<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.2 (Ruby 3.2.2) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-tls-rfc8447bis-06" category="std" consensus="true" updates="3749, 5077, 4680, 5246, 5705, 5878, 6520, 7301, 8447" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.18.2 -->
  <front>
    <title abbrev="(D)TLS IANA Registry Updates">IANA Registry Updates for TLS and DTLS</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-tls-rfc8447bis-06"/>
    <author initials="J." surname="Salowey" fullname="Joe Salowey">
      <organization>Venafi</organization>
      <address>
        <email>joe@salowey.net</email>
      </address>
    </author>
    <author initials="S." surname="Turner" fullname="Sean Turner">
      <organization>sn3rd</organization>
      <address>
        <email>sean@sn3rd.com</email>
      </address>
    </author>
    <date year="2023" month="November" day="27"/>
    <area>Security</area>
    <workgroup>Transport Layer Security</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <?line 40?>

<t>This document updates the changes to TLS and DTLS IANA registries
made in RFC 8447. It adds a new value "D" for discouraged
to the recommended column of the selected TLS registries.</t>
      <t>This document updates the following RFCs:
3749, 5077, 4680, 5246, 5705, 5878, 6520, 7301, and 8447.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-tls-rfc8447bis/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Transport Layer Security Working Group mailing list (<eref target="mailto:tls@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/tls/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/tls/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/tlswg/rfc8447bis"/>.</t>
    </note>
  </front>
  <middle>
    <?line 49?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This document instructs IANA to make changes to a number of the IANA
registries related to Transport Layer Security (TLS) and Datagram
Transport Layer Security (DTLS). These changes update the changes made
in <xref target="RFC8447"/>.</t>
      <aside>
        <t>NOTE for IANA: This document specifies changes to the registry to update
  the changes made in <xref target="RFC8447"/>.</t>
      </aside>
      <t>This specification updates the "Recommended" column in TLS
registries to define a third value "D" for items that are discouraged.</t>
    </section>
    <section anchor="terminology">
      <name>Terminology</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="adding-recommended-column">
      <name>Adding "Recommended" Column</name>
      <t>The instructions in this document update the Recommended column,
originally added in <xref target="RFC8447"/> to add a third value, "D",
indicating that a value is "Discouraged". The permitted values
are:</t>
      <dl>
        <dt>Y:</dt>
        <dd>
          <t>Indicates that the IETF has consensus that the
  item is <bcp14>RECOMMENDED</bcp14>. This only means that the associated
  mechanism is fit for the purpose for which it was defined.
  Careful reading of the documentation for the mechanism is
  necessary to understand the applicability of that mechanism.
  The IETF could recommend mechanisms that have limited
  applicability, but will provide applicability statements that
  describe any limitations of the mechanism or necessary constraints
  on its use.</t>
        </dd>
        <dt>N:</dt>
        <dd>
          <t>Indicates that the item has not been evaluated by
  the IETF and that the IETF has made no statement about the
  suitability of the associated mechanism. This does not necessarily
  mean that the mechanism is flawed, only that no consensus exists.
  The IETF might have consensus to leave an items marked as "N" on
  the basis of it having limited applicability or usage constraints.</t>
        </dd>
        <dt>D:</dt>
        <dd>
          <t>Indicates that the item is discouraged. This marking could be used to identify
  mechanisms that might result in problems if they are used, such as
  a weak cryptographic algorithm or a mechanism that might cause
  interoperability problems in deployment. Implementers <bcp14>SHOULD</bcp14>
  consult the linked references associated with the item to
  determine the conditions under which it <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</t>
        </dd>
      </dl>
      <t>Setting a value to "Y" or "D" in the "Recommended" column requires IETF Standards
Action <xref target="RFC8126"/>.  Any state transition to or from a "Y" or "D" value requires
IESG Approval. Not all items defined in Standards Track RFCs need to be set
to "Y" or "D". Any item not otherwise specified is set to "N". The column is
blank for values that are unassigned or reserved unless specifically set.</t>
      <section anchor="rec-note">
        <name>Recommended Note</name>
        <t>Existing registries have a note on the meaning of the recommended column. For the
registries discussed in the subsequent sections this note is updated
with a sentence describing the "D" vaue as follows:</t>
        <dl>
          <dt>Note:</dt>
          <dd>
            <t>If "Recommended" column is set to "N", it does not necessarily mean
that it is flawed; rather, it indicates that the item either has not
been through the IETF consensus process, has limited applicability, or
is intended only for specific use cases.  If the "Recommended" column
is set to "D" the item is discouraged and <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</t>
          </dd>
        </dl>
      </section>
    </section>
    <section anchor="tls-extensiontype-values">
      <name>TLS ExtensionType Values</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure to:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Values with the first byte in the range 0-254 (decimal) are assigned
    via Specification Required [RFC8126].  Values with the first byte
    255 (decimal) are reserved for Private Use [RFC8126].  Setting a
    "Recommended" column value to "Y" or "D" requires Standards Action [RFC8126].
    Any state transition to or from a "Y" or "D" value requires
    IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Extension</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">4</td>
            <td align="left">truncated_hmac</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">53</td>
            <td align="left">connection_id (deprecated)</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">40</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">46</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-cipher-suites-registry">
      <name>TLS Cipher Suites Registry</name>
      <t>Several categories of ciphersuites are discouraged for general use and
are maked as "D".</t>
      <t>Ciphersuites that use NULL encryption do not provide the confidentiality
normally expected of TLS. Protocols and applications are often designed
to require confidentialy as a security property. These
ciphersuites <bcp14>MUST NOT</bcp14> be used in those cases.</t>
      <t>Ciphersuites marked as EXPORT use weak ciphers and were deprecated in
TLS 1.1 <xref target="RFC4346"/>.</t>
      <t>Cipher suites maked as anon do not provide any authentication and are
vulnerable to man-in-the-middle attacks and are deprecated in TLS 1.1
<xref target="RFC4346"/>.</t>
      <t>RC4 is a weak cipher and is deprecated in <xref target="RFC7465"/>.</t>
      <t>DES and IDEA are not considered secure for general use and are deprecated
in <xref target="RFC5469"/>.</t>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure to:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Values with the first byte in the range 0-254 (decimal) are
    assigned via Specification Required [RFC8126].  Values with the
    first byte 255 (decimal) are reserved for Private Use [RFC8126].
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries. This document does not
make any changes to the DTLS-OK column.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Cipher Suite Name</th>
            <th align="right">Recommeded</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0x00,0x01</td>
            <td align="left">TLS_RSA_WITH_NULL_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x02</td>
            <td align="left">TLS_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x03</td>
            <td align="left">TLS_RSA_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x04</td>
            <td align="left">TLS_RSA_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x05</td>
            <td align="left">TLS_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x06</td>
            <td align="left">TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x07</td>
            <td align="left">TLS_RSA_WITH_IDEA_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x08</td>
            <td align="left">TLS_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x09</td>
            <td align="left">TLS_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0B</td>
            <td align="left">TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0C</td>
            <td align="left">TLS_DH_DSS_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0E</td>
            <td align="left">TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0F</td>
            <td align="left">TLS_DH_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x11</td>
            <td align="left">TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x12</td>
            <td align="left">TLS_DHE_DSS_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x14</td>
            <td align="left">TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x15</td>
            <td align="left">TLS_DHE_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x17</td>
            <td align="left">TLS_DH_anon_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x18</td>
            <td align="left">TLS_DH_anon_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x19</td>
            <td align="left">TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1A</td>
            <td align="left">TLS_DH_anon_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1B</td>
            <td align="left">TLS_DH_anon_WITH_3DES_EDE_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1E</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x20</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x21</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x22</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x24</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x25</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x26</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x27</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x28</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x29</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2A</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2B</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2C</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2D</td>
            <td align="left">TLS_DHE_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2E</td>
            <td align="left">TLS_RSA_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x34</td>
            <td align="left">TLS_DH_anon_WITH_AES_128_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x3A</td>
            <td align="left">TLS_DH_anon_WITH_AES_256_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x3B</td>
            <td align="left">TLS_RSA_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x46</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x6C</td>
            <td align="left">TLS_DH_anon_WITH_AES_128_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x6D</td>
            <td align="left">TLS_DH_anon_WITH_AES_256_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x89</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x8A</td>
            <td align="left">TLS_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x8E</td>
            <td align="left">TLS_DHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x92</td>
            <td align="left">TLS_RSA_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x9B</td>
            <td align="left">TLS_DH_anon_WITH_SEED_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xA6</td>
            <td align="left">TLS_DH_anon_WITH_AES_128_GCM_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xA7</td>
            <td align="left">TLS_DH_anon_WITH_AES_256_GCM_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB0</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB1</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB4</td>
            <td align="left">TLS_DHE_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB5</td>
            <td align="left">TLS_DHE_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB8</td>
            <td align="left">TLS_RSA_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB9</td>
            <td align="left">TLS_RSA_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xBF</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xC5</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x01</td>
            <td align="left">TLS_ECDH_ECDSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x02</td>
            <td align="left">TLS_ECDH_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x06</td>
            <td align="left">TLS_ECDHE_ECDSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x07</td>
            <td align="left">TLS_ECDHE_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x0B</td>
            <td align="left">TLS_ECDH_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x0C</td>
            <td align="left">TLS_ECDH_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x10</td>
            <td align="left">TLS_ECDHE_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x11</td>
            <td align="left">TLS_ECDHE_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x15</td>
            <td align="left">TLS_ECDH_anon_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x16</td>
            <td align="left">TLS_ECDH_anon_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x17</td>
            <td align="left">TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x18</td>
            <td align="left">TLS_ECDH_anon_WITH_AES_128_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x19</td>
            <td align="left">TLS_ECDH_anon_WITH_AES_256_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x33</td>
            <td align="left">TLS_ECDHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x39</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x3A</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x3B</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x46</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_128_CBC_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x47</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_256_CBC_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x5A</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_128_GCM_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x5B</td>
            <td align="left">TLS_DH_anon_WITH_ARIA_256_GCM_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x84</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_128_GCM_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x85</td>
            <td align="left">TLS_DH_anon_WITH_CAMELLIA_256_GCM_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0xB4</td>
            <td align="left">TLS_SHA256_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0xB5</td>
            <td align="left">TLS_SHA384_SHA384</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-supported-groups">
      <name>TLS Supported Groups</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS Supported Groups registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration policy to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Curve</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1</td>
            <td align="left">sect163k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">sect163r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">sect163r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">sect193r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">sect193r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">sect233k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">7</td>
            <td align="left">sect233r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">sect239k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">15</td>
            <td align="left">secp160k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">16</td>
            <td align="left">secp160r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">17</td>
            <td align="left">secp160r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">18</td>
            <td align="left">secp192k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">19</td>
            <td align="left">secp192r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">20</td>
            <td align="left">secp224k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">21</td>
            <td align="left">secp224r1</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-exporter-labels-registry">
      <name>TLS Exporter Labels Registry</name>
      <t>This document updates the registration procedure for the TLS Exporter
registry and updates the Recommended column allocation.
IANA <bcp14>SHALL</bcp14> update the TLS Exporter Labels Registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure from Specification Required to
Expert Review and update it to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries</t>
        </li>
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
        <li>
          <t>update the note on the role of the expert reviewer as follows.</t>
        </li>
      </ul>
      <dl>
        <dt>Note:</dt>
        <dd>
          <t>The role of the designated expert is described in <xref target="RFC8447"/>.
Even though this registry does not require a specification, the
designated expert <xref target="RFC8126"/> will strongly encourage registrants
to provide a link to a publicly available specification. An
Internet-Draft (that is posted and never published as an RFC)
or a document from another standards body, industry consortium,
university site, etc. are suitable for these purposes.
The expert may provide more in-depth reviews, but their approval
should not be taken as an endorsement of the exporter label.  The
expert also verifies that the label is a string consisting of
printable ASCII characters beginning with "EXPORTER".  IANA <bcp14>MUST</bcp14>
also verify that one label is not a prefix of any other label.
For example, labels "key" or "master secretary" are forbidden.</t>
        </dd>
      </dl>
    </section>
    <section anchor="tls-certificate-types">
      <name>TLS Certificate Types</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the the TLS Certificate Types registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure to:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Values in the range 0-223 (decimal) are assigned via Specification
    Required [RFC8126]. Values in the range 224-255 (decimal) are
    reserved for Private Use [RFC8126]. Setting a "Recommended" column
    value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries.</t>
        </li>
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-hashalgorithm-registry">
      <name>TLS HashAlgorithm Registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the TLS HashAlgorithm Registry
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS HashAlgorithm registry to add a "Recommended" column
as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">none</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">md5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">sha1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">sha224</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">sha256</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">sha384</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">sha512</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">Intrinsic</td>
            <td align="right">Y</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-signaturealgorithm-registry">
      <name>TLS SignatureAlgorithm registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the TLS SignatureAlgorithm registry
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS SignatureAlgorithm registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">anonymous</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dsa</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">ecdsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">7</td>
            <td align="left">ed25519</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">ed448</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">gostr34102012_256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">gostr34102012_512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-clientcertificatetypes-registry">
      <name>TLS ClientCertificateTypes registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the  TLS ClientCertificateTypes
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS ClientCertificateTypes registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dss_sign</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">rsa_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">dss_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">rsa_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">dss_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">20</td>
            <td align="left">fortezza_dms_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">ecdsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">rsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">66</td>
            <td align="left">ecdsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">67</td>
            <td align="left">gost_sign256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">68</td>
            <td align="left">gost_sign512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-pskkeyexchangemode-registry">
      <name>TLS PskKeyExchangeMode registry</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS PskKeyExchangeMode registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to "Y" or "D" requires Standards
    Action [RFC8126]. Any state transition to or from a "Y" or "D"
    value requires IESG Approval.
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing recommended column "Y" and "N" entries.</t>
        </li>
        <li>
          <t>Update note on the recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="adding-comment-column">
      <name>Adding "Comment" Column</name>
      <t>IANA is requested to add a "Comment" column to the following registries:</t>
      <ul spacing="normal">
        <li>
          <t>TLS Application-Layer Protocol Negotiation (ALPN) Protocol IDs</t>
        </li>
        <li>
          <t>TLS CachedInformationType Values</t>
        </li>
        <li>
          <t>TLS Certificate Compression Algorithm IDs</t>
        </li>
        <li>
          <t>TLS Cipher Suites</t>
        </li>
        <li>
          <t>TLS ContentType</t>
        </li>
        <li>
          <t>TLS EC Point Formats</t>
        </li>
        <li>
          <t>TLS EC Curve Types</t>
        </li>
        <li>
          <t>TLS Supplemental Data Formats (SupplementalDataType)</t>
        </li>
        <li>
          <t>TLS UserMappingType Values</t>
        </li>
        <li>
          <t>TLS Authorization Data Formats</t>
        </li>
        <li>
          <t>TLS Heartbeat Message Types</t>
        </li>
        <li>
          <t>TLS Heartbeat Modes</t>
        </li>
        <li>
          <t>TLS SignatureScheme</t>
        </li>
        <li>
          <t>TLS PskKeyExchangeMode</t>
        </li>
        <li>
          <t>TLS KDF Identifiers</t>
        </li>
      </ul>
      <t>This list of registries is all registries that do not already have a
"Comment" or "Notes" column or that were not orphaned by TLS 1.3. The TLS
ExtensionType Values is not listed above because it has the "TLS 1.3"
column.</t>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The change to Specification Required from IETF Review lowers the amount
of review provided by the WG for cipher suites and supported groups.
This change reflects reality in that the WG essentially provided no
cryptographic review of the cipher suites or supported groups.  This
was especially true of national cipher suites.</t>
      <t>Recommended algorithms are regarded as secure for general use at the
time of registration; however, cryptographic algorithms and parameters
will be broken or weakened over time.  It is possible that the
"Recommended" status in the registry lags behind the most recent advances
in cryptanalysis.  Implementers and users need to check that the
cryptographic algorithms listed continue to provide the expected level
of security.</t>
      <t>Designated experts ensure the specification is publicly available.  They may
provide more in-depth reviews.  Their review should not be taken as an
endorsement of the cipher suite, extension, supported group, etc.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document is entirely about changes to TLS-related IANA registries.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-normative-references">
      <name>Normative References</name>
      <reference anchor="RFC8447">
        <front>
          <title>IANA Registry Updates for TLS and DTLS</title>
          <author fullname="J. Salowey" initials="J." surname="Salowey"/>
          <author fullname="S. Turner" initials="S." surname="Turner"/>
          <date month="August" year="2018"/>
          <abstract>
            <t>This document describes a number of changes to TLS and DTLS IANA registries that range from adding notes to the registry all the way to changing the registration policy. These changes were mostly motivated by WG review of the TLS- and DTLS-related registries undertaken as part of the TLS 1.3 development process.</t>
            <t>This document updates the following RFCs: 3749, 5077, 4680, 5246, 5705, 5878, 6520, and 7301.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="8447"/>
        <seriesInfo name="DOI" value="10.17487/RFC8447"/>
      </reference>
      <reference anchor="RFC2119">
        <front>
          <title>Key words for use in RFCs to Indicate Requirement Levels</title>
          <author fullname="S. Bradner" initials="S." surname="Bradner"/>
          <date month="March" year="1997"/>
          <abstract>
            <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="2119"/>
        <seriesInfo name="DOI" value="10.17487/RFC2119"/>
      </reference>
      <reference anchor="RFC8174">
        <front>
          <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <date month="May" year="2017"/>
          <abstract>
            <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="8174"/>
        <seriesInfo name="DOI" value="10.17487/RFC8174"/>
      </reference>
      <reference anchor="RFC8126">
        <front>
          <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
          <author fullname="M. Cotton" initials="M." surname="Cotton"/>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <author fullname="T. Narten" initials="T." surname="Narten"/>
          <date month="June" year="2017"/>
          <abstract>
            <t>Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
            <t>To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed. This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
            <t>This is the third edition of this document; it obsoletes RFC 5226.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="26"/>
        <seriesInfo name="RFC" value="8126"/>
        <seriesInfo name="DOI" value="10.17487/RFC8126"/>
      </reference>
      <reference anchor="RFC4346">
        <front>
          <title>The Transport Layer Security (TLS) Protocol Version 1.1</title>
          <author fullname="T. Dierks" initials="T." surname="Dierks"/>
          <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
          <date month="April" year="2006"/>
          <abstract>
            <t>This document specifies Version 1.1 of the Transport Layer Security (TLS) protocol. The TLS protocol provides communications security over the Internet. The protocol allows client/server applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="4346"/>
        <seriesInfo name="DOI" value="10.17487/RFC4346"/>
      </reference>
      <reference anchor="RFC7465">
        <front>
          <title>Prohibiting RC4 Cipher Suites</title>
          <author fullname="A. Popov" initials="A." surname="Popov"/>
          <date month="February" year="2015"/>
          <abstract>
            <t>This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections. This applies to all TLS versions. This document updates RFCs 5246, 4346, and 2246.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="7465"/>
        <seriesInfo name="DOI" value="10.17487/RFC7465"/>
      </reference>
      <reference anchor="RFC5469">
        <front>
          <title>DES and IDEA Cipher Suites for Transport Layer Security (TLS)</title>
          <author fullname="P. Eronen" initials="P." role="editor" surname="Eronen"/>
          <date month="February" year="2009"/>
          <abstract>
            <t>Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346) include cipher suites based on DES (Data Encryption Standard) and IDEA (International Data Encryption Algorithm) algorithms. DES (when used in single-DES mode) and IDEA are no longer recommended for general use in TLS, and have been removed from TLS version 1.2 (RFC 5246). This document specifies these cipher suites for completeness and discusses reasons why their use is no longer recommended. This memo provides information for the Internet community.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="5469"/>
        <seriesInfo name="DOI" value="10.17487/RFC5469"/>
      </reference>
      <reference anchor="RFC8996">
        <front>
          <title>*** BROKEN REFERENCE ***</title>
          <author>
            <organization/>
          </author>
          <date/>
        </front>
      </reference>
    </references>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+0823LbRpbv+Ipe5sXeImmSIqnLZJNQJB1rLMleUU7WlUqp
mkCTxAgEEDQgmYmcb9lvmS+bc043gAYIUFRsP8yuXS6bbPa59rn1tdVqWbEb
e+KEnY0uR+xKLF0ZRxv2LnR4LCRbBBG7Pp8x7jtsAh8sPp9H4u6EPZs8x/ZK
KMsJbJ+vAakT8UXcckW8aMWebEUL+6jfP5y7stUZWjb0XQbR5oTJ2LESBXvC
Dg77x0026BweNll/eNSBz73+EP497Azg36PDoyYbDnrQfnjQ6TYZYrSAowPL
csPohMVRIuNep3Pc6Vk8EvyENWbCTiI33jSs+yC6XUZBEkLrdcR9GQZRzM75
RkQs73UrNtDRAaX4sYh8EbcmKIh1J/xEnFiMPY6CsXgTggYaPwNF11+yHxEE
29fc9aAd9PEDKqYdREts5pG9guZVHIfy5MUL7IVN7p1op91eYMOLeRTcS/EC
4F8g3NKNV8lcIbxfvshV3LAsGcO43XAv8IGTDQyMXPMovvktCUjTfmCF7gn7
JQ7sJpMgRSQWEj5t1vjhV8viSbwKIhC4BYQYc30A+nubzQDjvdhQmxrnvwei
0ArMct/9ncdu4J+wn4TPFy79IJT0/wjED1L1b4N6CwRmbXadgNIjA/9McN9s
LeKX/kHkmOgldP+BWtt2sLYsP4jW0PcOxs5y/YXxrdVqMT4H4+V2bFnXK1cy
MN5kLfyYaYtk8Uowe8X9JX4OCu6g7D9S9u+CgtfcESAGu3o5JsNss7OYcceR
jDNf3LM77iWCNSYN8izHlXaQRHwpHAswI6FIAMdA3hEOswMvWfssWNAvUnjC
jqEZ6eYk27vYXgQeKBnNDxiSJ9ZTfQvlJDGUptau43jCsr5Bx4gCJ7FxAMoM
wCiCD9qxVNoBwdb8tqBC0EWynoO/aNGwn5WLBNJ5HCVFbdd4GHsGaniuBoLH
fBnxtVXfF8fqOdjVSsicEaWowvDi8IGFsD/++B4UhpJ//Aiyf8ulC+MKznPr
BPf+fzXmXmDfNr4Dm7t8cz2lsUQZTlhREzIUtrtAiQzh1SjriAnfFRsYMEqM
sC1Gvn1BjHynNa7R2+QGhXFvXOVm1EjtCNBhBDf0DNQdsXB9ASMSr9zIKdmn
G4s1IuRgw5EwzbWNRnAtorXrB16w3CBHgkHcZBg4JWtcvJtdN5rqf1QSfr6a
/ve7s6vpBD/PXo3Oz7MPlu4xe/Xm3fkk/5RDjt9cXEwvJwoYWlmhyWpcjN43
lL023ry9PntzOTpvoMRxYUBQChB6jrqFyB5GAs2MQ8YS0o7cOXwBmNPx23/+
b7cPyv8PUH6v2z3++FF/Oeoe9uHL/Ur4ilrgexv9FRS/sXgYCh4hFu55zOah
G3MPgiqH4VqB7bCViARo7z9/Qc38esK+ndtht/+dbkCBC42pzgqNpLPtli1g
pcSKpgoymTYL7SVNF/kdvS98T/VuNH77vYfW1eoefQ9GCyYzchyMRkX7HJN9
KhNKgwdYtNweP8Nlr7YCZdMKInfp+qD4DcZcNZimB1HscZyitTfR3Jvg9Q55
EnCnDF77ApBvTHLDb1AUYSGafozGQ70kVhqQTt6fWFg0ECahPYcC3PT6JVuB
DdgglvBlkv+mEh84GlIyVN1WsYTsaw35zMDGpQxsFyMkAa8FRg1XEoaFG5Pr
Yr8wicJACvp+v3LtFdBh98CFcnpwYgQfA+uLxIOYxGlsdExOda6CS4rSpKXy
s7CFlFyHMhiNiIoOxWcYeqCJuethECa8IEGGQpG/TtUDGvacPP/l/bTkK34n
mOeC2rXcBfRNNk9AOBecLoyCOwzXRfLAFigZBFLoCEPq9eDJG4WaK8PTOsil
BfFzSXEQoWKAEKJ0APpxAW0i0bEva0yAhhhNwA9iCEDCZwJNh/LcXFVNmaUo
BZZth3KCH+SSQOUSJLkRyQT4N5VtWoqh9jRJCcVLKpfrbbQ5cT+nXjQuj98L
p6mMkroAO7lJiw+QWGRpWNfucqUHzzD+gHkCm7ivkwzmVgrFEN0bQCBTyBxS
Hg2IS1jQQrURlO0rghEAFzWHB8Zjsms8UA9GUlOaQVaQjDJIsA4YWKpFwKj8
2F1sil6ncSo5IyETD0sgtMK5h5K5NBQbyj2ICQrsBFyRK9vh7F7wW2ZHmzAO
oIoJwU8hdcC8COp6sjtujIFByeaATFfNkMoCiEipJnLSPph46AUbtBYoRdeh
R4YDTspUIiAEqDDkGtUC8RrHAUIC5CkfLMO0oXvgKVdeHGgniqkO0JVUAKpW
TkTRIA88eeZBqdJkl+oXRmomYgq/aeQFjTfeN7Az1iOUC2oqm0j8lrigemVx
MwxAHKoQa0R5JEvdvSEUUYyNfB0NYKoIcZW4RWJAaBEFa6BvkFWspASss+ns
RzYKMcRwr80uwX8wzysb1mEVWc14wALWvqXyGzxN2dEci/nYKsjXJrZIr+iU
Acga3bsQvNMa0kFjBTBSy6VOQ2llJ625x/1bCtMqIeVVW+LDCLpLZAx+BSFE
dAefE98Dt89rSEyagB4Lu28KyRVkFOyPbyAwt4Az8dGypujnOFJGKUkOzpF3
gfFQhQ4w2jyhbM9s2uylSitmTYr+mEip1EjznmQuQf1UTwtdGFBVQLTctI53
LLJODp3AwMFy0+iuMrrQo5lgUNTzIpgQWSgd/AchYlFTNZtab6IhV0VOEtYi
nUOPLFT+jUUcR5Lg3JogJFzskuYGi3JDvIqCZLnKE0AeO8H2kGyTACpDIQTo
yHIlBQZSN8VrtI10tNHlIIJImD4ylLzOsyxDelBfTdykfPWoe39DE9fpB+BJ
wiBeb0LBflLFk3UGs9wIowUQwtBjx4XZkLaE7ZIPnS9Q85+mRbNNVQgbdWId
0XwOVrCHFhsTUXOapkog0ruT0AwCOv75558U/jS2LDQuXKiAIKPHImU7Inyd
Vm/QZ88cGIA1956Ta6aOSYjuXM5mhRndlYo6DvtFh69f27voEZbeYFAiknk8
GsDbyL1DzbyD8TexZrGXkFQ6QlVQzgJvHu90zM2RE8ZPibkIX4y7pHwYqhHV
8lmuUrPrwnyBUpAayrTTStW5uKShFyzrE0um5dQSyeUk1WwCLAY0N/XVyg+D
2a8IsbMbqUqIJjogFU1KoagRqif8aIswr9LTZtc3lmugkPMEqm60Szxl7Fi/
0mxHLS7IDCWI+EDmwh5yF2CP/HkouNmD9XDSwj/6v0f+PJhfTgC4DwhhPudj
3HNuVmtuV1FM/0yQ3uCAPUC081Wsv3EdtGeYqROK55Ug/Q57uErNvFauIsjw
qSC5uZhJrmK9ThmN+BCr6WeWOHElKQ2DYzfEmD+Dkh2GPl1AxxroDuo4XDig
tXG0C0ifNvWWqnNpJYbsaCl8AsOwDuaGs1FadFMFNVQXljU2cVACws6X78CA
wLiw/ETjcALKbOkUSld0C1X5ckwuajEVqwXxIVQLksAhyNSG4BLEAShBksnr
lKQSNjIULMAEMSurmEehnly8QILiMWZxvXYXUmkbb/TqnVXQRTnNqJAbZMmt
JHY+yZj+z9s3V9ekAlV/q27E+L1ADWcmBzgtHLJuu6sryf5Bf0ijqUcxw66R
c39bkzjDxOV0FFKHd1JSJKy7xMPRA4dXa6V+y/Vb0LOlllsZj2MoIWXav8ga
06xZJdauxn3M0twUjzBg/CggUICH/eGAACdTtbx9NpmOiBxKgdUHSIG5iAZG
VFldiTkrwz3oD48J9//PNK/meWkN/tfSPOEwaP6lNE9I8lnWJ2R5ldPLmf5J
WV7VPIVM/zXL/6UsX9p0SKcntNV4qyJPafsBt0Nab16n0zAoE1haJ5iJiV3y
taivFJhRLBRqhT2LhcqqAYsG1vnQ6TThn64mAuzeXM1GNz+fXb+6wZR1czEZ
bKXqCWMmcK8WGBT6COxBCValC4UCIutNv6M5eFDVRAbYryKKEN3eUZnpCrqD
XeCPsz3cyXbvZnw6zlk3EE1MJIdVPGA2IPDHmTjawQQkF6C/H57jKj4AwZ7g
pxp0AkCz2V/mYmxwoVE9kZFpEcOnqORlEU0VIw9loG63QH/6Kdro9ipwPU0d
3X4JxSfoozuowLWDnQoMhwUMN1i51Tt7PZqjCjRPc/3u8SOcPEUvozp29tbL
aR2GA0QxnUz3Q2Pa/uur08ETjaXXqYTfOyD2upXw+wezXq8SQSrAo6Pa61fC
720VvUElfCZAEUEF/LAMXzKpNCWQJkrJrHe4C9jIJwhchj3aDdvPiOp+Rejj
PdnW8pfBR3syXgN+ugfvCFqGG2uYt7PXpWqj3HNiBK3He0+NLPho74N+lduO
QGdocanVl4FGdUC9wbAW6JSVsnPKEwCVO+N6yzaF8ehien5+NtrF23C8h0AV
FIeTPWSqgDs63snpDoUcmXaXDZQZrcoAxdpguhfQcbmw3QvotEqo2XQ6qRNm
VDlgqdp/HF/UqG90uEvtGu7gqF+GO+1UKW+HRZ12dwFUUehXaXoXhcEugCoK
R7s8FSlURbvT411QVWRe7utLFUKNB/uadxF4rGdkCng6BnD4Z2teVQYwjbUM
VG2vYz2VyWGme1E6LFGa7kvq1GRve6ZY7j4uS1Q5UStBdTsFzh6lUqjaSzC7
yAxMxvLhrSUzLAuzXbpWgR1Wg2wVh2W4o2q4cnbaqgrGukSuha6OygR2cLCl
ykcipgI7rgczVhHKUKPdEBU+dXC6G6QYAMb1yXR0te38VXrsV0foq6L3I9kq
6EF1qZDSNhJDJXRlHspoV6YHAjyqLGsKMa8yJyngx2NePeUsbSjcNSSyXKGQ
FHF9pr0jtXU0S0I84wwwdKXgy++elwnWLqkb66zFJfXAc206IOj6tpc4wlhX
/7oc/X9tObqwmpxEd/j/1pYy/lVrvVBR4LGe7vDgtps5VQ8+6dYobz0wWntZ
az9tPTb7DozWvO9Qt/YOTGqHeauB4ShrPTb6djXisDvsmM3DvNnA0T00mnM2
ukdp83HPRHKcNxtIeh3d3Ov1TR118+as92cJNOlJHfL6iJ1zMDtzk7r+vknN
TlpqdSZaK48iYKomkp2Bqr1z/6+a46dv/VF4qNmlo2OPQEpEMTTeueLekADP
eX2NcyrO6SBVGaIqxrgian0ec26ZdlLAE3giPZ0o1IBGNKC4VZ6ZTDs9JHhC
Ry5NIHWWgTbSNTztrhtXSfTRU31/Z3pHR/v0yT7XyKTZmcL0SAQv3u6h2yXW
Nj3zaKs6/Q7oAn+JxzN8fUQkM3I8rw6jmB1JoMO+6j5WmMwhR+Phizu8eIhn
EQr00cis4m1I9kwdd5SQ3yk54eD5eH5FYZOr9DQEnn59btFR5sx4lGH6dM6V
yez02DxwNk08KZmQWvDcAbi0m6ybVuK7gFvSWX43Fk0mYrtNW9/q4LuXxRmZ
XX2AwbvOB3fNN5nw6yDCnfuWA1lxpYddqksEylS59gdLrugcuDq2DznyFsZQ
iQUWGERSHcXPzUiFIA9DUJvOwVuaPPdkwEAEdSMsOwNKPdVZDTwCSwfPwYmV
nwQLK4Q2Jd5oNj47w6oAbyviaZU5DKxPZ2zJ/htqnXJ61cBTnRgm8XyMldPV
h/YD36CKcsH4gwu7H1AK3C5Wo6JEsPCMrvjA8ex4U7VJ1rgVGxVR1lyiuJCH
IhHzCFq5CvhzF8oDPy9bx6ACZU4QrDfhFz71maaELaqf+TxI+exH76DmiOf2
uQ9CU3X2owo15PjW1pkPwrDP8c7dycdICV8TUDEBtT/rzO0Vl6tRdrXDrKco
I6iTXB3iIT1wVj6LpuP98THE+6bu1aPAb9GlRjqLRSe9gzVozF2LNnuym1nb
bsbqq64aqZ48STT87Gv9VNLUtp7NG8TqSmONaxfUn8/MJlClyMhVpz6rz/wy
VjrHs3W6l+HMxMd08sDeMz2bY2tnkK/70ExuxUuTuBWHgFacwUETraq8z6dv
K66WUN7nc7cVH3R7WRNOo/AmuguDZutWrfnPsM5CpRYY5LbS/91ddpdoX/32
M/vtDmXXOK/FskKn4LxP8N3yEbxq18W10M06SOQDu8zcN5I8czB0NYe+X2bO
K2zH6IELHMKB0oQWL3K3FE6/f5T7LrrxEqYJ0UG/2+l1ur0b5e0K7XCw9bNy
88vP4tC6APVcGD2jICzWg//OPr1Dvq/+/Ln9+RE7qvPpSo9+Sjrew6e1+97g
lKPkwzJtzB0Ze8KkTzg3zir7oa97b/0w0BAiXMGMN+Ie/HhzNZ1Nr36aTgoL
rAi+uxetaC5wovz77/zGWcsKRP001BSlGQ4KnEOPnMXhMIOp+vVQBxlCWAg/
R+Yvnz/yvJW3r8Vm+kG5+kXgCCPqfOHNmx20v0aELzGxrLCQLzexzB9UGRNY
nD+mQiZBS4y/JULq15R0YMo6axL6WkC+E5TfxybLQEMa5de5Wup5pfS6F7sU
yyB2lbE8G52/vXye/3Y2kRrBmNsr4Zylz28VbwC3tlZrgEdIt5KuLOaVk4HO
vEGXtgV44zlGxLplOmZvAxeG9CVRlXmz2ppSObKV7XOq9xG4R49KpUDsmfkT
/oJgzzXYOymiCx6GoLdtiUb0gpp+qayAVHd4JXgUzwWP2QXeJV8WWTJ+Bc/N
GE0rypmNUVa3bnu6/uH15CU7U09XuCKSev8GdxRxvc+4eo9rkJ5nttByob7J
xj18IWajb/pbuRGh++EKuczsiZZhAZLKJnrOIAqBK3rpRFdLB+oBA/hiVV7b
0iuTet+TzwMgOhf06IV6CUQ/dKWxpfmVfCJ792usr62pS4jqgSFbr/MFdfs7
FFjozr3e3cFn6iJFjkOx7McWqY1+08vJJBh2+PlHKvvswsVA9H2ZbaLT24G0
MO2m74JhmMHH3dBb6ZKlCvt6gRhwgmmo25HeJifpB1bx2RDNk16KLvKAtWiZ
BUY3hyx8EUjQaj/hj6OENjh80gveRTUR4dVCI0ZlL5VIfQltCdFcrfvXXRRU
D9ZgTWyYH9H6G1uBqu/wuYSa91CULkMe8TW+OgK845YHlNzzKMB1eXzoSOAK
Pd5KxZ0IVXrjI3xqn0K6dM0yfXupmLEw0yT5wmuaJj2+xKX2laufNVpDpYCB
ml7gce44vpKClx2JZw4a20iX3lUwn1uhLUKJn9JXQMB37duclVqJtQvYENtc
X6VS83pudgvXA815aJrp1Vm8zFneMIKR9iWl8lVph4cUtLULpHYwNrh1Yu3c
OlEd3Sg1wtpdE6ti18S0sCZwquNBs2yyas+HVmgovW37d+EdQhQ2Bp9Ggeil
pOIrjq30mcHSI45IAJe/5ty+tf4F1j5kgSJVAAA=

-->

</rfc>
