RFC 9155: Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2
In plain English — editorial summary, not part of the RFC
The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digital signatures. However, this document does not deprecate SHA-1 with Hashed Message Authentication Code (HMAC), as used in record protection. This document updates RFC 5246.
Document record
- Document ID
- RFC9155
- Published
- December 2021
- Authors
- L. Velvindron; K. Moriarty; A. Ghedini
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 5
- Also known as
- —
- Updates:
- RFC 5246
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9149TLS Ticket RequestsCurrent
April 2022
- RFC 9162Certificate Transparency Version 2.0Current
December 2021
- RFC 8996Deprecating TLS 1.0 and TLS 1.1Current
March 2021
- RFC 8940Extensible Authentication Protocol (EAP) Session-Id Derivation for EAP Subscriber Identity Module (EAP-SIM), EAP Authentication and Key Agreement (EAP-AKA), and Protected EAP (PEAP)Current
October 2020
- RFC 8701Applying Generate Random Extensions And Sustain Extensibility (GREASE) to TLS ExtensibilityCurrent
January 2020
- RFC 9662Updates to the Cipher Suites in Secure SyslogCurrent
October 2024
- RFC 9765RADIUS/1.1: Leveraging Application-Layer Protocol Negotiation (ALPN) to Remove MD5Current
April 2025
- RFC 8473Token Binding over HTTPCurrent
October 2018
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?