RFC 9325: Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)
In plain English — editorial summary, not part of the RFC
Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) are used to protect data exchanged over a wide range of application protocols and can also form the basis for secure transport protocols. Over the years, the industry has witnessed several serious attacks on TLS and DTLS, including attacks on the most commonly used cipher suites and their modes of operation. This document provides the latest recommendations for ensuring the security of deployed services that use TLS and DTLS. These recommendations are applicable to the majority of use cases. RFC 7525, an earlier version of the TLS recommendations, was published when the industry was transitioning to TLS 1.2. Years later, this transition is largely complete, and TLS 1.3 is widely available. This document updates the guidance given the new environment and obsoletes RFC 7525. In addition, this document updates RFCs 5288 and 6066 in view of recent attacks.
Document record
- Document ID
- RFC9325
- Published
- November 2022
- Authors
- Y. Sheffer; P. Saint-Andre; T. Fossati
- Status
- BEST CURRENT PRACTICE
- Stream
- IETF
- Area
- sec
- Pages
- 34
- Also known as
- BCP195
- Obsoletes:
- RFC 7525
Referenced by
2 later RFCs formally update or obsolete part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9329TCP Encapsulation of Internet Key Exchange Protocol (IKE) and IPsec PacketsCurrent
November 2022
- RFC 9334Remote ATtestation procedureS (RATS) ArchitectureCurrent
January 2023
- RFC 9336X.509 Certificate General-Purpose Extended Key Usage (EKU) for Document SigningCurrent
December 2022
- RFC 9338CBOR Object Signing and Encryption (COSE): CountersignaturesCurrent
December 2022
- RFC 9310X.509 Certificate Extension for 5G Network Function TypesCurrent
January 2023
- RFC 9345Delegated Credentials for TLS and DTLSCurrent
July 2023
- RFC 9347Aggregation and Fragmentation Mode for Encapsulating Security Payload (ESP) and Its Use for IP Traffic Flow Security (IP-TFS)Current
January 2023
- RFC 9348A YANG Data Model for IP Traffic Flow SecurityCurrent
January 2023
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?