"[email protected]" <[email protected]> wrote:

> PS: As Kathleen noted TLS 1.2 and DTLS 1.2 are perfectly fine if you follow 
> RFC 7925/7525.

While TLS 1.2 and DTLS 1.2 can be configured to be secure, RFC 7525 is 
definitely not enough. RFC 7540 would be a good start, but also that would need 
to be extended with support of extensions like Extended Master Secret, 
Signature Algorithms, and Certificate Status Request to be considered fine in 
2019.

Cheers,
John


 

_______________________________________________
TLS mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/tls

Reply via email to