Eric Rescorla <[email protected]> wrote: > I fear that we have done this fairly often. To use an example I am > familiar with, TLS 1.2 (RFC 5246) is updated by at least the following > RFCs which change its behavior:
> * RFC 6176 forbids offering SSLv2
> * RFC 7568 forbids offering SSLv3
> * RFC 7465 forbids the use of RC4
> * RFC 9155 forbids MD5 and SHA-1
Yes, and also RFC6066/SNI is a good example of a document that Extended TLS
1.2, but due to the operational MUST USE, is essential reading, so it ought
to Update/Amends RFC5246, but actually it doesn't even Update 5246!
--
Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting )
Sandelman Software Works Inc, Ottawa and Worldwide
** My working hours and your working hours may be different. **
** Please do not feel obligated to reply outside your normal working hours **
signature.asc
Description: PGP signature
-- rswg mailing list -- [email protected] To unsubscribe send an email to [email protected]
