RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 9846.
Current document in this lineage: RFC 6066 — Transport Layer Security (TLS) Extensions: Extension Definitions; RFC 9846 — The Transport Layer Security (TLS) Protocol Version 1.3
In plain English — editorial summary, not part of the RFC
RFC 8446 specifies TLS 1.3, the version of TLS in use across most of the modern web. It cut the handshake to a single round trip (with an optional 0-RTT resumption mode), removed the legacy cipher suites and key exchanges that caused a decade of downgrade attacks, and made forward secrecy mandatory. Practically: faster connections and a much smaller set of ways to configure it insecurely.
Original abstract from the RFC
This document specifies version 1.3 of the Transport Layer Security (TLS) protocol. TLS allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery. This document updates RFCs 5705 and 6066, and obsoletes RFCs 5077, 5246, and 6961. This document also specifies new requirements for TLS 1.2 implementations.
Document record
- Document ID
- RFC8446
- Published
- August 2018
- Authors
- E. Rescorla
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 160
- Also known as
- —
- Obsoleted by:
- RFC 9846
Topics
Standards lineage
This document is one revision in a chain of 15 RFCs, each formally replacing the one before it.
- RFC 2246 (1999)
- RFC 3268 (2002)
- RFC 3546 (2003)
- RFC 4346 (2006)
- RFC 4366 (2006)
- RFC 4492 (2006)
- RFC 4507 (2006)
- RFC 5077 (2008)
- RFC 5246 (2008)
- RFC 6066 (2011)
- RFC 6961 (2013)
- RFC 7627 (2015)
- RFC 8422 (2018)
- RFC 8446 (2018)
- RFC 9846 (2026) ✓
Read the full history of The Transport Layer Security (TLS) Protocol Version 1.3 →
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6071IP Security (IPsec) and Internet Key Exchange (IKE) Document RoadmapCurrent
February 2011
- RFC 4366Transport Layer Security (TLS) ExtensionsObsoleted
April 2006
- RFC 3546Transport Layer Security (TLS) ExtensionsObsoleted
June 2003
- RFC 3268Advanced Encryption Standard (AES) Ciphersuites for Transport Layer Security (TLS)Obsoleted
July 2002
- RFC 2411IP Security Document RoadmapObsoleted
November 1998
- RFC 2246The TLS Protocol Version 1.0Obsoleted
January 1999
- RFC 7861Remote Procedure Call (RPC) Security Version 3Current
November 2016
- RFC 7844Anonymity Profiles for DHCP ClientsCurrent
May 2016
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?