UpdatedBEST CURRENT PRACTICEIETF streamBCP195

RFC 9325: Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)

Still current, but amended. Parts of this document are changed or extended by RFC 9852, RFC 10015. Read both.

In plain English — editorial summary, not part of the RFC

Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) are used to protect data exchanged over a wide range of application protocols and can also form the basis for secure transport protocols. Over the years, the industry has witnessed several serious attacks on TLS and DTLS, including attacks on the most commonly used cipher suites and their modes of operation. This document provides the latest recommendations for ensuring the security of deployed services that use TLS and DTLS. These recommendations are applicable to the majority of use cases. RFC 7525, an earlier version of the TLS recommendations, was published when the industry was transitioning to TLS 1.2. Years later, this transition is largely complete, and TLS 1.3 is widely available. This document updates the guidance given the new environment and obsoletes RFC 7525. In addition, this document updates RFCs 5288 and 6066 in view of recent attacks.

Document record

Document ID
RFC9325
Published
November 2022
Authors
Y. Sheffer; P. Saint-Andre; T. Fossati
Status
BEST CURRENT PRACTICE
Stream
IETF
Area
sec
Pages
34
Also known as
BCP195
Obsoletes:
RFC 7525
Updated by:
RFC 9852, RFC 10015

Referenced by

2 later RFCs formally update or obsolete part of this document.

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/9325-recommendations-for-secure-use-of-transport-layer-security-tls-and-datagram-tran