <author fullname="S. Farrell" initials="S." surname="Farrell"/>
          <date month="March" year="2021"/>
          <abstract>
            <t>This document formally deprecates Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346). Accordingly, those documents have been moved to Historic status. These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008 (subsequently being obsoleted by TLS version 1.3 in 2018), providing sufficient time to transition away from older versions. Removing support for older versions from implementations reduces the attack surface, reduces opportunity for misconfiguration, and streamlines library and product maintenance.</t>
            <t>This document also deprecates Datagram TLS (DTLS) version 1.0 (RFC 4347) but not DTLS version 1.2, and there is no DTLS version 1.1.</t>
            <t>This document updates many RFCs that normatively refer to TLS version 1.0 or TLS version 1.1, as described herein. This document also updates the best practices for TLS usage in RFC 7525; hence, it is part of BCP 195.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="195"/>
        <seriesInfo name="RFC" value="8996"/>
        <seriesInfo name="DOI" value="10.17487/RFC8996"/>
      </reference>
    </references>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+0823LbRpbv+Ipe5sXeImmSIqnLZDOhSDrWxJa9opysK5VS
NYEWiREIIN2AZCZKvmW/Zb9szzndABogQEmx8zC7Vrksqtnn2ufW106n4yR+
EogTdjY5n7ALsfJVIrfsfezxRCh2HUl2+XrBeOixGXxw+HIpxe0JezZ7ju21
UI4XuSHfAFJP8uuk44vkupMEqiOv3aPh8HDpq06/57jQdxXJ7QlTieekGvaE
HRwOj9ts1Ds8bLPh+KgHnwfDMfx/2BvB/0eHR202Hg2g/fCg128zxOgARweO
48fyhCUyVcmg1zvuDRwuBT9hrYVwU+kn25ZzF8mblYzSGFovJQ9VHMmEveZb
IVnR60ZsoaMHSgkTIUORdGYoiHMrwlScOIw9jIKxZBuDBlo/AkU/XLHvEATb
N9wPoB308S0qphvJFTZz6a6heZ0ksTp58QJ7YZN/K7pZtxfY8GIpozslXgD8
C4Rb+ck6XWqEd6sXhYpbjqMSGLcrHkQhcLKFgVEbLpOrX9KINB1GTuyfsJ+S
yG0zBVJIca3g03aDH352HJ4m60iCwB0gxJgfAtA/umwBGO/Eltr0OP8jEqVW
YJaH/q888aPwhP0gQn7t0xdCS//PSHyrdP8uqLdEYNFllykoXVr4F4KHdmsZ
vwoPpGejV9D9W2rtutHGccJIbqDvLYyd44fX1l+dTofxJRgvdxPHuVz7ioHx
phsRJsxYJEvWgrlrHq7wc1RyB23/Utu/DwrecE+AGOzi5ZQMs8vOEsY9TzHO
QnHHbnmQCtaatcizPF+5USr5SngOYEZCUgDHQN4THnOjIN2ELLqmb5QIhJtA
M9ItSCIvjqHQmhJsoloZLGDlQcBAOpDXguruE/Y6CmBo0GhBDHXiPNUjUTsk
vNbvxve8QDjOV+hOMvJSF4etygCMPXiumyitU2B8w29KigcNppsleJlRCPZz
LEVIEXDUD45Rg1+yZ6C853r4eMJXkm+c5r44ws/BGtdCFYxoRZWMAgcd7Ir9
9tu/gcJQ8t9/B9m/5soHawCXu/Giu/A/Wssgcm9a34Clnr+9nJMFoAwnrKwJ
FQvXv0aJLOG1bZg4C39rNjDMVBhhxIjFx9cviI9vjMINdpd8pzTsrYvC9nID
AmwY9i01A3FPXPuhgAFJ1r70KkbtJ2KDCDkYvhS2jXfRBi6F3PhhFESrLXIk
GARbhtFWsdab94vLVlv/Rh3h54v5f74/u5jP8PPi1eT16/yDY3osXr19/3pW
fCogp2/fvJmfzzQwtLJSk9N6M/nQ0ubaevvu8uzt+eR1CyVOSuOBUoDQS1Qt
pINYCrQyDmlOKFf6S/gDYE6n7/7nv/tDYwSDfv/4998zi+gfDuGPu7UINbUo
DLbmT1D81uFxLLhELOisLo/9hAcQiTkM1xpMh62FFKC9f/8JNfPzCft66cb9
4TemAQUuNWY6KzWSznZbdoC1Emuaasjk2iy1VzRd5nfyofR3pner8eu/B2hd
nf7R38FowWQmnofBqGyfU7JPbUJZ7ACLVrvjZ3nsxU50bTuR9Fd+CIrfYqDW
g2k5EEUezysbexutvQ0+75EjAXPa3o0rAPXWrLD7FsUQFqPlJ2g71EthdQIp
6MOJg4UGYRLGcSi8zS9fsjWYgAtSiVClxXc6WYKfISVL010dSci8NpADLWxc
qcj1MT4S8EZgzPAVYbj2E/Jc7BenMo6UoL/v1r67BjrsDrjQPg8+jOBTYP06
DSAicRoaE5EzlevYkqG0aemcLlyhFDeBDAZDUqGi+YzjADSx9AMMwYQXJMhR
aPKXmXpAw4FX5Myin5F8zSHrBT6o3chdQt9myxSE88HnYhndYrAukwe2QMmY
UAkdYcicHhx5q1FzbXdGB4W0IH4hKQ4iVBkQQbQOQD8+oE0V+vV5gwnQEKMJ
hFEC8UeETKDpUJZb6kortxStwKrtUEYIo0ISqHaitDAilQL/trJtS7HUnqUo
oXnJ5PKDrTEnHhbUy8YV8DvhtbVRUhdgpzBp8RHyiqoM68Zfrc3gWcYfsUBg
Ew9NjsHMSpEYgnsLCOQKWULGowHxCQtaqDGCqn1JGAFwUXt4YDxm+8YD9WDl
NK0ZZAXJaIME64CBpUoEjCpM/Ott2esMTi2nFCoNsABCK1wGKJlPQ7Gl1IOY
oChPwRW5th3O7gS/Ya7cxkkENUwMfgqZA+ZSMBcgu+PWGFiUXA7ITKUNmSyC
iJRpoiAdgonHQbRFa4HydRMHZDjgpEznAUKACkOuUS0QrnEcICRAmgpdrEkL
G7oDngrlJZFxooTKAFNHRaBq7UQUDYrAUyQelCrLdZl+YaQWIqHwm0Ve0Hjr
Qws7YzlCqaChsJHil9QH1WuLW2AA4lCEOBNKI3nmHoyhhmJsEppoANNLiKvE
LRIDQtcy2mDtXZDVrGQEnLP54js2iTHE8KDLzsF/MM1rGzZhFVnNecDy1b2h
4hs8TdvREicAiVOSr0tskV7RKSOQVd75ELyzCtJDYwUwUsu5SUNZYaecZcDD
GwrTOiEVRVsawgj6K2QMvgUhhLyFz2kYgNsXJSTmTECPdd1XpdwKMgr221cQ
mDvAmfjdcebo5zhSViVJDs6Rd4HxUIcOMNoioezOhrrspU4rdkmK/pgqpdVI
c6V0qUD9VE0LUxdQUUC0/KyK9xyyTg6dwMDBcrPorjO6MKOZYlA0syKYDjko
HfyCEHHdUDTbWm+jIddFThLWIZ1DjzxU/o1JjiNJcH5DEBI+dslyg0O5IVnL
KF2tiwRQxE6wPSTbJoDaUAgBWjq+osBA6qZ4jbaRjTa6HEQQBZNHhpI3eZZj
SQ/qa4iblK8edO+vaLI7/wg8KRjEy20s2A+6eHLOYGYsMVoAIQw9blKaCxlL
2K340PkiPf1pOzTX1HWwVSY2ES1mYCV76LApEbUnaboEIr17KU0goOMff/xB
4c9gy0PjtQ8VEGT0RGRsS8LX6wxGQ/bMgwHY8OA5uWbmmITo1udsUZrQXeio
47GfTPj6ubuPHmEZjEYVIrnHowG8k/4tauY9jL+NNY+9hKTWEeqCch54i3hn
Ym6BnDB+SsxF+HLcJeXDUE2ols9zlZ5bl6YLlIL0UGad1rrOxQUNs8jZnFhy
LWeWSC6nqGYTYDGguXmoV4sYTH5FjJ19qSshmueAVDQnhaJG6J7wpSviokrP
mv3QWqyBQi4QqLrJPvG0sWP9SpMdvbSgcpQg4j2ZC7svXIA98HNfcrN75/6k
gz/m1wM/9/YfJwA8BIQwnQsx7nlX6w136yhmPzOkNzpg9xDtQh3rr3wP7Rkm
6oTieS3IsMfuLzIzb5SrDDJ+KkhhLnaSq1nj00YjPiZ69pknTlxHysLg1I8x
5i+gZIehzxbdsQa6hToO1w1oPR3tAtKnS72V7lxZiCE7WomQwDCs0xqiFLTk
pgtqqC4cZ2rjoASEnc/fgwGBcWH5icbhRZTZsimUqeiudeXLMbnoBVisFsTH
WC9iAocgUxeCS5REoARax8xSkk7YyFB0DSaIWVnHPAr15OIlEhSPMYublbuY
Sttka9bunJIuqmlGh9woT24VsYtJxvy/3r29uCQV6PpbdyPG7wRqODc5wOng
kPW7fVNJDg+GYxpNM4o5doOch7uaxBkmLsGjkCa8k5KkcG7TAEcPHF6vlIYd
P+xAz45ebGU8SaCEVFn/MmvMsOZUWLuYDjFLc1s8woDxo4RAAx4OxyMCnM31
kvjZbD4hcigFVh8gBeYiGhhRZ3UV5opV1NFwfEy4/3+meT3Py2rwP5fmCYdF
80+leUJSzLI+IcvrnF7N9E/K8rrmKWX6L1n+T2X5ypZDNj2h7ckbHXkqmw+4
GdJ5+302DYMygWV1gp2Y2DnfiOZKgVnFQqlWeGSxUFs1YNHAeh97vTb81zdE
gN2ri8Xk6sezy1dXmLKu3sxGO6l6xpgNPGgEBoU+AHtQgdXpQqOAyHo17BkO
7nU1kQMO64giRH9wVGW6hu5oH/jDbI/3sj24mp5OC9YtRDMbyWEdD5gNCPxh
Jo72MAHJBeg/Ds9xHR+A4JHgpwZ0BkCLxZ/mYmpxYVA9kZF5GcOnqORlGU0d
I/dVoH6/RH/+KdroD2pwPU0d/WEFxSfooz+qwbWHnRoMhyUMV1i5NTt7M5qj
GjRPc/3+8QOcPEUvkyZ2Hq2X0yYMB4hiPps/Do1t+99fnI6eaCyDXi38owPi
oF8L//hgNhjUIsgEeHBUB8Na+EdbxWBUC58LUEZQAz+uwldMKksJpIlKMhsc
7gO28gkCV2GP9sMOc6KmXxn6+JFsG/mr4JNHMt4AfvoI3hG0Cjc1MO8W31eq
jWrPmRW0Hu49t7Lgg70PhnVuOwGdocVlVl8FmjQBDUbjRqBTVsnOGU8AVO2M
6y27FKaTN/PXr88m+3gbTx8hUA3F8ewRMtXAHR3v5XSPQo5su8sHyo5WVYBy
bTB/FNBxtbB9FNBpnVCL+XzWJMykdsAytX83fdOgvsnhPrUbuIOjYRXutFen
vD0WddrfB1BHYVin6X0URvsA6igc7fNUpFAX7U6P90HVkXn5WF+qEWo6eqx5
l4GnZkamgedTAIf/duZVVQDbWKtA9fY6NVOZAmb+KEqHFUrzx5I6tdnbnSlW
u0+rEtVO1CpQ/V6JsweplKr2Csw+MiObsWJ4G8mMq8Lslq51YIf1IDvFYRXu
qB6ump12qoKpKZEboeujMoEdHOyo8oGIqcGOm8GsVYQq1GQ/RI1PHZzuBykH
gGlzMp1c7Dp/nR6H9RH6ouz9SLYOelRfKmS0rcRQC12bh3LatemBAI9qy5pS
zKvNSRr44ZjXTDlPGxp3A4k8V2gkZVyfae9Ibx0t0hhPOAMMXUP463fPqwQb
l9StddbyknoU+C4dEPRDN0g9Ya2rf1mO/r+2HF1aTU7lLf7e2VLGf3qtFyoK
PNbTHx/c9HOnGsAn0yqL1gOrdZC3DrPWY7vvyGot+o5N6+DApnZYtFoYjvLW
Y6tv3yCO++Oe3Twumi0c/UOruWCjf5Q1Hw9sJMdFs4Vk0DPNg8HQ1lG/aM57
f5ZA04HxigPullx5aza4yEg0doMqsync+sI7JP1BZzwaHYzAkDQI0Wq9D024
wUPUxXEgCi2SveZg2/ZOePOVlobtuowNG61ThCrwBxvJ3mjY3bvJWM/x0/cX
KQY1bAXS2UogJWQCjbe+uLMkwMNkX4KpDqYmEtbGwZoxrgmNn8tnLDsp4YkC
kR2BFHpAJQ0o7sfnJtPNTiKe0LlOG0gfmKDdegNPW/jWdZX8hkMbLzzRwPTp
utD8lo4SmpOEvpW58zOM2REMXr5MRJdZnF3S9lFafdoe0EXhCo+DhOZISm7v
eD4eBjQ/AkGHi/XtrzhdQk2Ahz1u8XIkhpQSfbQ3p3xjkz3TxysV1BOUDHEc
Qzwvo7GpdXb6Ak/bPnfo6HRuR9pGQzpXy1R+Wm0Zeds2nsxMSS14zgG82083
bScNfcCt6O6An4g2E4nbpa12fdA+yEOOyq9awDheFuO84dtc+E0k8aRAx4Ms
vDYWoPSlBW213LiGo9Z07lxfE4BwewNjqMUCY4yk0kf/C4vS0SjAaNSlc/eO
Ic8DFTEQQd8/y8+cUk99NgSP3NJBd/Bn7TLRtRNDmxZvspienWEVgjcq8XTM
EgY2pDO9OqTrddH5RQtPkWLExPM4TkHXXBKIQosqygXjD97sf0QpcHtaj4oW
wcEzweIjx7Pqbd2mWOtGbHVw2XCF4kLekyLhElq5jv1LH8qRsCiTp6ACbU4Q
t7fxX3zKNMsOO1Q/8/mT6lmTwUHDkdLdcyaEpu6sSR1qqCk6O2dMCMNjjpPu
z0NWdviSi8q5qPtZZ4qvuFpP8qskdmlFGUGfHOsRD9kBt+rZNxPvj48h3rdN
rwEFfofuUNLZLzpZHm1AY/5GdNmT3czZdTPWXIA1SPXkSanlZ19KqYqmdvVs
31fWVygbXLuk/mImOIOCRUlfnzKtP2PMWOXc0M5pYoYzoRDTyT37wMzskW28
UbHORDPHNa9MGtccAlp5xghNtIrzoZgurrlesvlQzBXXHKYzeRNO2/Deuw+D
5ppWo/nPsK5DpRYY5K7S/9Vddp9oX/z2M/vtHmU3OK/D8kKn5LxP8N3qkb96
18W11+0mStU9O8/dVyqeOxi6mkd/n+fOK1zP6oELKsKD0oQWSwq3FN5weFT4
LrrxCqYJ8mDY7w16/cGV9naNdjza+Vq7+flncWhTgAY+jJ5VEJbrwX9ln94j
3xd//tz+/IAdNfl0rUc/JR0/wqeN+17hlKPiwyprLBwZe8KkT3hX3jr/Ymh6
73wxMhAiXsOMV/IAvry6mC/mFz/MZ6UFXQTf34tWUK9xovzrr/zK26gaRMMs
1JSlGY9KnEOPgsXxOIep+/bQBBlCWAo/R/Y3nz/yvFM334vt/KN29TeRJ6yo
8xdvFu2h/SUi/BUTyxoL+esmlpVKdeGi19nGhXZB64y/pEKZB5z4p4lfvBlj
XsQq3ovZQ67oXLyelZTewyrunJM1Nl5O1l9NittsHf22VHbbjZ2LVZT42naf
TV6/O39efHc2yxBMOSjLO8teLKujYS8eAfuQ/RXd2CwKOQudfYEwa4vwwneC
iDOBpuxd5IOKXxJVVTTrnTmdsjv5Nq9+HoIH9KJWBsSe2V/hNwj23IC9V0K+
4XEMKq3RGj06Zx53KyE1HV4JLpOl4Al7g1fpV2WWrG8hkOSMls3PtO4GHvPF
97OX7Ey/3OELqczOEm6o4vKj9fIALokGgd1Cq5fmIh8P8IGcrXnowCnsC6MB
rt0XD7XRqjBAUhVHrznIGLiih15M8XZAhl3e4AFuYFQkPewC3vsuSvSNyOJN
mLML+DAzbqOy95ISaz24YTspW/DO34B0MTDHET1h4yvztFx0R98LrrbliIyt
FkT1SRAnLl/8zMzVeoRCr2ZT2Kbn64ItlLfwK4ppCwMvFzokJr6jBlJ22Y9r
QZcbO0tOz68Id00vjfnmCqzGtoOEHkwABC8IW4IPr5gF9SW+aRRStexGkAL9
UAuXb7ejXn78Dq975gnSekpIRrFEkc3affZ2BUUfrrBWNi9qFKgcsEVfqvzh
B+tVD1ydpQcO29b+jlm4VxnHnnDp9axC9aVh0S96ZlFU6ZdWHG2fxljpLQnu
RXGiX/8oFIfyRMos41IP1AXYJ+qNntbEXit94MMMCq394ruVpl2vXeRv7E3N
JVHNnLZO16xyR02WSWmVxsp4AT4kKbUWOUwVw8QhL6XvzHCQH2EHGC0yzdI1
XDRBlR9ZyTglpzfcQJbB5xdp5OjBHN968Ahwwihqzwu2BckwcsqP9Mjca6l+
KvGAM7EqC4zu6Tn4/pagvS7Cn8iUdvq0MeLNbxsRXuS1MrTlWfrK5wp8Wu96
NV3L1c9D4YzQinZE629sDaq+xcdJGl4f0rqMueQbfOMHeMcNP/CjpYxwVwqf
FRO4P4XGhftweuKJz2TqXTrl06Xm7KWzcr2GdVZabDtkRWLAV7jRtPbNI2Ib
qJOxTKGw6N1yfJMIrxYTzxw0tlU+vWJiP25Ee+UKP2Vv7kCqcG8KVholNgdt
XEilfqgLSfsyfH7nPcDAg6aZXVTHq9PV7VIY6VBRIbuu7G+Sgnb2QPX+3RY3
Dp29G4e6oy8zI2zcM3Rq9gxtC2sDp6bmaVdNVu94ko9TobXr36U3P1HYBHwa
BaJ3ycrvrHayJz0rz6wiAVz8XXL3xvlf/lXfcMRYAAA=

-->

</rfc>
