RFC 8422: Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS) Versions 1.2 and Earlier
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 9846.
Current document in this lineage: RFC 6066 — Transport Layer Security (TLS) Extensions: Extension Definitions; RFC 9846 — The Transport Layer Security (TLS) Protocol Version 1.3
In plain English — editorial summary, not part of the RFC
This document describes key exchange algorithms based on Elliptic Curve Cryptography (ECC) for the Transport Layer Security (TLS) protocol. In particular, it specifies the use of Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key agreement in a TLS handshake and the use of the Elliptic Curve Digital Signature Algorithm (ECDSA) and Edwards-curve Digital Signature Algorithm (EdDSA) as authentication mechanisms. This document obsoletes RFC 4492.
Document record
- Document ID
- RFC8422
- Published
- August 2018
- Authors
- Y. Nir; S. Josefsson; M. Pegourie-Gonnard
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 34
- Also known as
- —
Topics
Standards lineage
This document is one revision in a chain of 15 RFCs, each formally replacing the one before it.
- RFC 2246 (1999)
- RFC 3268 (2002)
- RFC 3546 (2003)
- RFC 4346 (2006)
- RFC 4366 (2006)
- RFC 4492 (2006)
- RFC 4507 (2006)
- RFC 5077 (2008)
- RFC 5246 (2008)
- RFC 6066 (2011)
- RFC 6961 (2013)
- RFC 7627 (2015)
- RFC 8422 (2018)
- RFC 8446 (2018)
- RFC 9846 (2026) ✓
Read the full history of The Transport Layer Security (TLS) Protocol Version 1.3 →
Referenced by
3 later RFCs formally update or obsolete part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9053CBOR Object Signing and Encryption (COSE): Initial AlgorithmsUpdated
August 2022
- RFC 8410Algorithm Identifiers for Ed25519, Ed448, X25519, and X448 for Use in the Internet X.509 Public Key InfrastructureUpdated
August 2018
- RFC 8080Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSECCurrent
February 2017
- RFC 7427Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)Current
January 2015
- RFC 5754Using SHA2 Algorithms with Cryptographic Message SyntaxCurrent
January 2010
- RFC 8608BGPsec Algorithms, Key Formats, and Signature FormatsCurrent
June 2019
- RFC 6594Use of the SHA-256 Algorithm with RSA, Digital Signature Algorithm (DSA), and Elliptic Curve DSA (ECDSA) in SSHFP Resource RecordsCurrent
April 2012
- RFC 6162Elliptic Curve Algorithms for Cryptographic Message Syntax (CMS) Asymmetric Key Package Content TypeCurrent
April 2011
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?