I will be hitting the button to submit this to the IESG next week.  The
revisions based on the earlier consensus calls have been made and
references to updated RFCs have been cleaned up.  You can use the diffi
tool to see the comparison with the -03 version -
https://author-tools.ietf.org/iddiff?url1=draft-ietf-tls-deprecate-obsolete-kex-03&url2=draft-ietf-tls-deprecate-obsolete-kex-05&difftype=--html.
 Let me know if you spot any concerns with the document.

Thanks,

Joe

On Tue, Sep 3, 2024 at 2:13 AM <internet-dra...@ietf.org> wrote:

> Internet-Draft draft-ietf-tls-deprecate-obsolete-kex-05.txt is now
> available.
> It is a work item of the Transport Layer Security (TLS) WG of the IETF.
>
>    Title:   Deprecating Obsolete Key Exchange Methods in TLS 1.2
>    Authors: Carrick Bartle
>             Nimrod Aviram
>    Name:    draft-ietf-tls-deprecate-obsolete-kex-05.txt
>    Pages:   21
>    Dates:   2024-09-03
>
> Abstract:
>
>    This document deprecates the use of RSA key exchange and Diffie
>    Hellman over a finite field in TLS 1.2, and discourages the use of
>    static elliptic curve Diffie Hellman cipher suites.
>
>    Note that these prescriptions apply only to TLS 1.2 since TLS 1.0 and
>    1.1 are deprecated by RFC 8996 and TLS 1.3 either does not use the
>    affected algorithm or does not share the relevant configuration
>    options.
>
>    This document updates RFCs 9325, 4346, 5246, 4162, 6347, 5932, 5288,
>    6209, 6367, 8422, 5289, 5469, 4785, 4279, 5487, 6655, and 7905.
>
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-tls-deprecate-obsolete-kex/
>
> There is also an HTML version available at:
>
> https://www.ietf.org/archive/id/draft-ietf-tls-deprecate-obsolete-kex-05.html
>
> A diff from the previous version is available at:
>
> https://author-tools.ietf.org/iddiff?url2=draft-ietf-tls-deprecate-obsolete-kex-05
>
> Internet-Drafts are also available by rsync at:
> rsync.ietf.org::internet-drafts
>
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-le...@ietf.org
>
_______________________________________________
TLS mailing list -- tls@ietf.org
To unsubscribe send an email to tls-le...@ietf.org

Reply via email to