Eric Rescorla <[email protected]> wrote:
    > I fear that we have done this fairly often.  To use an example I am
    > familiar with, TLS 1.2 (RFC 5246) is updated by at least the following
    > RFCs which change its behavior:

    > * RFC 6176 forbids offering SSLv2
    > * RFC 7568 forbids offering SSLv3
    > * RFC 7465 forbids the use of RC4
    > * RFC 9155 forbids MD5 and SHA-1

Yes, and also RFC6066/SNI is a good example of a document that Extended TLS
1.2, but due to the operational MUST USE, is essential reading, so it ought
to Update/Amends RFC5246, but actually it doesn't even Update 5246!

--
Michael Richardson <[email protected]>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide

**       My working hours and your working hours may be different.         **
** Please do not feel obligated to reply outside your normal working hours **




Attachment: signature.asc
Description: PGP signature

-- 
rswg mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to