Transport Layer Security (tls)

Last Modified: 2011-05-31

Additional information is available at tools.ietf.org/wg/tls

Chair(s):

Security Area Director(s):

Security Area Advisor:

Technical Advisor(s):

Mailing Lists:

General Discussion: tls@ietf.org
To Subscribe: https://www.ietf.org/mailman/listinfo/tls
Archive: http://www.ietf.org/mail-archive/web/tls/

Description of Working Group:

The TLS Working Group was established in 1996 to standardize a
'transport layer' security protocol. The working group began with SSL
version 3.0. The TLS Working Group has completed a series of
specifications that describe the Transport Layer Security protocol
versions 1.0, 1.1, and 1.2, extensions to the protocol, and new
ciphersuites to be used with TLS.

The primary goals of the WG are to maintain:
- The TLS protocol, RFC 5246;
- The DTLS protocol, draft-ietf-tls-rfc4347-bis.

Significant changes to the protocol, such as a new version 1.3, are not
within scope of the working group unless they are explicitly added to
the charter.

The secondary goals of the WG are to publish:
- Guidelines for Specifying the Use of TLS/DTLS;
- Recommendations for use of TLS (e.g., server ID);
- Extensions to TLS and DTLS; and,
- Cipher suites.

Goals and Milestones:

Done  Agreement on charter and issues in current draft.
Done  Final draft for Secure Transport Layer Protocol ('STLP')
Done  Working group 'Last Call'
Done  Submit to IESG for consideration as a Proposed Standard.
Done  First revised draft of TLS specification
Done  TSL 1.1 Specification
Done  First draft of TLS 1.2 specification, including CTR mode cipher suites
Done  First draft of specification for cipher suites with combined encryption/authentication modes
Dec 2011  Heartbeat Extension Sent to IESG

Internet-Drafts:

Datagram Transport Layer Security version 1.2 (70296 bytes)
Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) Heartbeat Extension (13055 bytes)

Request For Comments:

The TLS Protocol Version 1.0 (RFC 2246) (170401 bytes) obsoleted by RFC 4346/ updated by RFC 3546,RFC 5746,RFC 6176
Addition of Kerberos Cipher Suites to Transport Layer Security (TLS) (RFC 2712) (13763 bytes)
Upgrading to TLS Within HTTP/1.1 (RFC 2817) (27598 bytes) updates RFC 2616
HTTP Over TLS (RFC 2818) (15170 bytes) updated by RFC 5785
AES Ciphersuites for TLS (RFC 3268) (13530 bytes) obsoleted by RFC 5246
Transport Layer Security (TLS) Extensions (RFC 3546) (63437 bytes) obsoleted by RFC 4366/ updates RFC 2246
Transport Layer Security Protocol Compression Methods (RFC 3749) (16411 bytes)
Addition of Camellia Cipher Suites to Transport Layer Security (TLS) (RFC 4132) (13590 bytes) obsoleted by RFC 5932
Pre-Shared Key Ciphersuites for Transport Layer Security (TLS) (RFC 4279) (32160 bytes)
The The Transport Layer Security (TLS) Protocol Version 1.1 (RFC 4346) (187041 bytes) obsoletes RFC 2246/ obsoleted by RFC 5246/ updated by RFC 4366,RFC 4680,RFC 4681,RFC 5746,RFC 6176
Transport Layer Security (TLS) Extensions (RFC 4366) (66040 bytes) obsoletes RFC 3546/ obsoleted by RFC 5246,RFC 6066/ updates RFC 4346/ updated by RFC 5746
Elliptic Curve Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS) (RFC 4492) (72231 bytes) updated by RFC 5246
Pre-Shared Key (PSK) Cipher Suites with NULL Encryption for Transport Layer Security (TLS) (RFC 4785) (9550 bytes)
Using OpenPGP keys for TLS authentication (RFC 5081) (15300 bytes) obsoleted by RFC 6091
Using the Secure Remote Password (SRP) Protocol for TLS Authentication (RFC 5054) (44445 bytes)
The Transport Layer Security (TLS) Protocol Version 1.2 (RFC 5246) (222395 bytes) obsoletes RFC 3268,RFC 4346,RFC 4366/ updates RFC 4492/ updated by RFC 5746,RFC 5878,RFC 6176
AES Galois Counter Mode (GCM) Cipher Suites for TLS (RFC 5288) (16468 bytes)
TLS Elliptic Curve Cipher Suites with SHA-256/384 and AES Galois Counter Mode (GCM) (RFC 5289) (12195 bytes)
DES and IDEA Cipher Suites for Transport Layer Security (TLS) (RFC 5469) (8558 bytes)
Pre-Shared Key Cipher Suites for TLS with SHA-256/384 and AES Galois Counter Mode (RFC 5487) (15537 bytes)
ECDHE_PSK Cipher Suites for Transport Layer Security (TLS) (RFC 5489) (14194 bytes)
Transport Layer Security (TLS) Renegotiation Indication Extension (RFC 5746) (33790 bytes) updates RFC 5246,RFC 4366,RFC 4347,RFC 4346,RFC 2246
Keying Material Exporters for Transport Layer Security (TLS) (RFC 5705) (16346 bytes)
Transport Layer Security (TLS) Extensions: Extension Definitions (RFC 6066) (55079 bytes) obsoletes RFC 4366
Prohibiting Secure Sockets Layer (SSL) Version 2.0 (RFC 6176) (7642 bytes) updates RFC 2246,RFC 4346,RFC 5246