CurrentPROPOSED STANDARDIETF stream

RFC 9155: Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2

In plain English — editorial summary, not part of the RFC

The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digital signatures. However, this document does not deprecate SHA-1 with Hashed Message Authentication Code (HMAC), as used in record protection. This document updates RFC 5246.

Document record

Document ID
RFC9155
Published
December 2021
Authors
L. Velvindron; K. Moriarty; A. Ghedini
Status
PROPOSED STANDARD
Stream
IETF
Area
sec
Pages
5
Also known as
Updates:
RFC 5246

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/9155-deprecating-md5-and-sha-1-signature-hashes-in-tls-1-2-and-dtls-1-2