logoalt Hacker News

RFC 9851: TLS 1.2 is in Feature Freeze

19 pointsby Jimmc414today at 1:23 AM6 commentsview on HN

Comments

mcpherrinmtoday at 1:52 AM

This shouldn’t be too much of a surprise, as TLS 1.3 has been out for many years and is widely adopted.

I haven’t paid too much attention to the TLS WG lately (for obvious reasons if you look at their mailing list), but I assume this is mostly a “if you want Post-Quantum cryptography, you need 1.3”.

pavontoday at 2:52 AM

I assume this is in contest with RFC10015 which proposes "Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2"[1]. Both are Proposed Standards submitted in July, by the same author. HN discussion[2]

[1]https://www.rfc-editor.org/rfc/rfc10015.html

[2]https://news.ycombinator.com/item?id=49139711

BobbyTables2today at 2:30 AM

I don’t get it. Were there revisions or optional features of v1.2?

I thought the 1.2 spec was the frozen spec.

show 2 replies
kijintoday at 2:19 AM

Makes sense. Nobody wants to deal with "this user-agent claims to support TLS 1.2, except this extension that was added in 2026" anymore.

If you're going to add or remove features, follow semver and bump that number.

show 1 reply
fenestellatoday at 2:56 AM

[flagged]

richard_ggtoday at 1:35 AM

[flagged]