CurrentBEST CURRENT PRACTICEIETF streamBCP195

RFC 8996: Deprecating TLS 1.0 and TLS 1.1

In plain English — editorial summary, not part of the RFC

This document formally deprecates Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346). Accordingly, those documents have been moved to Historic status. These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008 (subsequently being obsoleted by TLS version 1.3 in 2018), providing sufficient time to transition away from older versions. Removing support for older versions from implementations reduces the attack surface, reduces opportunity for misconfiguration, and streamlines library and product maintenance. This document also deprecates Datagram TLS (DTLS) version 1.0 (RFC 4347) but not DTLS version 1.2, and there is no DTLS version 1.1. This document updates many RFCs that normatively refer to TLS version 1.0 or TLS version 1.1, as described herein. This document also updates the best practices for TLS usage in RFC 7525; hence, it is part of BCP 195.

Document record

Document ID
RFC8996
Published
March 2021
Authors
K. Moriarty; S. Farrell
Status
BEST CURRENT PRACTICE
Stream
IETF
Area
sec
Pages
18
Also known as
BCP195
Obsoletes:
RFC 5469, RFC 7507

Topics

Standards lineage

This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.

  1. RFC 5469 (2009)
  2. RFC 7507 (2015)
  3. RFC 8996 (2021)

Read the full history of Deprecating TLS 1.0 and TLS 1.1

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/8996-deprecating-tls-1-0-and-tls-1-1