| rfc9847.original.xml | rfc9847.xml | |||
|---|---|---|---|---|
| <?xml version='1.0' encoding='utf-8'?> | <?xml version='1.0' encoding='utf-8'?> | |||
| <!DOCTYPE rfc [ | <!DOCTYPE rfc [ | |||
| <!ENTITY nbsp " "> | <!ENTITY nbsp " "> | |||
| <!ENTITY zwsp "​"> | <!ENTITY zwsp "​"> | |||
| <!ENTITY nbhy "‑"> | <!ENTITY nbhy "‑"> | |||
| <!ENTITY wj "⁠"> | <!ENTITY wj "⁠"> | |||
| ]> | ]> | |||
| <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?> | <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?> | |||
| <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.29 (Ruby 3.4. | <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.29 (Ruby 2.5. | |||
| 4) --> | 9) --> | |||
| <rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft | <rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft | |||
| -ietf-tls-rfc8447bis-15" category="std" consensus="true" submissionType="IETF" u | -ietf-tls-rfc8447bis-latest" category="std" consensus="true" submissionType="IET | |||
| pdates="8447" tocInclude="true" sortRefs="true" symRefs="true" version="3"> | F" number="9847" updates="8447" tocInclude="true" sortRefs="true" symRefs="true" | |||
| <!-- xml2rfc v2v3 conversion 3.30.0 --> | version="3"> | |||
| <!-- xml2rfc v2v3 conversion 3.31.0 --> | ||||
| <link href="https://datatracker.ietf.org/doc/draft-ietf-tls-rfc8447bis-latest" | ||||
| rel="prev"/> | ||||
| <front> | <front> | |||
| <title abbrev="(D)TLS IANA Registry Updates">IANA Registry Updates for TLS a | <title abbrev="TLS and DTLS IANA Registry Updates">IANA Registry Updates for | |||
| nd DTLS</title> | TLS and DTLS</title> | |||
| <seriesInfo name="Internet-Draft" value="draft-ietf-tls-rfc8447bis-15"/> | <seriesInfo name="RFC" value="9847"/> | |||
| <author initials="J." surname="Salowey" fullname="Joe Salowey"> | <author initials="J." surname="Salowey" fullname="Joe Salowey"> | |||
| <organization>Venafi</organization> | <organization>Venafi</organization> | |||
| <address> | <address> | |||
| <email>joe@salowey.net</email> | <email>joe@salowey.net</email> | |||
| </address> | </address> | |||
| </author> | </author> | |||
| <author initials="S." surname="Turner" fullname="Sean Turner"> | <author initials="S." surname="Turner" fullname="Sean Turner"> | |||
| <organization>sn3rd</organization> | <organization>sn3rd</organization> | |||
| <address> | <address> | |||
| <email>sean@sn3rd.com</email> | <email>sean@sn3rd.com</email> | |||
| </address> | </address> | |||
| </author> | </author> | |||
| <date year="2025" month="July" day="21"/> | <date year="2025" month="October"/> | |||
| <area>Security</area> | <area>SEC</area> | |||
| <workgroup>Transport Layer Security</workgroup> | <workgroup>TLS</workgroup> | |||
| <keyword>Internet-Draft</keyword> | ||||
| <abstract> | <abstract> | |||
| <?line 41?> | <?line 38?> | |||
| <t>This document updates the changes to TLS and DTLS IANA registries | <!-- [rfced] Note that we have updated the short title, which appears in the | |||
| made in RFC 8447. It adds a new value "D" for discouraged | running header in the PDF output, as follows. Please let us know any objections. | |||
| to the Recommended column of the selected TLS registries and | ||||
| Original: | ||||
| (D)TLS IANA Registry Updates | ||||
| Current: | ||||
| TLS and DTLS IANA Registry Updates | ||||
| --> | ||||
| <!-- [rfced] Please insert any keywords (beyond those that appear in the title) | ||||
| for use on https://www.rfc-editor.org/search. --> | ||||
| <!-- [rfced] FYI - We will do the following when we convert the file to RFCXML: | ||||
| - Update relevant URLs to be clickable in the HTML and PDF outputs | ||||
| --> | ||||
| <!-- [rfced] Because this document updates RFC 8447, please | ||||
| review the errata reported for RFC 8447 | ||||
| (https://www.rfc-editor.org/errata/rfc8447) | ||||
| and let us know if you confirm our opinion that none of them | ||||
| are relevant to the content of this document. | ||||
| --> | ||||
| <t>This document updates the changes to the TLS and DTLS IANA registries | ||||
| made in RFC 8447. It adds a new value, "D" for discouraged, | ||||
| to the "Recommended" column of the selected TLS registries and | ||||
| adds a "Comment" column to all active registries that do not | adds a "Comment" column to all active registries that do not | |||
| already have a "Comment" column. Finally, it updates the | already have a "Comment" column. Finally, it updates the | |||
| registration request instructions.</t> | registration request instructions.</t> | |||
| <t>This document updates RFC 8447.</t> | <t>This document updates RFC 8447.</t> | |||
| </abstract> | </abstract> | |||
| <note removeInRFC="true"> | ||||
| <name>About This Document</name> | ||||
| <t> | ||||
| Status information for this document may be found at <eref target="https | ||||
| ://datatracker.ietf.org/doc/draft-ietf-tls-rfc8447bis/"/>. | ||||
| </t> | ||||
| <t> | ||||
| Discussion of this document takes place on the | ||||
| Transport Layer Security Working Group mailing list (<eref target="mailt | ||||
| o:tls@ietf.org"/>), | ||||
| which is archived at <eref target="https://mailarchive.ietf.org/arch/bro | ||||
| wse/tls/"/>. | ||||
| Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/tls/"/> | ||||
| . | ||||
| </t> | ||||
| <t>Source for this draft and an issue tracker can be found at | ||||
| <eref target="https://github.com/tlswg/rfc8447bis"/>.</t> | ||||
| </note> | ||||
| </front> | </front> | |||
| <middle> | <middle> | |||
| <?line 52?> | <?line 74?> | |||
| <section anchor="introduction"> | <section anchor="introduction"> | |||
| <name>Introduction</name> | <name>Introduction</name> | |||
| <t>This document instructs IANA to make changes to a number of the IANA | <t>This document instructs IANA to make changes to a number of the IANA | |||
| registries related to Transport Layer Security (TLS) and Datagram | registries related to Transport Layer Security (TLS) and Datagram | |||
| Transport Layer Security (DTLS). These changes update the changes made | Transport Layer Security (DTLS). These changes update the changes made | |||
| in <xref target="RFC8447"/>.</t> | in <xref target="RFC8447"/>.</t> | |||
| <aside> | <t>This specification adds a new value, "D" for discouraged, to the "Recom | |||
| <t>RFC EDITOR NOTE: Please remove the note that follows.</t> | mended" | |||
| </aside> | ||||
| <aside> | ||||
| <t>NOTE for IANA: This document specifies changes to the registry to upd | ||||
| ate | ||||
| the changes made in <xref target="RFC8447"/>.</t> | ||||
| </aside> | ||||
| <t>This specification adds a new value "D" for discouraged to the Recommen | ||||
| ded | ||||
| column of the selected TLS registries and adds a "Comment" column to all | column of the selected TLS registries and adds a "Comment" column to all | |||
| active registries that do not already have a "Comment" column.</t> | active registries that do not already have a "Comment" column.</t> | |||
| <t>This specication also updates the registration request instructions.</t > | <t>This specification also updates the registration request instructions.< /t> | |||
| </section> | </section> | |||
| <section anchor="terminology"> | <section anchor="terminology"> | |||
| <name>Terminology</name> | <name>Terminology</name> | |||
| <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14 >REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL | <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14 >REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL | |||
| NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECO MMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>", | NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECO MMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>", | |||
| "<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be i nterpreted as | "<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be i nterpreted as | |||
| described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they | described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they | |||
| appear in all capitals, as shown here.</t> | appear in all capitals, as shown here.</t> | |||
| <?line -18?> | <?line -18?> | |||
| <!-- [rfced] In the sentence below, is the intention to have consensus | ||||
| to leave one item or multiple items marked? | ||||
| Original: | ||||
| The IETF might have consensus to leave an items marked as "N" on the | ||||
| basis of its having limited applicability or usage constraints. | ||||
| Perhaps (Singular): | ||||
| The IETF might have consensus to leave an item marked as "N" on the | ||||
| basis of the item having limited applicability or usage constraints. | ||||
| Or (Plural): | ||||
| The IETF might have consensus to leave items marked as "N" on the | ||||
| basis of the items having limited applicability or usage constraints. | ||||
| --> | ||||
| </section> | </section> | |||
| <section anchor="updating-recommended-columns-values"> | <section anchor="updating-recommended-columns-values"> | |||
| <name>Updating "Recommended" Column's Values</name> | <name>Updating "Recommended" Column's Values</name> | |||
| <t>The instructions in this document update the Recommended column, | <t>The instructions in this document update the "Recommended" column, | |||
| originally added in <xref target="RFC8447"/> to add a third value, "D", | originally added in <xref target="RFC8447"/> to add a third value, "D", | |||
| indicating that a value is "Discouraged". The permitted values | indicating that a value is discouraged. The permitted values | |||
| of the "Recommended" column are:</t> | of the "Recommended" column are:</t> | |||
| <dl> | <dl> | |||
| <dt>Y:</dt> | <dt>Y:</dt> | |||
| <dd> | <dd> | |||
| <t>Indicates that the IETF has consensus that the | <t>Indicates that the IETF has consensus that the | |||
| item is <bcp14>RECOMMENDED</bcp14>. This only means that the associated | item is <bcp14>RECOMMENDED</bcp14>. This only means that the associated | |||
| mechanism is fit for the purpose for which it was defined. | mechanism is fit for the purpose for which it was defined. | |||
| Careful reading of the documentation for the mechanism is | Careful reading of the documentation for the mechanism is | |||
| necessary to understand the applicability of that mechanism. | necessary to understand the applicability of that mechanism. | |||
| The IETF could recommend mechanisms that have limited | The IETF could recommend mechanisms that have limited | |||
| applicability, but will provide applicability statements that | applicability but will provide applicability statements that | |||
| describe any limitations of the mechanism or necessary constraints | describe any limitations of the mechanism or necessary constraints | |||
| on its use.</t> | on its use.</t> | |||
| </dd> | </dd> | |||
| <dt>N:</dt> | <dt>N:</dt> | |||
| <dd> | <dd> | |||
| <t>Indicates that the item has not been evaluated by | <t>Indicates that the item has not been evaluated by | |||
| the IETF and that the IETF has made no statement about the | the IETF and that the IETF has made no statement about the | |||
| suitability of the associated mechanism. This does not necessarily | suitability of the associated mechanism. This does not necessarily | |||
| mean that the mechanism is flawed, only that no consensus exists. | mean that the mechanism is flawed, only that no consensus exists. | |||
| The IETF might have consensus to leave an items marked as "N" on | The IETF might have consensus to leave an items marked as "N" on | |||
| the basis of its having limited applicability or usage constraints.</t> | the basis of its having limited applicability or usage constraints.</t> | |||
| </dd> | </dd> | |||
| <dt>D:</dt> | <dt>D:</dt> | |||
| <dd> | <dd> | |||
| <t>Indicates that the item is discouraged. This marking could be used to identify | <t>Indicates that the item is discouraged. This marking could be used to identify | |||
| mechanisms that might result in problems if they are used, such as | mechanisms that might result in problems if they are used, such as | |||
| a weak cryptographic algorithm or a mechanism that might cause | a weak cryptographic algorithm or a mechanism that might cause | |||
| interoperability problems in deployment. When marking a registry entry as | interoperability problems in deployment. When marking a registry entry as | |||
| “D”, either the References or the Comments Column <bcp14>MUST</bcp14> include sufficient | "D", either the "Reference" or the "Comment" column <bcp14>MUST</bcp14> includ e sufficient | |||
| information to determine why the marking has been applied. Implementers and | information to determine why the marking has been applied. Implementers and | |||
| users <bcp14>SHOULD</bcp14> consult the linked references associated with the item to | users <bcp14>SHOULD</bcp14> consult the linked references associated with the item to | |||
| determine the conditions under which the item <bcp14>SHOULD NOT</bcp14> or <bc p14>MUST NOT</bcp14> be used.</t> | determine the conditions under which the item <bcp14>SHOULD NOT</bcp14> or <bc p14>MUST NOT</bcp14> be used.</t> | |||
| </dd> | </dd> | |||
| </dl> | </dl> | |||
| <t>Setting a value to "Y" or "D" or transitioning the value from "Y" or "D " in the "Recommended" column requires | <t>Setting a value to "Y" or "D" or transitioning the value from "Y" or "D " in the "Recommended" column requires | |||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" />. Not all items defined | IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" />. Not all items defined | |||
| in Standards Track RFCs need to be set | in Standards Track RFCs need to be set | |||
| to "Y" or "D". Any item not otherwise specified is set to "N". The column is | to "Y" or "D". Any item not otherwise specified is set to "N". The column is | |||
| blank for values that are unassigned or reserved unless specifically set.</t> | blank for values that are unassigned or reserved unless specifically set.</t> | |||
| <section anchor="rec-note"> | <section anchor="rec-note"> | |||
| <name>Recommended Note</name> | <name>Recommended Note</name> | |||
| <t>Existing registries have a note on the meaning of the Recommended col | <t>Existing registries have a note on the meaning of the "Recommended" c | |||
| umn. For the | olumn. For the | |||
| registries discussed in the subsequent sections this note is updated | registries discussed in the subsequent sections, this note is updated | |||
| with a sentence describing the "D" value as follows:</t> | with a sentence describing the "D" value as follows:</t> | |||
| <dl> | <blockquote> | |||
| <dt>Note:</dt> | <t>Note: If the "Recommended" column is set to "N", it does not necess | |||
| <dd> | arily mean | |||
| <t>If "Recommended" column is set to "N", it does not necessarily me | that it is flawed; rather, it indicates that the item has not | |||
| an | ||||
| that it is flawed; rather, it indicates that the item either has not | ||||
| been through the IETF consensus process, has limited applicability, or | been through the IETF consensus process, has limited applicability, or | |||
| is intended only for specific use cases. If the "Recommended" column | is intended only for specific use cases. If the "Recommended" column | |||
| is set to "D" the item is discouraged and <bcp14>SHOULD NOT</bcp14> or <bcp14>MU | is set to "D", the item is discouraged and <bcp14>SHOULD NOT</bcp14> or <bcp14>M | |||
| ST NOT</bcp14> be used, | UST NOT</bcp14> be used, | |||
| depending upon the situation; consult the item’s references for clarity.</t> | depending upon the situation; consult the item's references for clarity.</t> | |||
| </dd> | </blockquote> | |||
| </dl> | ||||
| </section> | </section> | |||
| </section> | </section> | |||
| <section anchor="tls-extensiontype-values-registry"> | <section anchor="tls-extensiontype-values-registry"> | |||
| <name>TLS ExtensionType Values Registry</name> | <name>TLS ExtensionType Values Registry</name> | |||
| <t>In order to reflect the changes in the Recommended column allocation, | <t>In order to reflect the changes in the "Recommended" column allocation, | |||
| IANA is requested to update the TLS ExtensionType Values registry as follows:</t | IANA has updated the "TLS ExtensionType Values" registry as follows:</t> | |||
| > | ||||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Adjust the registration procedure related to setting the “Recommend | <t>Adjusted the registration procedure related to setting the "Recomme | |||
| ed” column as follows:</t> | nded" column as follows: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>Add a reference to this document under the reference heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update the "Recommended" column with the changes as listed below. | <t>Updated the "Recommended" column with the changes listed below. En | |||
| Entries | tries | |||
| keep their existing "Y" and "N" entries except for the entries in following tabl | keep their existing "Y" and "N" entries except for the entries in the following | |||
| e. | table. | |||
| IANA is requested to add a reference to this document for these entries.</t> | IANA has added a reference to this document for these entries.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| <table> | <!-- [rfced] FYI - We have reordered the values in Table 1 to reflect | |||
| how they are listed in the "TLS ExtensionType Values" registry. | ||||
| --> | ||||
| <table> | ||||
| <thead> | <thead> | |||
| <tr> | <tr> | |||
| <th align="left">Value</th> | <th align="left">Value</th> | |||
| <th align="left">Extension</th> | <th align="left">Extension Name</th> | |||
| <th align="right">Recommended</th> | <th align="right">Recommended</th> | |||
| </tr> | </tr> | |||
| </thead> | </thead> | |||
| <tbody> | <tbody> | |||
| <tr> | <tr> | |||
| <td align="left">4</td> | <td align="left">4</td> | |||
| <td align="left">truncated_hmac</td> | <td align="left">truncated_hmac</td> | |||
| <td align="right">D</td> | <td align="right">D</td> | |||
| </tr> | </tr> | |||
| <tr> | <tr> | |||
| <td align="left">53</td> | ||||
| <td align="left">connection_id (deprecated)</td> | ||||
| <td align="right">D</td> | ||||
| </tr> | ||||
| <tr> | ||||
| <td align="left">40</td> | <td align="left">40</td> | |||
| <td align="left">Reserved</td> | <td align="left">Reserved</td> | |||
| <td align="right">D</td> | <td align="right">D</td> | |||
| </tr> | </tr> | |||
| <tr> | <tr> | |||
| <td align="left">46</td> | <td align="left">46</td> | |||
| <td align="left">Reserved</td> | <td align="left">Reserved</td> | |||
| <td align="right">D</td> | <td align="right">D</td> | |||
| </tr> | </tr> | |||
| <tr> | ||||
| <td align="left">53</td> | ||||
| <td align="left">connection_id (deprecated)</td> | ||||
| <td align="right">D</td> | ||||
| </tr> | ||||
| </tbody> | </tbody> | |||
| </table> | </table> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Update note on the Recommended column with text in <xref target="re c-note"/>.</t> | <t>Updated the note on the "Recommended" column with text in <xref tar get="rec-note"/>.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>For the truncated_hmac, add the following link to Reference column: | <t>For the truncated_hmac, added the following link to the "Reference" | |||
| https://www.iacr.org/archive/asiacrypt2011/70730368/70730368.pdf</t> | column: https://www.iacr.org/archive/asiacrypt2011/70730368/70730368.pdf</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>For the two Reserved values above, add the following link in the Re | <t>For the two Reserved values above, added the following link in the | |||
| ference column: | "Reference" column: https://mailarchive.ietf.org/arch/msg/tls-reg-review/5BD62HB | |||
| https://mailarchive.ietf.org/arch/msg/tls-reg-review/5BD62HBFjo_AsW-Y8ohVuWEe1gI | Fjo_AsW-Y8ohVuWEe1gI/</t> | |||
| /</t> | ||||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="tls-cipher-suites-registry"> | <section anchor="tls-cipher-suites-registry"> | |||
| <name>TLS Cipher Suites Registry</name> | <name>TLS Cipher Suites Registry</name> | |||
| <t>Several categories of ciphersuites are discouraged for general use and | <t>Several categories of cipher suites are discouraged for general use and | |||
| are marked as "D".</t> | are marked as "D".</t> | |||
| <t>Ciphersuites that use NULL encryption do not provide the confidentialit y | <t>Cipher suites that use NULL encryption do not provide the confidentiali ty | |||
| normally expected of TLS. Protocols and applications are often designed | normally expected of TLS. Protocols and applications are often designed | |||
| to require confidentiality as a security property. These | to require confidentiality as a security property. These | |||
| ciphersuites <bcp14>MUST NOT</bcp14> be used in those cases.</t> | cipher suites <bcp14>MUST NOT</bcp14> be used in those cases.</t> | |||
| <t>Ciphersuites marked as EXPORT use weak ciphers and were deprecated in | <t>Cipher suites marked as EXPORT use weak ciphers and were deprecated in | |||
| TLS 1.1 <xref target="RFC4346"/>.</t> | TLS 1.1 <xref target="RFC4346"/>.</t> | |||
| <t>Cipher suites marked as anon do not provide any authentication and are | <t>Cipher suites marked as anon do not provide any authentication, are | |||
| vulnerable to on-path attacks and are deprecated in TLS 1.1 | vulnerable to on-path attacks, and were deprecated in TLS 1.1 | |||
| <xref target="RFC4346"/>.</t> | <xref target="RFC4346"/>.</t> | |||
| <t>RC4 is a weak cipher and is deprecated in <xref target="RFC7465"/>.</t> | <t>RC4 is a weak cipher and is deprecated in <xref target="RFC7465"/>.</t> | |||
| <t>DES and IDEA are not considered secure for general use and are deprecat | <t>DES and the International Data Encryption Algorithm (IDEA) are not cons | |||
| ed | idered secure for general use and were deprecated in <xref target="RFC5469"/>. M | |||
| in <xref target="RFC5469"/>. Nor is MD5 or SHA-1 and these are deprecated in <xr | D5 and SHA-1 are also not secure for general use and were deprecated in <xref ta | |||
| ef target="RFC9155"/>.</t> | rget="RFC9155"/>.</t> | |||
| <t>In order to reflect the changes in the Recommended column allocation, | <t>In order to reflect the changes in the "Recommended" column allocation, | |||
| IANA is requested to update the TLS ExtensionType Values registry as follows:</t | IANA has updated the "TLS Cipher Suites" registry as follows:</t> | |||
| > | ||||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Adjust the registration procedure related to setting the “Recommend | <t>Adjusted the registration procedure related to setting the "Recomme | |||
| ed” column as follows:</t> | nded" column as follows: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>Add a reference to this document under the reference heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update the "Recommended" column with the changes as listed below. Entries | <t>Updated the "Recommended" column with the changes listed below. En tries | |||
| keep their existing "Y" and "N" entries except for the entries in following tabl e. | keep their existing "Y" and "N" entries except for the entries in following tabl e. | |||
| IANA is requested to add a reference to this document for these entries. This do | IANA has added a reference to this document for these entries. This document doe | |||
| cument does not | s not | |||
| make any changes to the DTLS-OK column.</t> | make any changes to the "DTLS-OK" column.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| <table> | <table> | |||
| <thead> | <thead> | |||
| <tr> | <tr> | |||
| <th align="left">Value</th> | <th align="left">Value</th> | |||
| <th align="left">Cipher Suite Name</th> | <th align="left">Description</th> | |||
| <th align="right">Recommended</th> | <th align="right">Recommended</th> | |||
| </tr> | </tr> | |||
| </thead> | </thead> | |||
| <tbody> | <tbody> | |||
| <tr> | <tr> | |||
| <td align="left">0x00,0x1E</td> | <td align="left">0x00,0x1E</td> | |||
| <td align="left">TLS_KRB5_WITH_DES_CBC_SHA</td> | <td align="left">TLS_KRB5_WITH_DES_CBC_SHA</td> | |||
| <td align="right">D</td> | <td align="right">D</td> | |||
| </tr> | </tr> | |||
| <tr> | <tr> | |||
| skipping to change at line 402 ¶ | skipping to change at line 414 ¶ | |||
| </tr> | </tr> | |||
| <tr> | <tr> | |||
| <td align="left">0xC0,0xB5</td> | <td align="left">0xC0,0xB5</td> | |||
| <td align="left">TLS_SHA384_SHA384</td> | <td align="left">TLS_SHA384_SHA384</td> | |||
| <td align="right">D</td> | <td align="right">D</td> | |||
| </tr> | </tr> | |||
| </tbody> | </tbody> | |||
| </table> | </table> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Update note on the Recommended column with text in <xref target="re c-note"/>.</t> | <t>Updated the note on the "Recommended" column with text in <xref tar get="rec-note"/>.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="tls-supported-groups-registry"> | <section anchor="tls-supported-groups-registry"> | |||
| <name>TLS Supported Groups Registry</name> | <name>TLS Supported Groups Registry</name> | |||
| <t>In order to reflect the changes in the Recommended column allocation, | <t>In order to reflect the changes in the "Recommended" column allocation, | |||
| IANA is requested to update the TLS Supported Groups registry as follows:</t> | IANA has updated the "TLS Supported Groups" registry as follows:</t> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Update the registration policy to include:</t> | <t>Updated the registration policy to include: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>Add a reference to this document under the reference heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update the "Recommended" column with the changes as listed below. Entries | <t>Updated the "Recommended" column with the changes listed below. En tries | |||
| keep their existing "Y" and "N" entries except for the entries in following tabl e. | keep their existing "Y" and "N" entries except for the entries in following tabl e. | |||
| IANA is requested to add a reference to this document for these entries.</t> | IANA has added a reference to this document for these entries.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| <table> | <table> | |||
| <thead> | <thead> | |||
| <tr> | <tr> | |||
| <th align="left">Value</th> | <th align="left">Value</th> | |||
| <th align="left">Curve</th> | <th align="left">Description</th> | |||
| <th align="right">Recommended</th> | <th align="right">Recommended</th> | |||
| </tr> | </tr> | |||
| </thead> | </thead> | |||
| <tbody> | <tbody> | |||
| <tr> | <tr> | |||
| <td align="left">1</td> | <td align="left">1</td> | |||
| <td align="left">sect163k1</td> | <td align="left">sect163k1</td> | |||
| <td align="right">D</td> | <td align="right">D</td> | |||
| </tr> | </tr> | |||
| <tr> | <tr> | |||
| skipping to change at line 518 ¶ | skipping to change at line 527 ¶ | |||
| </tr> | </tr> | |||
| <tr> | <tr> | |||
| <td align="left">21</td> | <td align="left">21</td> | |||
| <td align="left">secp224r1</td> | <td align="left">secp224r1</td> | |||
| <td align="right">D</td> | <td align="right">D</td> | |||
| </tr> | </tr> | |||
| </tbody> | </tbody> | |||
| </table> | </table> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Update note on the Recommended column with text in <xref target="re c-note"/>.</t> | <t>Updated the note on the "Recommended" column with text in <xref tar get="rec-note"/>.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Remove the "Elliptic curve groups" note from the registration | <t>Removed the "Elliptic curve groups" note from the registration | |||
| procedures table.</t> | procedures table.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>For each of the entries above, add the following link to the | <t>For each of the entries above, added the following link to the | |||
| Comment column: | "Comment" column: https://datatracker.ietf.org/meeting/118/materials/slides-118- | |||
| https://datatracker.ietf.org/meeting/118/materials/slides-118-tls-rfc8447bis-00< | tls-rfc8447bis-00</t> | |||
| /t> | ||||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="tls-exporter-labels-registry"> | <section anchor="tls-exporter-labels-registry"> | |||
| <name>TLS Exporter Labels Registry</name> | <name>TLS Exporter Labels Registry</name> | |||
| <t>This document updates the registration procedure for the TLS Exporter | <t>This document updates the registration procedure for the "TLS Exporter | |||
| Labels registry and updates the Recommended column allocation. | Labels" registry and updates the "Recommended" column allocation. | |||
| IANA is requested to update the TLS Exporter Labels Registry as follows:</t> | IANA has updated the "TLS Exporter Labels" registry as follows:</t> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Change the registration procedure from Specification Required to | <t>Changed the registration procedure from Specification Required to | |||
| Expert Review and update it to include:</t> | Expert Review and updated it to include: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>Add a reference to this document under the reference heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Entries keep their existing Recommended column "Y" and "N" entries< /t> | <t>Entries kept their existing "Recommended" column "Y" and "N" entrie s.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update note on the Recommended column with text in <xref target="re c-note"/>.</t> | <t>Updated the note on the "Recommended" column with text in <xref tar get="rec-note"/>.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update the note on the role of the expert reviewer as follows.</t> | <t>Updated the note on the role of the expert reviewer as follows.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| <dl> | <blockquote> | |||
| <dt>Note:</dt> | <t>Note: The role of the designated expert is described in <xref section | |||
| <dd> | ="17" sectionFormat="comma" target="RFC8447"/>. | |||
| <t>The role of the designated expert is described in <xref section="17 | ||||
| " sectionFormat="comma" target="RFC8447"/>. | ||||
| Even though this registry does not require a specification, the | Even though this registry does not require a specification, the | |||
| designated expert <xref target="RFC8126"/> will strongly encourage registrants | designated expert <xref target="RFC8126"/> will strongly encourage registrants | |||
| to provide a link to a publicly available specification. An | to provide a link to a publicly available specification. An | |||
| Internet-Draft (that is posted and never published as an RFC) | Internet-Draft (that is posted and never published as an RFC) | |||
| or a document from another standards body, industry consortium, | or a document from another standards body, industry consortium, | |||
| university site, etc. are suitable for these purposes. | university site, etc. is suitable for these purposes. | |||
| The expert may provide more in-depth reviews, but their approval | The expert may provide more in-depth reviews, but their approval | |||
| should not be taken as an endorsement of the exporter label. The | should not be taken as an endorsement of the exporter label. The | |||
| expert also verifies that the label is a string consisting of | expert also verifies that the label is a string consisting of | |||
| printable ASCII characters beginning with "EXPORTER". IANA <bcp14>MUST</bcp14> | printable ASCII characters beginning with "EXPORTER". IANA <bcp14>MUST</bcp14> | |||
| also verify that one label is not a prefix of any other label. | also verify that one label is not a prefix of any other label. | |||
| For example, labels "key" or "master secretary" are forbidden.</t> | For example, labels "key" or "master secretary" are forbidden.</t> | |||
| </dd> | </blockquote> | |||
| </dl> | ||||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Rename the Note column to Comment column.</t> | <t>Renamed the "Note" column to "Comment".</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="tls-certificate-types-registry"> | <section anchor="tls-certificate-types-registry"> | |||
| <name>TLS Certificate Types Registry</name> | <name>TLS Certificate Types Registry</name> | |||
| <t>In order to reflect the changes in the Recommended column allocation, | <t>In order to reflect the changes in the "Recommended" column allocation, | |||
| IANA is requested to update the TLS Certificate Types registry as follows:</t> | IANA has updated the "TLS Certificate Types" registry as follows:</t> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Adjust the registration procedure related to setting the “Recommend | <t>Adjusted the registration procedure related to setting the "Recomme | |||
| ed” column as follows:</t> | nded" column as follows: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>Add a reference to this document under the reference heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Entries keep their existing Recommended column "Y" and "N" entries. </t> | <t>Entries kept their existing "Recommended" column "Y" and "N" entrie s.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update note on the Recommended column with text in <xref target="re c-note"/>.</t> | <t>Updated the note on the "Recommended" column with text in <xref tar get="rec-note"/>.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="tls-hashalgorithm-registry"> | <section anchor="tls-hashalgorithm-registry"> | |||
| <name>TLS HashAlgorithm Registry</name> | <name>TLS HashAlgorithm Registry</name> | |||
| <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TL | <t>TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 w | |||
| S 1.2 will | ill | |||
| be in use for some time. In order to reflect the changes in the Recommended | be in use for some time. In order to reflect the changes in the "Recommended" | |||
| column allocation, IANA is requested to update the TLS HashAlgorithm Registry | column allocation, IANA has updated the "TLS HashAlgorithm" registry | |||
| as follows:</t> | as follows:</t> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Update the registration procedure to include:</t> | <t>Updated the registration procedure to include: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>Add a reference to this document under the reference heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update the TLS HashAlgorithm registry to add a "Recommended" column | <t>Updated the "TLS HashAlgorithm" registry to add a "Recommended" col umn | |||
| as follows:</t> | as follows:</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| <table> | <table> | |||
| <thead> | <thead> | |||
| <tr> | <tr> | |||
| <th align="left">Value</th> | <th align="left">Value</th> | |||
| <th align="left">Description</th> | <th align="left">Description</th> | |||
| <th align="right">Recommended</th> | <th align="right">Recommended</th> | |||
| </tr> | </tr> | |||
| skipping to change at line 689 ¶ | skipping to change at line 685 ¶ | |||
| </tr> | </tr> | |||
| <tr> | <tr> | |||
| <td align="left">8</td> | <td align="left">8</td> | |||
| <td align="left">Intrinsic</td> | <td align="left">Intrinsic</td> | |||
| <td align="right">Y</td> | <td align="right">Y</td> | |||
| </tr> | </tr> | |||
| </tbody> | </tbody> | |||
| </table> | </table> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Add note on the Recommended column with text in <xref target="rec-n ote"/>.</t> | <t>Added a note on the "Recommended" column with text in <xref target= "rec-note"/>.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="tls-signaturealgorithm-registry"> | <section anchor="tls-signaturealgorithm-registry"> | |||
| <name>TLS SignatureAlgorithm Registry</name> | <name>TLS SignatureAlgorithm Registry</name> | |||
| <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TL | <t>TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 w | |||
| S 1.2 will | ill | |||
| be in use for some time. In order to reflect the changes in the Recommended | be in use for some time. In order to reflect the changes in the "Recommended" | |||
| column allocation, IANA is requested to update the TLS SignatureAlgorithm regist | column allocation, IANA has updated the "TLS SignatureAlgorithm" registry | |||
| ry | ||||
| as follows:</t> | as follows:</t> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Update the registration procedure to include:</t> | <t>Updated the registration procedure to include: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>Add a reference to this document under the reference heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update the TLS SignatureAlgorithm registry to add a "Recommended" | <t>Updated the "TLS SignatureAlgorithm" registry to add a "Recommended " | |||
| column as follows:</t> | column as follows:</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| <table> | <table> | |||
| <thead> | <thead> | |||
| <tr> | <tr> | |||
| <th align="left">Value</th> | <th align="left">Value</th> | |||
| <th align="left">Description</th> | <th align="left">Description</th> | |||
| <th align="right">Recommended</th> | <th align="right">Recommended</th> | |||
| </tr> | </tr> | |||
| skipping to change at line 771 ¶ | skipping to change at line 764 ¶ | |||
| </tr> | </tr> | |||
| <tr> | <tr> | |||
| <td align="left">65</td> | <td align="left">65</td> | |||
| <td align="left">gostr34102012_512</td> | <td align="left">gostr34102012_512</td> | |||
| <td align="right">N</td> | <td align="right">N</td> | |||
| </tr> | </tr> | |||
| </tbody> | </tbody> | |||
| </table> | </table> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Add note on the Recommended column with text in <xref target="rec-n ote"/>.</t> | <t>Added a note on the "Recommended" column with text in <xref target= "rec-note"/>.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="tls-clientcertificatetype-identifiers-registry"> | <section anchor="tls-clientcertificatetype-identifiers-registry"> | |||
| <name>TLS ClientCertificateType Identifiers Registry</name> | <name>TLS ClientCertificateType Identifiers Registry</name> | |||
| <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TL | <t>TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 w | |||
| S 1.2 will | ill | |||
| be in use for some time. In order to refect the changes in the Recommended | be in use for some time. In order to reflect the changes in the "Recommended" | |||
| column allocation, IANA is requested to update the TLS ClientCertificateType Ide | column allocation, IANA has updated the "TLS ClientCertificateType Identifiers" | |||
| ntifiers | ||||
| registry as follows:</t> | registry as follows:</t> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Update the registration procedure to include:</t> | <t>Updated the registration procedure to include: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>Add a reference to this document under the reference heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update the TLS ClientCertificateType Identifiers registry to add a "Recommended" | <t>Updated the "TLS ClientCertificateType Identifiers" registry to add a "Recommended" | |||
| column as follows:</t> | column as follows:</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| <table> | <table> | |||
| <thead> | <thead> | |||
| <tr> | <tr> | |||
| <th align="left">Value</th> | <th align="left">Value</th> | |||
| <th align="left">Description</th> | <th align="left">Description</th> | |||
| <th align="right">Recommended</th> | <th align="right">Recommended</th> | |||
| </tr> | </tr> | |||
| skipping to change at line 873 ¶ | skipping to change at line 863 ¶ | |||
| </tr> | </tr> | |||
| <tr> | <tr> | |||
| <td align="left">68</td> | <td align="left">68</td> | |||
| <td align="left">gost_sign512</td> | <td align="left">gost_sign512</td> | |||
| <td align="right">N</td> | <td align="right">N</td> | |||
| </tr> | </tr> | |||
| </tbody> | </tbody> | |||
| </table> | </table> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Add note on the Recommended column with text in <xref target="rec-n ote"/>.</t> | <t>Added a note on the "Recommended" column with text in <xref target= "rec-note"/>.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="tls-pskkeyexchangemode-registry"> | <section anchor="tls-pskkeyexchangemode-registry"> | |||
| <name>TLS PskKeyExchangeMode Registry</name> | <name>TLS PskKeyExchangeMode Registry</name> | |||
| <t>In order to reflect the changes in the Recommended column allocation, | <t>In order to reflect the changes in the "Recommended" column allocation, | |||
| IANA is requested to update the TLS PskKeyExchangeMode registry as follows:</t> | IANA has updated the "TLS PskKeyExchangeMode" registry as follows:</t> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Update the registration procedure to include:</t> | <t>Updated the registration procedure to include: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>Add a reference to this document under the reference heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Entries keep their existing Recommended column "Y" and "N" entries. </t> | <t>Entries kept their existing "Recommended" column "Y" and "N" entrie s.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update note on the Recommended column with text in <xref target="re c-note"/>.</t> | <t>Updated note on the "Recommended" column with text in <xref target= "rec-note"/>.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="tls-signaturescheme-registry"> | <section anchor="tls-signaturescheme-registry"> | |||
| <name>TLS SignatureScheme Registry</name> | <name>TLS SignatureScheme Registry</name> | |||
| <t>In order to reflect the changes in the Recommended column allocation, | <t>In order to reflect the changes in the "Recommended" column allocation, | |||
| IANA is requested to update the TLS SignatureScheme registry as follows:</t> | IANA has updated the "TLS SignatureScheme" registry as follows:</t> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>Update the registration procedure to include:</t> | <t>Updated the registration procedure to include: </t> | |||
| <t> | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval <xref target="RFC812 | ||||
| 6"/>.</t> | ||||
| </li> | </li> | |||
| </ul> | ||||
| <artwork><![CDATA[ | ||||
| Setting a value to "Y" or "D" or transitioning the value from | ||||
| "Y" or "D" in the "Recommended" column requires | ||||
| IETF Standards Action with Expert Review or IESG Approval [RFC8126]. | ||||
| ]]></artwork> | ||||
| <ul spacing="normal"> | ||||
| <li> | <li> | |||
| <t>IANA is requested to add a reference to this document under the ref erence heading.</t> | <t>Added a reference to this document under the reference heading.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Entries keep their existing Recommended column "Y" and "N" entries. </t> | <t>Entries kept their existing "Recommended" column "Y" and "N" entrie s.</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Update note on the Recommended column with text in <xref target="re c-note"/>.</t> | <t>Updated note on the "Recommended" column with text in <xref target= "rec-note"/>.</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| </section> | </section> | |||
| <section anchor="adding-comment-column"> | <section anchor="adding-comment-column"> | |||
| <name>Adding "Comment" Column</name> | <name>Adding "Comment" Column</name> | |||
| <t>IANA is requested to add a "Comment" column to the following registries :</t> | <t>IANA has added a "Comment" column to the following registries:</t> | |||
| <ul spacing="normal"> | <ul spacing="normal"> | |||
| <li> | <li> | |||
| <t>TLS ExtensionType Values</t> | <t>TLS ExtensionType Values</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS Application-Layer Protocol Negotiation (ALPN) Protocol IDs</t> | <t>TLS Application-Layer Protocol Negotiation (ALPN) Protocol IDs</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS CachedInformationType Values</t> | <t>TLS CachedInformationType Values</t> | |||
| </li> | </li> | |||
| skipping to change at line 967 ¶ | skipping to change at line 951 ¶ | |||
| <li> | <li> | |||
| <t>TLS EC Curve Types</t> | <t>TLS EC Curve Types</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS Supplemental Data Formats (SupplementalDataType)</t> | <t>TLS Supplemental Data Formats (SupplementalDataType)</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS UserMappingType Values</t> | <t>TLS UserMappingType Values</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS Signature Algorithm</t> | <t>TLS SignatureAlgorithm</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS Hash Algorithm</t> | <t>TLS HashAlgorithm</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS Authorization Data Formats</t> | <t>TLS Authorization Data Formats</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS Heartbeat Message Types</t> | <t>TLS Heartbeat Message Types</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS Heartbeat Modes</t> | <t>TLS Heartbeat Modes</t> | |||
| </li> | </li> | |||
| skipping to change at line 995 ¶ | skipping to change at line 979 ¶ | |||
| <t>TLS PskKeyExchangeMode</t> | <t>TLS PskKeyExchangeMode</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS KDF Identifiers</t> | <t>TLS KDF Identifiers</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>TLS SSLKEYLOGFILE Labels</t> | <t>TLS SSLKEYLOGFILE Labels</t> | |||
| </li> | </li> | |||
| </ul> | </ul> | |||
| <t>This list of registries is all registries that do not already have a | <t>This list of registries is all registries that do not already have a | |||
| "Comment" or "Notes" column or that were not orphaned by TLS 1.3.</t> | "Comment" or "Note" column or that were not orphaned by TLS 1.3.</t> | |||
| <t>IANA is requested to rename the "Note" column to "Comment" column in | <!--[rfced] May we remove this sentence from the end of Section 14? | |||
| TLS Exporter Labels registry.</t> | This action is already listed in Section 7. | |||
| Original: | ||||
| IANA is requested to rename the "Note" column to "Comment" column in | ||||
| TLS Exporter Labels registry. | ||||
| --> | ||||
| <t>IANA has renamed the "Note" column to "Comment" in the | ||||
| "TLS Exporter Labels" registry.</t> | ||||
| </section> | </section> | |||
| <section anchor="expert-review-of-current-and-potential-ietf-and-irtf-docume nts"> | <section anchor="expert-review-of-current-and-potential-ietf-and-irtf-docume nts"> | |||
| <name>Expert Review of Current and Potential IETF and IRTF Documents</name > | <name>Expert Review of Current and Potential IETF and IRTF Documents</name > | |||
| <t>The intent of the Specification Required choice for TLS code points | <t>The intent of the Specification Required choice for TLS codepoints | |||
| is to allow for easy registration for code points associated with | is to allow for easy registration for codepoints associated with | |||
| protocols and algorithms that are not being actively developed inside | protocols and algorithms that are not being actively developed inside | |||
| IETF or IRTF. When TLS-based technologies are being developed inside | the IETF or IRTF. When TLS-based technologies are being developed inside | |||
| the IRTF/IETF they should be done in coordination with the TLS WG in | the IETF or IRTF, they should be done in coordination with the TLS WG in | |||
| order to provide appropriate review. For this reason, unless the TLS WG | order to provide appropriate review. For this reason, unless the TLS WG | |||
| chairs indicate otherwise via email, designated | Chairs indicate otherwise via email, designated | |||
| experts should decline code point registrations for documents which | experts should decline codepoint registrations for documents that | |||
| have already been adopted or are being proposed for adoption by IETF | have already been adopted or are being proposed for adoption by IETF | |||
| working groups or IRTF research groups.</t> | working groups or IRTF research groups.</t> | |||
| </section> | </section> | |||
| <section anchor="registration-requests"> | <section anchor="registration-requests"> | |||
| <name>Registration Requests</name> | <name>Registration Requests</name> | |||
| <t>Registration requests <bcp14>MUST</bcp14> be submitted in one of two wa ys:</t> | <t>Registration requests <bcp14>MUST</bcp14> be submitted in one of two wa ys:</t> | |||
| <ol spacing="normal" type="1"><li> | <ol spacing="normal" type="1"><li> | |||
| <t>By sending email to iana@iana.org; this email <bcp14>SHOULD</bcp14> | <t>By sending email to iana@iana.org; this email <bcp14>SHOULD</bcp14> | |||
| use an appropriate subject (e.g., "Request to register value in TLS | use an appropriate subject (e.g., "Request to register value in TLS | |||
| bar registry").</t> | bar registry").</t> | |||
| </li> | </li> | |||
| <li> | <li> | |||
| <t>Using the online form at | <t>Using the online form at https://www.iana.org/form/protocol-assignm | |||
| https://www.iana.org/form/protocol-assignment.</t> | ent.</t> | |||
| </li> | </li> | |||
| </ol> | </ol> | |||
| <t>Specification Required <xref target="RFC8126"/> registry requests are r egistered after | <t>Specification Required <xref target="RFC8126"/> registry requests are r egistered after | |||
| a three-week review period on the advice of one or more designated | a three-week review period on the advice of one or more designated | |||
| experts. However, to allow for the allocation of values prior to | experts. However, to allow for the allocation of values prior to | |||
| publication, the designated experts may approve registration once they | publication, the designated experts may approve registration once they | |||
| are satisfied that such a specification will be published.</t> | are satisfied that such a specification will be published.</t> | |||
| </section> | </section> | |||
| <section anchor="security-considerations"> | <section anchor="security-considerations"> | |||
| <name>Security Considerations</name> | <name>Security Considerations</name> | |||
| skipping to change at line 1047 ¶ | skipping to change at line 1038 ¶ | |||
| in cryptanalysis. Implementers and users need to check that the | in cryptanalysis. Implementers and users need to check that the | |||
| cryptographic algorithms listed continue to provide the expected level | cryptographic algorithms listed continue to provide the expected level | |||
| of security.</t> | of security.</t> | |||
| <t>Designated experts ensure the specification is publicly available. The y may | <t>Designated experts ensure the specification is publicly available. The y may | |||
| provide more in-depth reviews. Their review should not be taken as an | provide more in-depth reviews. Their review should not be taken as an | |||
| endorsement of the cipher suite, extension, supported group, etc.</t> | endorsement of the cipher suite, extension, supported group, etc.</t> | |||
| </section> | </section> | |||
| <section anchor="iana-considerations"> | <section anchor="iana-considerations"> | |||
| <name>IANA Considerations</name> | <name>IANA Considerations</name> | |||
| <t>This document is entirely about changes to TLS-related IANA registries. </t> | <t>This document is entirely about changes to TLS-related IANA registries. </t> | |||
| <t>IANA is requested to modify the note applied to all TLS Specification | <t>IANA has modified the note applied to all TLS Specification | |||
| Required registries instructing where to send registration requests as | Required registries instructing where to send registration requests as | |||
| follows:</t> | follows:</t> | |||
| <aside> | <!--[rfced] IANA provided the following note when they notified us that th | |||
| <t>RFC EDITOR: Please replace "This RFC" in the following with the RFC n | eir | |||
| umber | actions were complete: | |||
| assigned to this specification.</t> | ||||
| </aside> | NOTE: Some text at the end of the IANA Considerations section concerning reques | |||
| <t>Requests for assignments from the registry's Specification Required | t | |||
| range should be sent to the mailing list described in [This RFC, Section 16]. | submission needs to be removed or replaced. Details at the end of the list of | |||
| If approved, designated experts should notify IANA within three weeks. For | actions. | |||
| assistance, please contact iana@iana.org.</t> | ||||
| </section> | Per this note and to reflect what appears in the TLS-related IANA registries, | |||
| we have updated the text as shown below. Please let us know if any changes are | ||||
| needed. | ||||
| Original: | ||||
| Requests for assignments from the registry's Specification Required | ||||
| range should be sent to the mailing list described in [This RFC, | ||||
| Section 16]. If approved, designated experts should notify IANA | ||||
| within three weeks. For assistance, please contact iana@iana.org. | ||||
| Current: | ||||
| | Note: Requests for registration in the "Specification Required" | ||||
| | [RFC8126] range should be sent to iana@iana.org or submitted via | ||||
| | IANA's application form, per [RFC 9847]. IANA will forward the | ||||
| | request to the expert mailing list described in [RFC8447], | ||||
| | Section 17 and track its progress. See the registration procedure | ||||
| | table below for more information. | ||||
| --> | ||||
| <blockquote> | ||||
| <t>Note: Requests for registration in the "Specification Required" <xref | ||||
| target="RFC8126"/> | ||||
| range should be sent to iana@iana.org or submitted via IANA's | ||||
| application form, per [RFC 9847]. IANA will | ||||
| forward the request to the expert mailing list described in | ||||
| <xref section="17" sectionFormat="comma" target="RFC8447"/> and track its progre | ||||
| ss. See the registration | ||||
| procedure table below for more information.</t> | ||||
| </blockquote> | ||||
| <!-- [rfced] FYI - We have added an expansion for the following abbreviati | ||||
| on | ||||
| per Section 3.6 of RFC 7322 ("RFC Style Guide"). Please review each expansion | ||||
| in the document carefully to ensure correctness. | ||||
| International Data Encryption Algorithm (IDEA) | ||||
| --> | ||||
| <!-- [rfced] FYI - We have updated the following terms to the form on the | ||||
| right to match other documents in Cluster 430. Please let us know any objections | ||||
| . | ||||
| ciphersuite(s) > cipher suite(s) | ||||
| code points > codepoints | ||||
| --> | ||||
| <!-- [rfced] Please review the "Inclusive Language" portion of the online | ||||
| Style Guide <https://www.rfc-editor.org/styleguide/part2/#inclusive_language> | ||||
| and let us know if any changes are needed. Updates of this nature typically | ||||
| result in more precise language, which is helpful for readers. | ||||
| Note that our script did not flag any words in particular, but this should | ||||
| still be reviewed as a best practice. | ||||
| --> | ||||
| </section> | ||||
| </middle> | </middle> | |||
| <back> | <back> | |||
| <references anchor="sec-normative-references"> | <references anchor="sec-normative-references"> | |||
| <name>Normative References</name> | <name>Normative References</name> | |||
| <reference anchor="RFC8447"> | <xi:include href="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.844 | |||
| <front> | 7.xml"/> | |||
| <title>IANA Registry Updates for TLS and DTLS</title> | <xi:include href="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.211 | |||
| <author fullname="J. Salowey" initials="J." surname="Salowey"/> | 9.xml"/> | |||
| <author fullname="S. Turner" initials="S." surname="Turner"/> | <xi:include href="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.817 | |||
| <date month="August" year="2018"/> | 4.xml"/> | |||
| <abstract> | <xi:include href="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.812 | |||
| <t>This document describes a number of changes to TLS and DTLS IANA | 6.xml"/> | |||
| registries that range from adding notes to the registry all the way to changing | <xi:include href="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.434 | |||
| the registration policy. These changes were mostly motivated by WG review of the | 6.xml"/> | |||
| TLS- and DTLS-related registries undertaken as part of the TLS 1.3 development | <xi:include href="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.746 | |||
| process.</t> | 5.xml"/> | |||
| <t>This document updates the following RFCs: 3749, 5077, 4680, 5246, | <xi:include href="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.546 | |||
| 5705, 5878, 6520, and 7301.</t> | 9.xml"/> | |||
| </abstract> | <xi:include href="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.915 | |||
| </front> | 5.xml"/> | |||
| <seriesInfo name="RFC" value="8447"/> | <xi:include href="https://bib.ietf.org/public/rfc/bibxml/reference.RFC.899 | |||
| <seriesInfo name="DOI" value="10.17487/RFC8447"/> | 6.xml"/> | |||
| </reference> | ||||
| <reference anchor="RFC2119"> | ||||
| <front> | ||||
| <title>Key words for use in RFCs to Indicate Requirement Levels</title | ||||
| > | ||||
| <author fullname="S. Bradner" initials="S." surname="Bradner"/> | ||||
| <date month="March" year="1997"/> | ||||
| <abstract> | ||||
| <t>In many standards track documents several words are used to signi | ||||
| fy the requirements in the specification. These words are often capitalized. Thi | ||||
| s document defines these words as they should be interpreted in IETF documents. | ||||
| This document specifies an Internet Best Current Practices for the Internet Comm | ||||
| unity, and requests discussion and suggestions for improvements.</t> | ||||
| </abstract> | ||||
| </front> | ||||
| <seriesInfo name="BCP" value="14"/> | ||||
| <seriesInfo name="RFC" value="2119"/> | ||||
| <seriesInfo name="DOI" value="10.17487/RFC2119"/> | ||||
| </reference> | ||||
| <reference anchor="RFC8174"> | ||||
| <front> | ||||
| <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</titl | ||||
| e> | ||||
| <author fullname="B. Leiba" initials="B." surname="Leiba"/> | ||||
| <date month="May" year="2017"/> | ||||
| <abstract> | ||||
| <t>RFC 2119 specifies common key words that may be used in protocol | ||||
| specifications. This document aims to reduce the ambiguity by clarifying that on | ||||
| ly UPPERCASE usage of the key words have the defined special meanings.</t> | ||||
| </abstract> | ||||
| </front> | ||||
| <seriesInfo name="BCP" value="14"/> | ||||
| <seriesInfo name="RFC" value="8174"/> | ||||
| <seriesInfo name="DOI" value="10.17487/RFC8174"/> | ||||
| </reference> | ||||
| <reference anchor="RFC8126"> | ||||
| <front> | ||||
| <title>Guidelines for Writing an IANA Considerations Section in RFCs</ | ||||
| title> | ||||
| <author fullname="M. Cotton" initials="M." surname="Cotton"/> | ||||
| <author fullname="B. Leiba" initials="B." surname="Leiba"/> | ||||
| <author fullname="T. Narten" initials="T." surname="Narten"/> | ||||
| <date month="June" year="2017"/> | ||||
| <abstract> | ||||
| <t>Many protocols make use of points of extensibility that use const | ||||
| ants to identify various protocol parameters. To ensure that the values in these | ||||
| fields do not have conflicting uses and to promote interoperability, their allo | ||||
| cations are often coordinated by a central record keeper. For IETF protocols, th | ||||
| at role is filled by the Internet Assigned Numbers Authority (IANA).</t> | ||||
| <t>To make assignments in a given registry prudently, guidance descr | ||||
| ibing the conditions under which new values should be assigned, as well as when | ||||
| and how modifications to existing values can be made, is needed. This document d | ||||
| efines a framework for the documentation of these guidelines by specification au | ||||
| thors, in order to assure that the provided guidance for the IANA Considerations | ||||
| is clear and addresses the various issues that are likely in the operation of a | ||||
| registry.</t> | ||||
| <t>This is the third edition of this document; it obsoletes RFC 5226 | ||||
| .</t> | ||||
| </abstract> | ||||
| </front> | ||||
| <seriesInfo name="BCP" value="26"/> | ||||
| <seriesInfo name="RFC" value="8126"/> | ||||
| <seriesInfo name="DOI" value="10.17487/RFC8126"/> | ||||
| </reference> | ||||
| <reference anchor="RFC4346"> | ||||
| <front> | ||||
| <title>The Transport Layer Security (TLS) Protocol Version 1.1</title> | ||||
| <author fullname="T. Dierks" initials="T." surname="Dierks"/> | ||||
| <author fullname="E. Rescorla" initials="E." surname="Rescorla"/> | ||||
| <date month="April" year="2006"/> | ||||
| <abstract> | ||||
| <t>This document specifies Version 1.1 of the Transport Layer Securi | ||||
| ty (TLS) protocol. The TLS protocol provides communications security over the In | ||||
| ternet. The protocol allows client/server applications to communicate in a way t | ||||
| hat is designed to prevent eavesdropping, tampering, or message forgery.</t> | ||||
| </abstract> | ||||
| </front> | ||||
| <seriesInfo name="RFC" value="4346"/> | ||||
| <seriesInfo name="DOI" value="10.17487/RFC4346"/> | ||||
| </reference> | ||||
| <reference anchor="RFC7465"> | ||||
| <front> | ||||
| <title>Prohibiting RC4 Cipher Suites</title> | ||||
| <author fullname="A. Popov" initials="A." surname="Popov"/> | ||||
| <date month="February" year="2015"/> | ||||
| <abstract> | ||||
| <t>This document requires that Transport Layer Security (TLS) client | ||||
| s and servers never negotiate the use of RC4 cipher suites when they establish c | ||||
| onnections. This applies to all TLS versions. This document updates RFCs 5246, 4 | ||||
| 346, and 2246.</t> | ||||
| </abstract> | ||||
| </front> | ||||
| <seriesInfo name="RFC" value="7465"/> | ||||
| <seriesInfo name="DOI" value="10.17487/RFC7465"/> | ||||
| </reference> | ||||
| <reference anchor="RFC5469"> | ||||
| <front> | ||||
| <title>DES and IDEA Cipher Suites for Transport Layer Security (TLS)</ | ||||
| title> | ||||
| <author fullname="P. Eronen" initials="P." role="editor" surname="Eron | ||||
| en"/> | ||||
| <date month="February" year="2009"/> | ||||
| <abstract> | ||||
| <t>Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (R | ||||
| FC 4346) include cipher suites based on DES (Data Encryption Standard) and IDEA | ||||
| (International Data Encryption Algorithm) algorithms. DES (when used in single-D | ||||
| ES mode) and IDEA are no longer recommended for general use in TLS, and have bee | ||||
| n removed from TLS version 1.2 (RFC 5246). This document specifies these cipher | ||||
| suites for completeness and discusses reasons why their use is no longer recomme | ||||
| nded. This memo provides information for the Internet community.</t> | ||||
| </abstract> | ||||
| </front> | ||||
| <seriesInfo name="RFC" value="5469"/> | ||||
| <seriesInfo name="DOI" value="10.17487/RFC5469"/> | ||||
| </reference> | ||||
| <reference anchor="RFC9155"> | ||||
| <front> | ||||
| <title>Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS | ||||
| 1.2</title> | ||||
| <author fullname="L. Velvindron" initials="L." surname="Velvindron"/> | ||||
| <author fullname="K. Moriarty" initials="K." surname="Moriarty"/> | ||||
| <author fullname="A. Ghedini" initials="A." surname="Ghedini"/> | ||||
| <date month="December" year="2021"/> | ||||
| <abstract> | ||||
| <t>The MD5 and SHA-1 hashing algorithms are increasingly vulnerable | ||||
| to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digita | ||||
| l signatures. However, this document does not deprecate SHA-1 with Hashed Messag | ||||
| e Authentication Code (HMAC), as used in record protection. This document update | ||||
| s RFC 5246.</t> | ||||
| </abstract> | ||||
| </front> | ||||
| <seriesInfo name="RFC" value="9155"/> | ||||
| <seriesInfo name="DOI" value="10.17487/RFC9155"/> | ||||
| </reference> | ||||
| <reference anchor="RFC8996"> | ||||
| <front> | ||||
| <title>Deprecating TLS 1.0 and TLS 1.1</title> | ||||
| <author fullname="K. Moriarty" initials="K." surname="Moriarty"/> | ||||
| <author fullname="S. Farrell" initials="S." surname="Farrell"/> | ||||
| <date month="March" year="2021"/> | ||||
| <abstract> | ||||
| <t>This document formally deprecates Transport Layer Security (TLS) | ||||
| versions 1.0 (RFC 2246) and 1.1 (RFC 4346). Accordingly, those documents have be | ||||
| en moved to Historic status. These versions lack support for current and recomme | ||||
| nded cryptographic algorithms and mechanisms, and various government and industr | ||||
| y profiles of applications using TLS now mandate avoiding these old TLS versions | ||||
| . TLS version 1.2 became the recommended version for IETF protocols in 2008 (sub | ||||
| sequently being obsoleted by TLS version 1.3 in 2018), providing sufficient time | ||||
| to transition away from older versions. Removing support for older versions fro | ||||
| m implementations reduces the attack surface, reduces opportunity for misconfigu | ||||
| ration, and streamlines library and product maintenance.</t> | ||||
| <t>This document also deprecates Datagram TLS (DTLS) version 1.0 (RF | ||||
| C 4347) but not DTLS version 1.2, and there is no DTLS version 1.1.</t> | ||||
| <t>This document updates many RFCs that normatively refer to TLS ver | ||||
| sion 1.0 or TLS version 1.1, as described herein. This document also updates the | ||||
| best practices for TLS usage in RFC 7525; hence, it is part of BCP 195.</t> | ||||
| </abstract> | ||||
| </front> | ||||
| <seriesInfo name="BCP" value="195"/> | ||||
| <seriesInfo name="RFC" value="8996"/> | ||||
| <seriesInfo name="DOI" value="10.17487/RFC8996"/> | ||||
| </reference> | ||||
| </references> | </references> | |||
| </back> | </back> | |||
| <!-- ##markdown-source: | <!-- ##markdown-source: | |||
| H4sIAAAAAAAAA+087XIbN5L/8RQ45sfaVyQlUpQsKblsJJGOtZZlnyjH50ql | H4sIAPDdA2kAA+09a3PbNrbf8Suw6ofaO5JsyfKznbaOrTTeOk6u5bSb6WQ8 | |||
| VOAMSE40HMwCM6KZyKm8xlXdVd2z3KPkSa67gZnB8EOSc065smtXYksYoNHd | EAlJrCmSS5BW1Dr/5f6W+8vueYAkqJed9DFze+PZaWwQj4OD88bB2VarJbIg | |||
| 6E80gFarxbIoi+UhPz06P+IXchKZTC/46zQUmTR8rDS/PBtykYS8Dz8wMRpp | C/WJvDi9OpXXehyYLJ3LN4mvMm3kKE7lzeVAqsiX5/CLUMNhqu9Pao2rxwo/ | |||
| eXPIH/UfY/vaUSxUQSJmADTUYpy1IpmNW1lsWnoc7Pd6T0aRaXV2mclHs8iY | 9iI1han9VI2yVqCzUSsLTSsdeUe93uEwMK0QO2YiyqdDnZ7I46PeoYiHJg41 | |||
| SCXZIkUMBpdPWQAAJkovDrnJQpZbgIcchzGYdoexKNWHPNO5ybrb2wfbXSa0 | tJ+InGc6kdhfmHw4DYwJ4iibJwhx/+a58KDDOE7nJ9JkvgDA9kSQwFRZmpus | |||
| FIe8MZRBrqNs0WBzpa8nWuUptF5qkZhU6YyfiYXUvOp1LRfQMYR5k0zqRGat | u7t7vNsVKtXqRA76Z2IWp3fjNM4T2oC403No8U+EwHVOZHe3u9/q7AovjoyO | |||
| PmLLbmSSy0PG+f0gOLeYN97AjFEy4d/iEGyfiSiGdiD6G6S+rfQEm4UOptA8 | TG5oHi1MBlu9VWEcQac5bM1MVZrd/iePCbooFklwIn/OYq8pTZxmqR4Z+G0+ | |||
| zbLUHG5tYS9sim5ku+i2hQ1bI63mRm7B+C0cN4myaT6yAOeTrYqPDcZMBotz | xV/eCaHybBKnJ0K2hISfIIJB/2rLAcw403NqY0z9K9a11jgdqyj4VWWw6RP5 | |||
| JWKVACYL4L6ZCZ1d/T1XxLlEsTQ65N9nKmhyA1RoOTbw02KGP/zAmMizqdJA | o47UKKAPeqqC8ET+EuvvDPdvRzqrLTBoy5s8jXTqzD/QKnJb6/ObaC/13ekN | |||
| cAsm4jxKYNDf2nwIEOdyQW12Mf+mZK0VkBVJ9JPIYAUP+XcyEeOIPkhL/Y9K | dP+OWttePBUiitMp9L3XgLEgGjl/tVotqYZw/MrLhPj6H/Dnz3DO2n8nrwBJ | |||
| fmNs/zawtzbBsM0vc2C69uAPpUj81jp8k+zo0AdvoPs31NoO1IyxROkZ9L2B | MpuoTM60nKh7LflYfWjU0gBiMkk02JSzSeBNpEoSrVIDu8AeIs2jKIjGcqKV | |||
| tWNRMvZ+a7VaXIxAQkWQMXY5jQwHCc1nMsm4kzCeTSUPpiKZ4M+qJvNWyLUV | r1PbKl+fP5dxniV51pQK6TQELJi2fB1qZbQEApK5kXdRPAMynct4+Iv2cJem | |||
| 8ggYPBOhBDL4xdMTEsw2P824CEPDBU/knN+IOJe80W+Q+oSRCVSuxUSGDCDj | LcSrNBgHkQrhQLbOt9cTsDjL01RHGfR7Arm3Wt8s7NzCAqehYY8IhiU4I7eG | |||
| RBcSMIbpQxnyQMX5LOFqTF+MjGWQQTPOW02JuDA3Q+OExmaNYigAFXHMgTgg | eh5HiILYWOzwtov9EUa2BfJfDj3iSE6yLDEnOzuz2awNC7S0H2Rx2oYj3IFz | |||
| 1x+UTUUGlIIIZEzEoCXhgk8F9FkF0uZPowSgLJo8qjGFOXi0CgD877k0Ga4h | Sr1JWy6D8PzthWzJn7ScBWEo/ZjmZmQhTmcTHeGxAMHfI4z0NQhh+VhePz/7 | |||
| aGCAbaa9iaUle+wKzKIwjCVjX6DCaRXa4cuDC8jGch1om4nr2tIAj/PZCPTQ | 98tLPFu7RZnqUN+rKJNvri8NdhnCyDDw7tQw1AXgL25eXhKqqhNahZtn2lM5 | |||
| sQz7MY9qLWOBHMRV3KC5/BGw97FdYJGJiRYztrkvysBjkNepNBUilsia2KBY | bT0wAJeXTwHRljIMrk0835QJ4VCAzAn0jBbQaaoyBcAkQDlARYiior8UWxvQ | |||
| gOTxn3/+FyAdKX//Hmj/SpgI5AWU8jpU8+TfGqNYBdeNr0GWkUOD/unlywt+ | xCN3rPzZFgilSyjBSM7jHJExCtIpAJ/KOAkioBo+oQj4X8YjhGKKQqVCSMaI | |||
| /vJycMhfxVIYXMOZurHAYe2kXcixikGXgN1fbRHEr+8EjfBI/JA9h7zOZJPK | hZEZboP6OPtqMwJuVu6VBk5UNNammGeZ2lKmtgDobApsgMgu9tyWF0A8PhCV | |||
| IBojszy+4my6sOTwu6UQbdwSjZxo9EisEKJpHPTAisxD9IKv6gV7sF7wu/WC | khHg6F6FOfBS47xBqPED48FO1Fj7TWHnb1xr4GeAwtd+A6AO82lkNwY8HwKn | |||
| 3akX/D698GkqKIqNqtmNh6jIF/xS6lmUqFhNFghUcnBAHD2Q4Y0Xr4eXjab9 | AF5x7WpZhEfYVRpnNDgrh8K0CsgLeB+kgTuI0AZUF8WZUCGIYX/OImB5krZ8 | |||
| F5cOf74Y/Pvr04tBH38ePjs6Oyt/YK7H8NnL12f96qdq5MnLFy8G5307GFp5 | jjwZzpsyqCFH2PlISMHk/8lBZSBTgWguWXo1aksUsYCaBr4faiG+kBdRlsY+ | |||
| rYk1Xhy9hS/IvMbLV5enL8+Pzhq4rFlNTMCxIhNHuOLgIlMtcQUE+HdpAh2N | D18cXMxsGPOwt6m6qx0R4JkUVoEy7CecXQNZsHyL5U2qIoOEKi/VHEYMtJen | |||
| 4BcYc3zy6n//p9NzYt/tdA7evy90oPOkB7/MpzKxs6kkXrhfgXELJtJUCo1Q | QTaXW4DebT5koMlxqqZifV+kg20Q5xNtKkB4kzXyQdIAwSx/++0fsHXc+YcP | |||
| 0IIFIo0y4C70BY5PQaL5VGoJ3PvX75EzPxzyr0ZB2ul97RqQ4FpjwbNaI/Fs | BXJMor1gFHiMxqfRi1xFL+LJ9CI304vYSC/yMXpZva/QxDXOegrxfCFvdDoN | |||
| tWVlsGXimqY105TcrLUvcbqO79Hb2u8F373Gr/4aR4nkrc7+X0GXQGQonsK4 | ojiMx3OcVqOgliypGy/fDG4aTf5XXr2i36/7//Xm4rp/jr8PXpxeXpa/CNtj | |||
| ouFpRoOfkGj+xfDvUKGMlSZf3laX0jNXq86nyZSOJtb+ozbZdfVUnFQphKVH | 8OLVm8vz6rdq5Nmrly/7V+c8GFplrUk0Xp6+hS+Ivsar1zcXr65OLxssXF0q | |||
| qDq0itxETW6CwQtJMQBL0ivh1Bxmb/QrFW+QAeUpKkGGYnRjcXf6XSfQKTDI | RfHDEjgAmZMmqcYzUGB1aeOlwRD+gDHPzl7/z393epYgup3O8YcPBXV0Dnvw | |||
| H3jvt4cMYzSapVBesvsQLoLagg0DimVi8uqbjTMyOUMsvAVpWztIUjiD8MGD | B2oAXi2Owrn9ExA3F5U+Qt72VBJkgF3StqC0Z6CQdKoBe//8GTHz7kR+PfSS | |||
| JoxRQYSOgwbPJFq8yBCEcZSRxcJ+aa5TBSYaf59Po2CK/nIOWIRyDIsXtmn4 | Tu8b24AbrjUWOKs1Es6WW5YGMxJXNK1YpsRmrX0B03V4T9/W/i7w7jR+/W0Y | |||
| CaA+zmOOtgU546gslsNaigKkP5cNh2QgjRHODANLNMV4Fs80jYEToyhG30Rw | gPRvdY6+BUle12UXkeUElP6ehkMB9QpijCkwIJ1ASiRmYi7NS5THoN/uUb9D | |||
| gYIShJ3+smAPcD8OAQvH26qfo5ysXhzBkji6a+CbfJQDcRGoZqrVDbqa+vSA | x0yD0knlNA+zIAm5AZk6vdP+t47ZItFGQypFCxik2niSLUwsy4nB3nOnwdNr | |||
| FjAZCLLgCEJhG0DfFxa0sDLpeFBRC+RXlOIiggkFQ2N5APyJAGxuUP3PN4gA | XDVkzLYVzDNUBgAFZg5A4sEsaBaEwTQgckoSUO9qGIQohsgUAblAywBLwcaQ | |||
| LTGKAFrykZQJlyhW5P5HNkgtJcUycFl2yJ8lqqIEAkWVV0JkcsDfZ7YvKR7b | e17rdKISMGkGMDQPVbr9KQA+Dh/hEnt+CpCvUrn1OgSxFn4cdE/EXQHbJ2GQ | |||
| CwcrLS4FXVG8cOIkkmr2unDFYi7DphVK6gLoVCIt34FrMUvLOosmU7d4nvAr | bIMv2MjCsXXtfEbS7ksjf0Q5bVg8uQJsWTY4mmGVpm+K2FISMDyIaBYVv/1W | |||
| DtEDerGEGGMoLiCDDT6gAROUDBmBv6YFQRYDGBRRJwXLAqZhCUB//fWBBenf | qgySzz4Aj/OmvqMhmqBdfJK1ACdbrfwVid3RHKSrZIJSNUM03DPsFlMrzQ8Q | |||
| tSDIiErxHWsQF5zGSiSIB6ws+X2QqiSLxou62jmYllAtTR6jR0UxHMVIWkRr | aGBrvj0R4NjxGoU+yIqjmsABOGdkv7HHg4QBMDgcjjDg6aBYm4Ij48ymjIm9 | |||
| sSAXhZAgoclBF4UVHsHnUlzzQC/STEF0l4KigoeBvBLyKBI84S2CN1MgAJjL | AHU0DZ5qVKCBoRlGYH2gHsR+SZ4maJ/j3+ybwMcZQOHrEUgDv03DzwD0UR5K | |||
| UsDjKTBXBSeqqROQ8TRWCxSXNn8D3qykTlQRFHyEvx1Cv/36X/3ffv3vJpeA | VFeIF7vL4jhY9RRTumuxY6Y9bYwCRwKwngNKUvI2Gc469Yx4B+UUvHxJyYD8 | |||
| gNTODo/BuSUgKNwZAhd7GGfgObm4KAniHITU5GOIqSL47vBzGY6iQCcE14zh | 0AcoLG6rfnbnROOWMGlkffphnrGXkKTxfeAvrg5QAY5hPzwbTVDoGvJtaGbF | |||
| hQSjtLBC5lBCKSfVoIXF9TidpTHJOtgVSiwQHtANvzl/h4uNHEc44JJQiHSF | JGlRUG0Wdl9t1KF+9kIjEj7gDgCnXq2hAMv6hmyDoQa/RSNVkaE1ZG+5JBTG | |||
| racAcyCnWvhMOQtQ4EKRowIxsRaATJmzmuWgysUiGwqvXkgIyNpQZpnlrXUs | 3yLpkOEcxdVOwGMFB6WkIZMD/C6uXUJxsC6tvagZlmJfQTi31KSiavU6bYVq | |||
| QG3jbQM7YySJrMPInaawTki6jmOtZn5XcoobXA1GbRHIGSP9GqK5FRiZHZFD | hmYV0aR1KRyK1u/BVDELp/qJ4r1EyO+W7+ebDmSZ7QOGBZdhggTygJMlaxio | |||
| tXQO3oE4ZLBuNxEEsxhaD4bf8qMUbaOIy5CnuwcxMT+n2DJ2muicA2YHFWzI | CjThaF7nOjsnbzTVBtQfCiQgQ3Ar4WtAZzEnkwdnasJJYZiAiUeB/6rupJfO | |||
| OIJrzAHAZkirDCOMdDNWI7HNj8CSEq/QtCgUoHkELqiI4kPUOBhGnDl3jtbR | kywGOzoBPgWLZQwyLpsQ4SnnEJyVyP+04RKwoGKQVgUmqqUjoPEkjOfkxcmf | |||
| BR5lFIvkmpyNdbnOTaPiJLCU0QQQw6mAeqlv4Oc8icF4VWE8RgUAHoPYL2rR | 0F0udqcK23Iu4SP81wKEYlJqWFynhbQbgaUEhkFDWiGwZBCTwRREXpgDiZp8 | |||
| wznmJj9/Ae6lhWnKe8YGaK1wFbxo20XWlMioxBlAkXhucTUigXTU6oSf2KFR | BPZsAN8tdDbQwhaED4YeGqvg0k/mTGIWIKRxYgw6VjyNiymYEbgQCBVy4HA+ | |||
| yY2x0QklBfnIYLSNGY10kQ+FPTRXVCRpIaPlE9AJZB5EuPBRhbigcFiREaZI | 2DX8Za0nPGrEN84DBg6SUFqAa1zyn8GGqmPPYsv/BSzW+wVfm/if5JgVmeWg | |||
| syDwQPLgHzB04/VCU2M7Jc7rHABRy4jp0KO0+F9ySBhgKWlctMGUOnPhXBwj | ymBDPBQ2YkEfQGkDnWWMWdYpsNvGW0IaOieIO/SQaAnWP9p2HKXx1O1qQxEr | |||
| Pc6mWuWTaeXHKhcAkojTNmnAWoMOfkazyJB5I36T20HhKJYb1Q7soJGmzZHy | 9Qz6AAFQmSDuGqCsVWjnn5I25X323ycYDbnmoANMetEffC9PE5SMKiwN6O4B | |||
| TSrDPOqBfxusP7ndu1W8CelECqBxNfLUSQjoc07G7cuaMcIZfvv1P41vjhD5 | uFcY3yILmfnQagb0wqq5wbPz7tAbBYmhmRWGaC9morbFtjwFOUq4QsESIwnN | |||
| IBaYq7cpasYUcfAO6MOtxctFKl2cXO5TMnYKiaVGYwTYAyjMLWtprhOwNfs0 | AtA/1sdBRW1wGGHmqsFa1u4L1MkwVNEdaRrWt1ZDI9tEcJTBGADDpWD3Or2H | |||
| oA3K5oFNRjsUkSlSPqvCXqS9EZHSSdTkrcWPwh9zk63mlLSuYa6lv7lhnF3E | 3/MoBNFVuVBoEMD06BJ9IR3kcQzvty9At7QAMv1BiD7KKjwFx3uznhr2sEYS | |||
| 3uBfPFzB05To+hP88ssvZKD/XxaVIHyoVcUxv9+yfu/s6g9tIoEYFZKvdUJg | CUNHJ646EXD8mS1cFxqFSm4MmyZkXOdDg94bSG1jI3lNNntouaDwh31BJ6gq | |||
| 9w9q+Q65GsvIotPUBuO4HeV2qjdjXjq2QiJIoWiNRxLYCboxSOxuIIdEXqbY | a9wqqYJikD6YaqqwIRgev51QNPeD+IY2CxJvg61SOwWKV6zSBrR5QWcAPUrx | |||
| OdI2XKOMDThE+TVEXtL2hI+BTKtUomiOErdGxGwBUQaGe2uFS9xHt4NtSuhA | /5UEbxROlsYFmxWdIH7OJmmcjyeVNqsUAVAkrtekASvFOmibVASG3RA8S1I+ | |||
| 7S1JHb+tZJHf8+e2Jvm37PawhX/cP/f8ufV/OYTBPQAIqWmCBi68ms5EsG7G | SCTFsVOA0VNGm7bctG3hbBtl3BolQNp3M683wUtNYG48kzyxpAKMnZOU+6om | |||
| 4k8f59vd4beg94m16ldRyB+BkQBHgyAerx3S2+a3F4UL20hXfcjehw6pJMd3 | lXCFL40rlRB2D/wM2BxQKnrvlwNgWdge3g3czBNtbeUyRisEuGjgzaNEjnEq | |||
| Z2vMhJUf+S6zmXTpIt+T9DnnxutcadLyYnslDhh94SqXwaKb4JAVNYT5fN6O | DFnUIiebJAawRczhhaagkBDi2o1hN9YB0KhURI3YWvLU/yU3xfhajIJO1M85 | |||
| RKDL2kF0I3E/TlD0293udLaebD/Z2d7Z2y9/aKfhuIbHHGdwjHBRAuRBN3Ij | uliEkYyVjOthdKdH0fy7ZCnrsY+Upzjm02Xqz1aivmszepBSVXXqHImqOTmk | |||
| SqWB3ITW5tLGzEy2qBgkJ/A/avzW7nF/r/vs+OmP6urIvGm93VfT7/I3A9mZ | Yhh9RacJW+DtKmbtrwe81GgFDYQBnQh578AJ/YjjrVLeaZ1gzyBlE42cNMAO | |||
| nG6VJv0kStEXDiEjq9nyobyBKB13j6hyhBoFcUVAvY3tjMGO75RQSyYyoWHo | xWjA2tLcEz56Oqm8h6LZYq+KumcYL0czr6Qm9fh+7aymnLe9LtRPYjjVRO8W | |||
| 7mh3XUs/YYK4i7ETHwh5Zux9/vrsDNSL+IvK5HYSixTZBb1jm9gI9Lq2NoFx | AVYfACQ3FKvvOHwgJvGsMrAsEooTf5yyrf/6QO3yoeotr9RUy/U/DzUN8yAe | |||
| lARLR/uYgCIQ1eavtMoUMM9tZVpfbUMZxEiNQWUxXqEwjZG7Ipu6PAUijRGO | Tlr4Y/955OfB/eMEBvdgQnCJIxSm/u1kqrxVKxY/57heb1c+XBeqcC2Q9SEH | |||
| 27ROKXcBj2i3rVmNHcse2K6mKv3+EuEVVwb/8erlxSUxwSZYthuhPpfI5FJJ | Hz1kf08+gDyLWGndBr7cAuEHmhQB3V41ZIF4XXW6gZD1+4zd+FJJfyA+sMpV | |||
| ASbDVeu0Oy4y7u309kj+3UKuQBfJKjNxEwELVEhnsf2KfNKS3eQxriCYS1QQ | 1pHTtCRXJ0y0AJ2Yb2m28kIntSuoQHl8q4JXT8G93gE/Q5EV3t3tdHYOdw/3 | |||
| lbRSgVFelkFUbYpedYy4w4gtYXRx0kNTK3yqCAKa1hoAO/BJb2+XBvYHtkx0 | dvcOjspf2ok/qsEzi2WJSkuf4I/d6w2gVXJoLWh4cWkhauONcwniztSMd+j6 | |||
| 2h8c0XSIOwYsgLuGEbQecp28LSFX1Q12e3sHNoHQOP2L/i46xOGzo1bH7WGg | WY9bfJ20s//s/KD74tnzX+LbU/NT6+1RPPkx/6mvO+OLnVKznAUJmvID8A5r | |||
| dV8lzY4+6OxazD5HOJ8jnH+SCGepuFXkYFSFv7YmZKnMhRW91svnVY3nlhcx | KmWg78FjwMgo3UAjp4OV43Fvw72Ro1zViEw81hGNQ61Llyqpdr03MAOFOKvN | |||
| ku9l+LmYyd8TKD0wUlobMmHExLffbW83t991BjAD4Hr1/OJ49+rN6eWzK7A4 | QqYBdr96c3kJ7E9YRg6zkfLCYbdG+IjdLIXan69s0a7TIH8pTg9Awrba8nUa | |||
| VyfHJ1dgEJbDlD7n3tju9spYMHNXne7+A8Z2VsaihXvgxN2NSKMxu3tsbyPS | ZzGgz4bq2WZg8x1BikfAx2g8kdkoSF6QpF9cAqFGc8teViTkSYFq5usKUUfI | |||
| 94/d3Yx0ffCasXv+WOvm6qj3ti3ltzZ0LAc+2TTw4qTrD1wet795XG/TmIMH | oiXARxqXBsji1ivE9P/9+tX1DaGBHT7qx8DPNOK55CqYVODJddoda6v39noH | |||
| IImULo87egCO68Yd34PjujEnbsyr4XPbF6OlddTsHy339MVzqfPx9iaw3d29 | xA/rZlfRMjoxqIE397hTq/8RM+I+D/EEh3xNGketRKHFmWVg5JvmGoCkBUgs | |||
| lc6dTZ139nte5xPsvF2s/OCk/2yAfw+PNiJuRzzZNGI9ATSos10bdHHfJJ3O | AHR91kP7SbmboilQ9tcm4IGHvYN9GnjeH8giTnSBHl5EIAJh4YUSaK+SSk5L | |||
| +v53TLGzUxtyD1vtkIP1QzZhtXN0d//6Ytghx3cPWbMkx4URsBA3AD7erXoB | Z3jr4rx/uk3HixtFMytgJUHHp1fR56q9MCj7vYNjdIBenu9bm++01aHJ6RYG | |||
| kDqsj5KnubxjmKd4LATG0OmuT7ONtILEpgDLc/v1AEtBYkEFRVdQ+Bwt/XNG | V/iUaY87+7zDP99mq7H2Z2Pts7FGRPWHG2qyfsFc+IowL90so5xZSABo4I1v | |||
| S7VgJ4eMf10Qg//ZSATsEO6td/Z2rjulCqKHd626at3xWrtla69oPfD77nqt | 69UPzmXngywsrHNyaJm3H/9ZY2Y90c5aaXChvSV33+/uNnffd/qwAgB7+8P1 | |||
| Vd8919rd8Wd7UrV6EPbL1gOvb8cBTjt7237zXtXsweg88ZorNDr7RfNB1wdy | s/3bny5uXtyCZLo9e3Z2C/Jg0S46l9IZ291dGgvi8LbTPXrC2M7SWBRuT1y4 | |||
| UDV7QCjQwuZut+fzqFM1l70/0v7RRXU+rDGI4yiF5JgHtJh0aNU0LHyqgC2b | uxZoFGabx/bWAv342P31QNcHrxh74I5lbVgHvbfLO39gw7MceLhu4PVZ1x24 | |||
| ApClMtsyhXy5zSApgmlRlSnE8e6NIBtRA0xXvFzZCAJqBZ68vJa62giaSYla | OO5o/bjeujHHTwASd7o47vQJMK4a9+wRGFeNObNjXg9+4L5oVq3azdHpYk+X | |||
| sdXp7G/NgB06ErHZMjGkzaYFjcunhbe3vZ19MoSanwnQPN8abz7YuSHVLBTP | PBc6P9tdN213/2Cpc2dd572jntP5DDvvFiffPzt/0cf/Dk7XAs4jDteNWL0B | |||
| B8sc2Mq+gtL6sO405u0HZszrSVi25Sdka+6kABd4WDtvd2FtbGirsXVLWtGC | GtTZrQ26fmyRTmd1/w1L7O3VhjyCVh5yvHrIOqj2Tjf3rx8GD3m2eciKI3lW | |||
| RafPvmC9L3CGfK0ZX7P6ayz7x9Jzzyv5cLSKZamllj12IxV3rUx1UNRVMA+p | CAGecc3Ez/arXjBJfa4/0suznsogT2xO3PeY4/rXxr8WF19vTrnbrltTMbgg | |||
| IOwPsvuJtM3ixtNGl3eorzz81cSDsLQaHTrrObihEqSrQEaeopS1z2KHUtRP | dA9qr0I+m0f/H8yjdbbNCssF/8fmBwgfvAfoHOzddUq+Q7VuW9Oqdc9p7Zat | |||
| gtKRP7Y6tV83t4eNAJxKJrhbmrgt21L+8XgQLGi5PVgaIcHTfAQhDp5gu8G9 | vaL12O2777RWfQ9sa3fPXe2wanVmOCpbj52+HTtx0jnYdZsPqmZnjs6h01yB | |||
| Z9wXrM2PdXRWP+vPH9myrIHwiHQV1zHB/WQLzUyLnUks0z9mdHCk8q2ofCKh | 0Tkqmo+77iTHVbMzCVlX2Nzt9lwcdarmsvcfG3K61tP4viDXfhjieXoSPMF7 | |||
| gjw3pfCOVIinqJMwJ7bgbiBoe5TPmixPIoBt6OhUlIFRlVnQpr08e84olp7D | LcdWONASdG+3KAaAnkq3yhQ0ZgNHWnmT4i6pIMnHgkZsUsOsi7euVdAIdq4w | |||
| difNYB0vq3WeiUVJ/ExpPPbXCiGImDoJMPbMlpVa4ZSEmSmdurGnpMDkX8vE | df1Op1XQaKo1csdOp3O0MwXUpAG4tTsmBI/ZtKBx8S3D7q5zGUGiMJWXCjjQ | |||
| kQXCqLSxJ58qibLWKUbr1KZjR8xNT0dfgQR7eLisVVNPu4OKtXo65gNGwqqM | lcPrU4DX+JUFAzbceQXP64pYYF93tkcEeXvjRUYN+PVy/IxkzUavmA54UMvQ | |||
| GrMU2ix5R8OT01MMovAsPm4dj2BhEzIlpAoNm2YOLhptF/LgZjWr5nVnpFTi | vGYZ6/Mdcl2SVrvw8XLssyJYVARWjoMUT7IlKb5qIytE+5JG+Z3cvm6qNA51 | |||
| zUrneIEtchy9Qypwx8euiiWBkWt7J/DcS9O2Gd64lgtrqGbCILngq7XMhIZW | yauMJw67YoCrerGx4ur1ZmE0ByFpETsRBcecPNcyea2JWdN0Ph3Kfe7f0/2p | |||
| YZ3DKApDmTiPi3cUiFg69VAdMa77vXZZrQB2WdEDm79IP1H1eRWLzxuzf373 | vT4NTEXM5Y1tEdZU9VRiut8Uy0u7l/+cLwXTxdEYQ6yRDfSW7IAZTnDIZUSx | |||
| 0v6o+e0zYaZH5dk4P5wiI29LJtuEQ1HQWa71OBN+cAAmvOl6dcmWMzo8TkUP | lEhKJvkQrB3MwLvHkDVGE2vrYzKA4MCezlrn+IRKbvFlsgFLidQ7nmyEYWie | |||
| OmSiUImimWzzD1cCtqoE67OiJSXYQOBDE+dSAf74eOlPKtGv7+K3f6XEpqtr | zUyKYCbmGmwLyn2pFC/yooooq0CakpyHsY8p95GfE1owJgjsH+TTpsijAOY2 | |||
| TxPxur2octQ+hSW20rp+u53zpe32lRMIHFO0BH3GLX/LXVrLZ+FutZ9LKe1U | lP0VZCBjdea16fKbMqVC7ShzmyoH53lTnfdUzcu9T+MU8xZbPpDuxFKCaVLW | |||
| LGWzU9HtVvtTPddEm1Fvqzx2KuzO09sqiZ2K3U63bMJ8Ei89RSAJgWt1jP8I | GROyslwjzITyhjjPCxTAnY7sroAs49Rw7lZFWSytQpRWbUqcEnZ5CkPCDjB1 | |||
| +1MUT4GA/kMr8Roq9WdN/oM1+Q6mb1BnIGmd+799uDYv187WKzOeFVjMVG5u | wrlgp54cdMVsA0pUAqnBXBSPRAJtvL3TwdnFBdpU+KwJg81DOFd+jUQ80WCP | |||
| +Xmp0NqIUuVQ+UL6/bxUZxmEXg/c+5Fhd3eX9nUqRZVhr7dfaTMq9gSyA73T | s3/daFsjCOPbolrXZnlhdm+5KuW2A1r0KHiPu6DnSXQovAVBiu69wtydJrcZ | |||
| 62x3tzvdK6v/Fuze7spnq/jnH0XFXSwZ47FvL5ajSvupPTgfYRT9qRT+j9P3 | 2bjTc5ZcU2Vwu6DBU52pFFoVq4lhAPIlsgoYn3tZmY485Wbel2qwXd5wALKY | |||
| e2lmH7wD/ln9P1D975e7+6zBWlvwAa79AdbAKf4Vbissab8pGisTgD0hS5Th | 7rTEO76/1nFYWv1zIPazglnybV8oM6kuMhyDiq5VdgmG4s5n8WrBiuzjYxDZ | |||
| VTgtP/Rc75UPu26ETKeQImsRw8eri8FwcPHdoF/btcbhd/eibeIxZtY//SSu | TdurS7Jb0PsJupOgjJh4ii/vprotP4XuxTLdy/V0X9tRRfPiyd5ySfJ/rp30 | |||
| wplZA6hXGKk6NXu7NcyhR4Xi3l45Zt3XJ848EcCa4dr3v3x8m/XKXD+Xi8E7 | f5KO3zwR21Wq+8qMJ1kXEU/2U/G1mVyIsC+lLEh00OhN4YN8K61TK6f+fhXC | |||
| axleqFB+kgR4DRqf7cY/bkq7FBEPA9TIT1OwXcLhs9QtS93vK2j+iUQR1Ioq | JYd2ohZ82YnqdquQVM82UfzpbeXFThQHm95WLuxE7Xe6ZRN6k/gQLgBS8Gyr | |||
| v+WTAvZaH1svP859rnnEoF51qy5EkfxsOoHpPh1VB4pb9l2L4sAxP5cTlUVW | g/0/JCJFxhPQ6N+LdZe39Zl//2T+3YTyNUwMe1ql5x+ezsOLl2SrWRhzB+bT | |||
| 2h4dnb06f1x9O+0XAE4EyG94Wt02XJ3D32QE9CG+pEd9eJU0eODuDetaq4e9 | ODcP8qpk49SoktGQ5Xz6+6pkYu35Tg+M92i/u79PsZyKPbXf6x1VPIzsPAbT | |||
| izaFl5YyHFEQfsJfqQik4ilhZ6pmW9mmLU/XiCco7LVHkEZ89aMYxB/5n/AL | P93rdXa7u53uLXM9T3uwv/SZ2f3qD2RsazGGmJ7uWG6UGnbB6f0BWsp/BzZ/ | |||
| Dnvshr02Ur8QaQqsX6W8VPKKVvcF90BWGo/opR33ok0Nh2KUFDobSZHxF3h7 | dJcN8fEx7s9c/xFc//gJPCoEVoqAj9DjTxAClt9vMVSwwPSmaKw4H3uC66f9 | |||
| bFKnwPsKfmwFB2toXOuq33MfnvefrmH3cHj2fPD27OW3T0/PBq4s6QqqeMoB | W39SfujZ3ksf9u0InUzA701VCB9vr/uD/vWP/fNagBqHb+5FEeERusu//qpu | |||
| N9W9i3i40R/HD3tRg1USjdYGN89NKdxU64CRlJnQ5UadAsJ0e9slJDvtDfqi | /alZMVGvkE313Rzs1yCHHhWIBwflmFVfD61Uoglr8urI/fJniarX5u4HPe+/ | |||
| qx15guprzIoWucPoy4XXwiiTui4ZsDHKkKYb4WAfXqnMHrWvLpOfXsAPfWeX | Z7HwMvb1X+rdLi//KRdjn4XGX+iy/gFEV1orAw8Z8q+9iK2v/Znc/t7kBlui | |||
| ykcYMq+SsqEwG0xVFMjyaa0Ag5JU0c33yLhXS9ScvkthFnW/QLfdqhHLl3FZ | pcvLLX4wLsTSpeyqMhz1+7LqARYRyLrkf/vptEoZbnHFkiKlWF7pcZwFTE1b | |||
| Wr9PUEigd+vTVoHIedDLKPECkkL4R6VU+sOj6/YWLNpwoNFdccYjsyNBl7Zl | p5evr7arbxfnxQRnCijUv6jeNy6v4QYHAXwwGKkAmJPT6kz3mLFQ9HOzPos2 | |||
| MKV3TCJ3tcJCWwGCLEAAWwQtw+varhA1wqcQEsoxAwUOOUpE5UgKD/rmW1y2 | rtyDI4qNn8nXcQAE8ZygM1XzGV1kUqjSNmLuAz+0LNJv7SC55X7CLzhs2w57 | |||
| 0l17LxBolWok2dW8isuiJCHCYIbprrBWoBgoQqRNedHSu0Z7Ewn7pFTTq4u6 | Y3T6UiUJoH5558sOj/1Qi2QUR0EFxmwhrxoExSCt0myoVSZf4vO0cR1+5yso | |||
| gpcpMA5lQG9zVKyvLYu9hVg4KWPvODOrAU4d7B3sUKWZvW5bMQ7pUcZdS6Ee | qCUIWJDY1mWFZj/8cP58BbIHg8sf+m8vX33//OKyb68U7TUo5ihgANx59odB | |||
| yAvQAHoQbe6eFrMHO4pFodu6eJ3GtZMEX/iCcmGVBQSz1ux0yF0CGdElWvci | +TB8WkUYUdEzypNamJuuJajimE11jtME4KWn4ta92LPvZ4rnMy/VHCthpXR3 | |||
| B6wGLgoK71zxuVigh+m0+TFe/7X3M4lPFJGIRHyDf+Fxji8t8+1He9mT2WsO | zTKhfEJY3lPjs3qAuLxj6n3LW1H8N4HPMFbvaIrOh/XKY/bCgK6kqCoNx6xT | |||
| tdWCmX7EgOuRbE/a+EyNeymHlBlRlLp4O4TEjY2ELlW08RhI3GmDPS7iGZXQ | Ct0/Erkv3yHSM+9VN8611znQxxEH6ZMuB4rqa5uvhEkCLUjgkbRl07gKWJzx | |||
| iqBj4iJbug9lEdvCj1uFSrTsbWe6ts/YBuW0hW9bjC5jtpJpQssSVywNj/HE | S4HqZf7FNfxybuVtWdCiKpyl190Ye5M48HRZk9AD2ktiqiIQGFtTKJ7RZ63M | |||
| CL6KoqVszaW8diKJ75xEKixCBxHeoMYDZ4nB2pZuV6WtzZ+pOZafm3UzQDDK | vK7T6NFgOWDxZbNI6o8hCvZyntDydRTpPipbFM7BgYV/4oSOGRPpBeXi4zZR | |||
| ABThuEtawFn8rJgtfld19tUSv6HasS0JL8WaiiIteo8HS9HQaOhaOZkM+67C | DcEu7YtxzOUdKnoDr70JlRkK7OMQnvHRibgkj7Q3Y0MsLhGRX+zFYE0EnPpf | |||
| 0qNOVKYfyapKTvJXPpl14m7AWN1ACaxCJ88kOW5CKGnL7Jtuy9jnOHADynNE | ZQEhdn76HsmjtDWcog5pnKQB13PDEyve3xIlKoMusX0XXE0lziYqoJJ8/FzV | |||
| 7nbwtGDYhscerB1MhQZngQVnVqA+0grL4PiMi8SCOGolFv7tPhe+6GaPBZiI | eZt8HyguF9h07mntDZwpIPa1R+VzyhOoHQ4/6Sw0sK0vwUxuuYmftftxkvEL | |||
| bhgVL8vUY2R8NiQv04ZSXmIxwcr2NHKPtswgz8ZXWMibhDcC7y3jjR/CGWQ1 | 5gp1uJvY2Kc11AMxAVxO1SGx3iP24qyTApv0ABrfBNl2ouJrl1qumSWBOGvN | |||
| XpiIrlsvvczgXmUoXgcABx9cV6hspNgdTAwgXooSmxz4l9PKO2gxWmx8gae4 | llPtM5YhvUq2FU7gLIrqcLNYztQcVWinLZ/hi2p+6UpYIpNKReo7/A/mmXzF | |||
| NoY3mlblBu+Wazu0LgXIoJVDF/bAwAKljd15UsF2jHShMhsPKbA1hxQC7w5Z | qOeP/GxW8BuJ2lnBSljBUG7p9riNdaRsKSsSGQiiTotKLERwYqjSkk0b27DF | |||
| EzB1ATA+A1IclCXDaI9YUK2EoohlyVx6fA6JzcAOIEH0Dkz9ScBWUQNfehFw | bhsUTmGUxRGdB2peiaVBag+7GLAd/LhTMEaLH5BzNTuxhkH5Gp6vxkurs0Qa | |||
| U4wyU6E9seAyCfcER/FiH0VePkdZaYb8aKt42AnPSOB7WLYCn4R1Ja5slGFV | V8xjWNEgGWEmC9aYSbVuzbS+swSJdWOC2C9sIuXfI9cDZgnBKd8kL9NaW76I | |||
| gvmgx+e8d+fSWIAtaBBboENZY6/yj9JH43j7Eh8V79xDEkXCVj964z0RV/gl | Z3gZ3qzLApqjtJxxHvvaDDCLn2PBV/HVrf9ywoGhq2y+oV4wlmOyIqlgFoBl | |||
| 6+1Ki2xWDisu/mI2RFBM07m4KpjAhx2KTAmdkD2dCDpXO9P0fUGVd6YJ89HT | oNHQS30SHFyoYqFGGSUNDHV1Z0/0V1Z7O7Ovcpg1kAKroIQjmCw2wR7mS/91 | |||
| cWEWw+Y6u1kJJi4mLTQygTgDdp+j3TcUhDCkB08CBSCUqeUpaiEEWnWP6Z5E | T224vgmGzBxda99ZTwqEramewdIwUSkoDLz/FgXowzTGW3ksi6Pxfh65EtMQ | |||
| HIngmv0fSJbSfoRVAAA= | ODKHBQk5ScEE9EqqqNRTN2+xDkteejwlvYRqjBftk8A+bprGBsWFRxrFv1f4 | |||
| BhzLKxDMQKvh3AT0cn2h2IUtdFEUXAAbxrurQFm7Y6u4sZRjELGH476vK5/R | ||||
| hSizsaJR8fIN32Qt0w0+0095aJ0KEEFLKSCcvzBHahMbEye4Y5AWLLM2Z0Ks | ||||
| yJlwn+Q1AVJr4WNdlSKHlwQjJ3zQZQ5ZD4uUuVA3ETebgRzADVFhHedRC6rA | ||||
| 4mZ+oaBl27FNprEfWO6x18a2lklRYpJMShePohQ+rhlZlMfiEqfsyKIYXlkO | ||||
| EK0BUTnGrlFIgNmDWEwuJPCogCrpZviTQXdKUwWpULZIF1miQPwJljZGZ/rq | ||||
| 1U3/RA4ono2+nU1OsRYmGQDLOC9qXyB5ejqN2GmjXQhZ1Ucmoi8qtKY2G5MK | ||||
| fySh8rAyzLnOgOTMilWtVS6sTWsrvMmq1AY9OqyCF7Oqdm3JyxtOuylWVQFm | ||||
| DBSFBW3W8opSvsGo9loKX2PiVkmE1mzrQoGzWVCqLrOUcjr/0qwxN3GaFNdx | ||||
| zC70CAq3GRU2J5kCwmrZaD8TY4AqbAoKmVhn4eAd19ewasRvrtIzFSNj9hBV | ||||
| FoU50LIj3IKqlKgqUQA8t1vDXC5PF6VySXLB2dWtjLZbzJieF3GqXQ1PNeYo | ||||
| YjOrkdOws5ThlbWoqoGBRFjZTGA62mlwn3AQziNkMk2aaArQGlQa/F2RZUVq | ||||
| CDrMQPtJTu7FWdLKJnKSDjeck00afNe0E1S5g0zlVLYH62bBgY0x9NDGPnpD | ||||
| xMxOxOljRMeEWSvDy0CHLZqwlPn4ycfhml7i047CHoJ4/BDKMxDOGXws9sWa | ||||
| nM21mF+FeOGEKh9F+aZyGTZGFiHYistXFLZjJfG59n1gV+YKvQT3XvsAxSei | ||||
| 6HCv25VbDfx1kM0Bou9zEN9ggBfizCpsymQvFxP2eEtl6nFNwZCutawN4cXA | ||||
| wF4WITZAgXzco+8VJbjrGHDFsfPEQ6dTUwUKsSq2rcpONdSoOHKGOfmUwFi5 | ||||
| cLCfszAnr6S3t/u0suz2RT9aJVtmW35Ts1OgRaD3KK0D/43r/q8tve6UDW9c | ||||
| YCDbYMHhS+CPXI11Q6K1Y52CyisSzsHJrzeVXcd+Y+y2AzZy1t35IijWuA3t | ||||
| Gt+sqjK+oMOk1WGy/L9dKAqIc/xNZvOEq3OJqjwe0TdeoKMTXqxWlNCHoRMd | ||||
| JliVkiUJls5HHFfF+LG6Od99Sj9gy3EEpjfBxpWPsQYfbCvwsKhrkakblCpK | ||||
| mMx6Azatm3OPocFgDQU0HzzNgg7ToYbA0eJ/AcZrjGNwYgAA | ||||
| --> | --> | |||
| </rfc> | </rfc> | |||
| End of changes. 110 change blocks. | ||||
| 595 lines changed or deleted | 505 lines changed or added | |||
| This html diff was produced by rfcdiff 1.48. | ||||