RFC 7919: Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS)
In plain English — editorial summary, not part of the RFC
Traditional finite-field-based Diffie-Hellman (DH) key exchange during the Transport Layer Security (TLS) handshake suffers from a number of security, interoperability, and efficiency shortcomings. These shortcomings arise from lack of clarity about which DH group parameters TLS servers should offer and clients should accept. This document offers a solution to these shortcomings for compatible peers by using a section of the TLS "Supported Groups Registry" (renamed from "EC Named Curve Registry" by this document) to establish common finite field DH parameters with known structure and a mechanism for peers to negotiate support for these groups. This document updates TLS versions 1.0 (RFC 2246), 1.1 (RFC 4346), and 1.2 (RFC 5246), as well as the TLS Elliptic Curve Cryptography (ECC) extensions (RFC 4492).
Document record
- Document ID
- RFC7919
- Published
- August 2016
- Authors
- D. Gillmor
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 29
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7590Use of Transport Layer Security (TLS) in the Extensible Messaging and Presence Protocol (XMPP)Current
June 2015
- RFC 7525Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)Obsoleted
May 2015
- RFC 7465Prohibiting RC4 Cipher SuitesUpdated
February 2015
- RFC 7457Summarizing Known Attacks on Transport Layer Security (TLS) and Datagram TLS (DTLS)Current
February 2015
- RFC 3749Transport Layer Security Protocol Compression MethodsUpdated
May 2004
- RFC 3546Transport Layer Security (TLS) ExtensionsObsoleted
June 2003
- RFC 3268Advanced Encryption Standard (AES) Ciphersuites for Transport Layer Security (TLS)Obsoleted
July 2002
- RFC 2817Upgrading to TLS Within HTTP/1.1Updated
May 2000
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?