TLS

TLS (Transport Layer Security): protocol, extensions, deployment guidance

TLS subjects:

TLS RFCs (171)

Display RFCs as
  • RFC 10024: Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3

    Proposed Standard
  • RFC 9852: BCP 195: New Protocols Using TLS Must Require TLS 1.3

    Best Current Practice
  • RFC 9850: The SSLKEYLOGFILE Format for TLS

    Informational
  • RFC 9851: TLS 1.2 is in Feature Freeze

    Proposed Standard
  • RFC 9954: Hybrid Key Exchange in TLS 1.3

    Informational
  • RFC 9973: TLS 1.3 Extension for Using Certificates with an External Pre-Shared Key

    Proposed Standard
  • RFC 9916: Updates to the Usage of TLS to Provide a Secure Transport for the Path Computation Element Communication Protocol (PCEP)

    Proposed Standard
  • RFC 9918: Updates to Using the NETCONF Protocol over Transport Layer Security (TLS) with Mutual X.509 Authentication

    Proposed Standard
  • RFC 9846: The Transport Layer Security (TLS) Protocol Version 1.3

    Proposed Standard
  • RFC 9966: Bootstrapped TLS Authentication with Proof of Knowledge

    Proposed Standard
  • RFC 9963: Legacy RSASSA-PKCS1-v1_5 Code Points for TLS 1.3

    Proposed Standard
  • RFC 9932: Mutually Authenticating TLS in the Context of Federations

    Informational
  • RFC 9950: A YANG Data Model for Terminal Access Controller Access-Control System Plus (TACACS+)

    Proposed Standard
  • RFC 9934: Privacy-Enhanced Mail (PEM) File Format for Encrypted ClientHello (ECH)

    Proposed Standard
  • RFC 9848: Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings

    Proposed Standard
  • RFC 9849: TLS Encrypted Client Hello

    Proposed Standard
  • RFC 9887: Terminal Access Controller Access-Control System Plus (TACACS+) over TLS 1.3

    Proposed Standard
  • RFC 9813: BCP 243: Operational Considerations for Using TLS Pre-Shared Keys (TLS-PSKs) with RADIUS

    Best Current Practice
  • RFC 9765: RADIUS/1.1: Leveraging Application-Layer Protocol Negotiation (ALPN) to Remove MD5

    Experimental
  • RFC 9645: YANG Groupings for TLS Clients and TLS Servers

    Proposed Standard
  • RFC 9539: Unilateral Opportunistic Deployment of Encrypted Recursive-to-Authoritative DNS

    Experimental
  • RFC 9525: Service Identity in TLS

    Proposed Standard
  • RFC 9431: Message Queuing Telemetry Transport (MQTT) and Transport Layer Security (TLS) Profile of Authentication and Authorization for Constrained Environments (ACE) Framework

    Proposed Standard
  • RFC 9427: TLS-Based Extensible Authentication Protocol (EAP) Types for Use with TLS 1.3

    Proposed Standard
  • RFC 9368: Compatible Version Negotiation for QUIC

    Proposed Standard
  • RFC 9367: GOST Cipher Suites for Transport Layer Security (TLS) Protocol Version 1.3

    Informational
  • RFC 9289: Towards Remote Procedure Call Encryption by Default

    Proposed Standard
  • RFC 9266: Channel Bindings for TLS 1.3

    Proposed Standard
  • RFC 9257: Guidance for External Pre-Shared Key (PSK) Usage in TLS

    Informational
  • RFC 9258: Importing External Pre-Shared Keys (PSKs) for TLS 1.3

    Proposed Standard
  • RFC 9261: Exported Authenticators in TLS

    Proposed Standard
  • RFC 9149: TLS Ticket Requests

    Proposed Standard
  • RFC 9150: TLS 1.3 Authentication and Integrity-Only Cipher Suites

    Informational
  • RFC 9189: GOST Cipher Suites for Transport Layer Security (TLS) Protocol Version 1.2

    Informational
  • RFC 9190: EAP-TLS 1.3: Using the Extensible Authentication Protocol with TLS 1.3

    Proposed Standard
  • RFC 9191: Handling Large Certificates and Long Certificate Chains in TLS-Based EAP Methods

    Informational
  • RFC 9162: Certificate Transparency Version 2.0

    Experimental
  • RFC 9103: DNS Zone Transfer over TLS

    Proposed Standard
  • RFC 9102: TLS DNSSEC Chain Extension

    Experimental
  • RFC 9001: Using TLS to Secure QUIC

    Proposed Standard
  • RFC 8996: BCP 195: Deprecating TLS 1.0 and TLS 1.1

    Best Current Practice
  • RFC 8997: Deprecation of TLS 1.1 for Email Submission and Access

    Proposed Standard
  • RFC 8998: ShangMi (SM) Cipher Suites for TLS 1.3

    Informational
  • RFC 8879: TLS Certificate Compression

    Proposed Standard
  • RFC 8940: Extensible Authentication Protocol (EAP) Session-Id Derivation for EAP Subscriber Identity Module (EAP-SIM), EAP Authentication and Key Agreement (EAP-AKA), and Protected EAP (PEAP)

    Proposed Standard
  • RFC 8937: Randomness Improvements for Security Protocols

    Informational
  • RFC 8902: TLS Authentication Using Intelligent Transport System (ITS) Certificates

    Experimental
  • RFC 8744: Issues and Requirements for Server Name Identification (SNI) Encryption in TLS

    Informational
  • RFC 8773: TLS 1.3 Extension for Certificate-Based Authentication with an External Pre-Shared Key

    Experimental

    Obsoleted by RFC 9973

  • RFC 8737: Automated Certificate Management Environment (ACME) TLS Application-Layer Protocol Negotiation (ALPN) Challenge Extension

    Proposed Standard
  • RFC 8705: OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens

    Proposed Standard
  • RFC 8740: Using TLS 1.3 with HTTP/2

    Proposed Standard

    Obsoleted by RFC 9113

  • RFC 8734: Elliptic Curve Cryptography (ECC) Brainpool Curves for Transport Layer Security (TLS) Version 1.3

    Informational
  • RFC 8701: Applying Generate Random Extensions And Sustain Extensibility (GREASE) to TLS Extensibility

    Informational
  • RFC 8689: SMTP Require TLS Option

    Proposed Standard
  • RFC 8672: TLS Server Identity Pinning with Tickets

    Experimental
  • RFC 8492: Secure Password Ciphersuites for Transport Layer Security (TLS)

    Informational
  • RFC 8448: Example Handshake Traces for TLS 1.3

    Informational
  • RFC 8471: The Token Binding Protocol Version 1.0

    Proposed Standard
  • RFC 8472: Transport Layer Security (TLS) Extension for Token Binding Protocol Negotiation

    Proposed Standard
  • RFC 8473: Token Binding over HTTP

    Proposed Standard
  • RFC 8460: SMTP TLS Reporting

    Proposed Standard
  • RFC 8461: SMTP MTA Strict Transport Security (MTA-STS)

    Proposed Standard
  • RFC 8470: Using Early Data in HTTP

    Proposed Standard
  • RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3

    Proposed Standard

    Obsoleted by RFC 9846

  • RFC 8449: Record Size Limit Extension for TLS

    Proposed Standard
  • RFC 8422: Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS) Versions 1.2 and Earlier

    Proposed Standard

    Obsoleted by RFC 9846

  • RFC 8323: CoAP (Constrained Application Protocol) over TCP, TLS, and WebSockets

    Proposed Standard
  • RFC 8314: Cleartext Considered Obsolete: Use of Transport Layer Security (TLS) for Email Submission and Access

    Proposed Standard
  • RFC 8253: PCEPS: Usage of TLS to Provide a Secure Transport for the Path Computation Element Communication Protocol (PCEP)

    Proposed Standard
  • RFC 8143: Using Transport Layer Security (TLS) with Network News Transfer Protocol (NNTP)

    Proposed Standard
  • RFC 8122: Connection-Oriented Media Transport over the Transport Layer Security (TLS) Protocol in the Session Description Protocol (SDP)

    Proposed Standard
  • RFC 7918: Transport Layer Security (TLS) False Start

    Informational
  • RFC 7919: Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS)

    Proposed Standard
  • RFC 7924: Transport Layer Security (TLS) Cached Information Extension

    Proposed Standard
  • RFC 7858: Specification for DNS over Transport Layer Security (TLS)

    Proposed Standard
  • RFC 7836: Guidelines on the Cryptographic Algorithms to Accompany the Usage of Standards GOST R 34.10-2012 and GOST R 34.11-2012

    Informational
  • Proposed Standard
  • RFC 7685: A Transport Layer Security (TLS) ClientHello Padding Extension

    Proposed Standard
  • RFC 7633: X.509v3 Transport Layer Security (TLS) Feature Extension

    Proposed Standard
  • RFC 7672: SMTP Security via Opportunistic DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS)

    Proposed Standard
  • RFC 7627: Transport Layer Security (TLS) Session Hash and Extended Master Secret Extension

    Proposed Standard

    Obsoleted by RFC 9846

  • RFC 7562: Transport Layer Security (TLS) Authorization Using Digital Transmission Content Protection (DTCP) Certificates

    Informational
  • RFC 7568: Deprecating Secure Sockets Layer Version 3.0

    Proposed Standard
  • RFC 7589: Using the NETCONF Protocol over Transport Layer Security (TLS) with Mutual X.509 Authentication

    Proposed Standard
  • RFC 7590: Use of Transport Layer Security (TLS) in the Extensible Messaging and Presence Protocol (XMPP)

    Proposed Standard
  • RFC 7507: TLS Fallback Signaling Cipher Suite Value (SCSV) for Preventing Protocol Downgrade Attacks

    Proposed Standard

    Obsoleted by RFC 8996

  • RFC 7465: Prohibiting RC4 Cipher Suites

    Proposed Standard
  • RFC 7194: Default Port for Internet Relay Chat (IRC) via TLS/SSL

    Informational
  • RFC 7301: Transport Layer Security (TLS) Application-Layer Protocol Negotiation Extension

    Proposed Standard
  • RFC 7251: AES-CCM Elliptic Curve Cryptography (ECC) Cipher Suites for TLS

    Informational
  • RFC 7027: Elliptic Curve Cryptography (ECC) Brainpool Curves for Transport Layer Security (TLS)

    Informational
  • RFC 6961: The Transport Layer Security (TLS) Multiple Certificate Status Request Extension

    Proposed Standard

    Obsoleted by RFC 8446, RFC 9846

  • RFC 6962: Certificate Transparency

    Experimental

    Obsoleted by RFC 9162

  • RFC 6876: A Posture Transport Protocol over TLS (PT-TLS)

    Proposed Standard
  • RFC 6797: HTTP Strict Transport Security (HSTS)

    Proposed Standard
  • RFC 6698: The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA

    Proposed Standard
  • RFC 6655: AES-CCM Cipher Suites for Transport Layer Security (TLS)

    Proposed Standard
  • RFC 6614: Transport Layer Security (TLS) Encryption for RADIUS

    Experimental
  • RFC 6618: Mobile IPv6 Security Framework Using Transport Layer Security for Communication between the Mobile Node and Home Agent

    Experimental
  • RFC 6546: Transport of Real-time Inter-network Defense (RID) Messages over HTTP/TLS

    Proposed Standard
  • RFC 6460: Suite B Profile for Transport Layer Security (TLS)

    Historic
  • RFC 6394: Use Cases and Requirements for DNS-Based Authentication of Named Entities (DANE)

    Informational
  • RFC 6367: Addition of the Camellia Cipher Suites to Transport Layer Security (TLS)

    Informational
  • RFC 6101: The Secure Sockets Layer (SSL) Protocol Version 3.0

    Historic
  • RFC 6251: Using Kerberos Version 5 over the Transport Layer Security (TLS) Protocol

    Informational
  • RFC 6209: Addition of the ARIA Cipher Suites to Transport Layer Security (TLS)

    Informational
  • RFC 6125: Representation and Verification of Domain-Based Application Service Identity within Internet Public Key Infrastructure Using X.509 (PKIX) Certificates in the Context of Transport Layer Security (TLS)

    Proposed Standard

    Obsoleted by RFC 9525

  • RFC 6176: Prohibiting Secure Sockets Layer (SSL) Version 2.0

    Proposed Standard
  • RFC 6135: An Alternative Connection Model for the Message Session Relay Protocol (MSRP)

    Proposed Standard
  • RFC 6091: Using OpenPGP Keys for Transport Layer Security (TLS) Authentication

    Informational
  • RFC 6066: Transport Layer Security (TLS) Extensions: Extension Definitions

    Proposed Standard
  • RFC 6042: Transport Layer Security (TLS) Authorization Using KeyNote

    Informational
  • RFC 5929: Channel Bindings for TLS

    Proposed Standard
  • RFC 5932: Camellia Cipher Suites for TLS

    Proposed Standard
  • RFC 5922: Domain Certificates in the Session Initiation Protocol (SIP)

    Proposed Standard
  • RFC 5923: Connection Reuse in the Session Initiation Protocol (SIP)

    Proposed Standard
  • RFC 5878: Transport Layer Security (TLS) Authorization Extensions

    Experimental
  • RFC 5705: Keying Material Exporters for Transport Layer Security (TLS)

    Proposed Standard
  • RFC 5746: Transport Layer Security (TLS) Renegotiation Indication Extension

    Proposed Standard
  • RFC 5630: The Use of the SIPS URI Scheme in the Session Initiation Protocol (SIP)

    Proposed Standard
  • RFC 5734: STD 69: Extensible Provisioning Protocol (EPP) Transport over TCP

    Internet Standard
  • RFC 5539: NETCONF over Transport Layer Security (TLS)

    Proposed Standard

    Obsoleted by RFC 7589

  • RFC 5430: Suite B Profile for Transport Layer Security (TLS)

    Historic

    Obsoleted by RFC 6460

  • RFC 5489: ECDHE_PSK Cipher Suites for Transport Layer Security (TLS)

    Informational
  • RFC 5425: Transport Layer Security (TLS) Transport Mapping for Syslog

    Proposed Standard
  • RFC 5487: Pre-Shared Key Cipher Suites for TLS with SHA-256/384 and AES Galois Counter Mode

    Proposed Standard
  • RFC 5469: DES and IDEA Cipher Suites for Transport Layer Security (TLS)

    Historic

    Obsoleted by RFC 8996

  • RFC 5288: AES Galois Counter Mode (GCM) Cipher Suites for TLS

    Proposed Standard
  • RFC 5289: TLS Elliptic Curve Cipher Suites with SHA-256/384 and AES Galois Counter Mode (GCM)

    Proposed Standard
  • RFC 5246: The Transport Layer Security (TLS) Protocol Version 1.2

    Proposed Standard

    Obsoleted by RFC 8446, RFC 9846

  • RFC 5281: Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0 (EAP-TTLSv0)

    Informational
  • RFC 5216: The EAP-TLS Authentication Protocol

    Proposed Standard
  • RFC 5077: Transport Layer Security (TLS) Session Resumption without Server-Side State

    Proposed Standard

    Obsoleted by RFC 8446, RFC 9846

  • RFC 5114: Additional Diffie-Hellman Groups for Use with IETF Standards

    Informational
  • RFC 5054: Using the Secure Remote Password (SRP) Protocol for TLS Authentication

    Informational
  • RFC 5081: Using OpenPGP Keys for Transport Layer Security (TLS) Authentication

    Experimental

    Obsoleted by RFC 6091

  • RFC 5018: Connection Establishment in the Binary Floor Control Protocol (BFCP)

    Proposed Standard
  • RFC 4934: Extensible Provisioning Protocol (EPP) Transport Over TCP

    Draft Standard

    Obsoleted by RFC 5734

  • RFC 4785: Pre-Shared Key (PSK) Ciphersuites with NULL Encryption for Transport Layer Security (TLS)

    Proposed Standard
  • RFC 4642: Using Transport Layer Security (TLS) with Network News Transfer Protocol (NNTP)

    Proposed Standard
  • RFC 4680: TLS Handshake Message for Supplemental Data

    Proposed Standard
  • RFC 4681: TLS User Mapping Extension

    Proposed Standard
  • RFC 4572: Connection-Oriented Media Transport over the Transport Layer Security (TLS) Protocol in the Session Description Protocol (SDP)

    Proposed Standard

    Obsoleted by RFC 8122

  • RFC 4511: Lightweight Directory Access Protocol (LDAP): The Protocol

    Proposed Standard
  • RFC 4513: Lightweight Directory Access Protocol (LDAP): Authentication Methods and Security Mechanisms

    Proposed Standard
  • RFC 4492: Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS)

    Informational

    Obsoleted by RFC 8422

  • RFC 4507: Transport Layer Security (TLS) Session Resumption without Server-Side State

    Proposed Standard

    Obsoleted by RFC 5077

  • RFC 4366: Transport Layer Security (TLS) Extensions

    Proposed Standard

    Obsoleted by RFC 5246, RFC 6066

  • RFC 4346: The Transport Layer Security (TLS) Protocol Version 1.1

    Historic

    Obsoleted by RFC 5246

  • RFC 4261: Common Open Policy Service (COPS) Over Transport Layer Security (TLS)

    Proposed Standard
  • RFC 4279: Pre-Shared Key Ciphersuites for Transport Layer Security (TLS)

    Proposed Standard
  • RFC 4169: Hypertext Transfer Protocol (HTTP) Digest Authentication Using Authentication and Key Agreement (AKA) Version-2

    Informational
  • RFC 4217: Securing FTP with TLS

    Proposed Standard
  • RFC 4162: Addition of SEED Cipher Suites to Transport Layer Security (TLS)

    Proposed Standard
  • RFC 4132: Addition of Camellia Cipher Suites to Transport Layer Security (TLS)

    Proposed Standard

    Obsoleted by RFC 5932

  • RFC 3943: Transport Layer Security (TLS) Protocol Compression Using Lempel-Ziv-Stac (LZS)

    Informational
  • RFC 3749: Transport Layer Security Protocol Compression Methods

    Proposed Standard
  • RFC 3734: Extensible Provisioning Protocol (EPP) Transport Over TCP

    Proposed Standard

    Obsoleted by RFC 4934

  • RFC 3546: Transport Layer Security (TLS) Extensions

    Proposed Standard

    Obsoleted by RFC 4366

  • RFC 3436: Transport Layer Security over Stream Control Transmission Protocol

    Proposed Standard
  • RFC 3268: Advanced Encryption Standard (AES) Ciphersuites for Transport Layer Security (TLS)

    Proposed Standard

    Obsoleted by RFC 5246

  • RFC 3207: SMTP Service Extension for Secure SMTP over Transport Layer Security

    Proposed Standard
  • RFC 2817: Upgrading to TLS Within HTTP/1.1

    Proposed Standard
  • RFC 2818: HTTP Over TLS

    Informational

    Obsoleted by RFC 9110

  • RFC 2830: Lightweight Directory Access Protocol (v3): Extension for Transport Layer Security

    Proposed Standard

    Obsoleted by RFC 4510, RFC 4511, RFC 4513

  • RFC 2712: Addition of Kerberos Cipher Suites to Transport Layer Security (TLS)

    Proposed Standard
  • RFC 2716: PPP EAP TLS Authentication Protocol

    Experimental

    Obsoleted by RFC 5216

  • RFC 2595: Using TLS with IMAP, POP3 and ACAP

    Proposed Standard
  • RFC 2246: The TLS Protocol Version 1.0

    Historic

    Obsoleted by RFC 4346

  • RFC 2487: SMTP Service Extension for Secure SMTP over TLS

    Proposed Standard

    Obsoleted by RFC 3207

Subscribe to TLS

Get notified when:

  • RFC changes to status, obsoleted by, updates, updated by, or subseries.
  • New RFC added to this subject or below
  • The subject was merged into another.