RFC 7525: Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 9325.
Current version: RFC 9325 — Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)
In plain English — editorial summary, not part of the RFC
Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) are widely used to protect data exchanged over application protocols such as HTTP, SMTP, IMAP, POP, SIP, and XMPP. Over the last few years, several serious attacks on TLS have emerged, including attacks on its most commonly used cipher suites and their modes of operation. This document provides recommendations for improving the security of deployed services that use TLS and DTLS. The recommendations are applicable to the majority of use cases.
Document record
- Document ID
- RFC7525
- Published
- May 2015
- Authors
- Y. Sheffer; R. Holz; P. Saint-Andre
- Status
- BEST CURRENT PRACTICE
- Stream
- IETF
- Area
- sec
- Pages
- 27
- Also known as
- —
Topics
Referenced by
2 later RFCs formally update or obsolete part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7457Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS)Current
February 2015
- RFC 7590Use of Transport Layer Security (TLS) in the Extensible Messaging and Presence Protocol (XMPP)Current
June 2015
- RFC 7568Deprecating Secure Sockets Layer Version 3.0Updated
June 2015
- RFC 7465Prohibiting RC4 Cipher SuitesUpdated
February 2015
- RFC 7919Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS)Current
August 2016
- RFC 9662Updates to the Cipher Suites in Secure SyslogCurrent
October 2024
- RFC 3749Transport Layer Security Protocol Compression MethodsUpdated
May 2004
- RFC 3546Transport Layer Security (TLS) ExtensionsObsoleted
June 2003
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?