| ▲ | RFC 9851: TLS 1.2 is in Feature Freeze(rfc-editor.org) | |||||||
| 22 points by Jimmc414 4 hours ago | 7 comments | ||||||||
| ▲ | mcpherrinm 4 hours ago | parent | next [-] | |||||||
This shouldn’t be too much of a surprise, as TLS 1.3 has been out for many years and is widely adopted. I haven’t paid too much attention to the TLS WG lately (for obvious reasons if you look at their mailing list), but I assume this is mostly a “if you want Post-Quantum cryptography, you need 1.3”. | ||||||||
| ▲ | pavon 3 hours ago | parent | prev | next [-] | |||||||
I assume this is in contest with RFC10015 which proposes "Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2"[1]. Both are Proposed Standards submitted in July, by the same author. HN discussion[2] | ||||||||
| ▲ | alex_akimov an hour ago | parent | prev | next [-] | |||||||
This makes sense, especially given that everyone should be already migrating to TLS 1.3 as fast as possible. However, as we see from past industry examples, migrations to every new standard often take decades.... Maybe the recent security incidents with AI will accelerate TLS 1.3 adoption everywhere. | ||||||||
| ▲ | BobbyTables2 3 hours ago | parent | prev | next [-] | |||||||
I don’t get it. Were there revisions or optional features of v1.2? I thought the 1.2 spec was the frozen spec. | ||||||||
| ||||||||
| ▲ | kijin 3 hours ago | parent | prev [-] | |||||||
Makes sense. Nobody wants to deal with "this user-agent claims to support TLS 1.2, except this extension that was added in 2026" anymore. If you're going to add or remove features, follow semver and bump that number. | ||||||||
| ||||||||