互联网工程任务组(IETF)发布了RFC 10015标准文件,规定弃用TLS 1.2和DTLS 1.2中的多种过时密钥交换方法[1]。被弃用的方法包括有限域上的Diffie-Hellman(FFDH)、RSA和静态椭圆曲线Diffie-Hellman(ECDH)密码套件[1]。该决定针对这些算法存在的已知安全漏洞,包括Raccoon攻击、Bleichenbacher攻击、Invalid Curve攻击以及缺乏前向保密性[1]。此外,1024位FFDHE组仅提供相对于795位离散对数记录的微小安全边际[1]。
根据新标准,客户端禁止提供非临时FFDH密码套件,服务器也禁止选择这些套件[1]。RFC 10015同时更新了18项相关RFC文件[1]。互联网号码分配局(IANA)将在"TLS密码套件"注册表中把受影响的密码套件标记为"D"(已弃用)[1]。
The Internet Engineering Task Force (IETF) has published RFC 10015, a new standard that deprecates outdated key exchange methods in TLS 1.2 and DTLS 1.2 protocols [1]. The deprecated methods include finite field Diffie-Hellman (FFDH), RSA, and static elliptic curve Diffie-Hellman (ECDH) cipher suites [1].
The deprecation addresses multiple known security vulnerabilities affecting these algorithms [1]. The deprecated methods are vulnerable to Raccoon attacks, Bleichenbacher attacks, Invalid Curve attacks, and lack forward secrecy [1]. Additionally, 1024-bit FFDHE groups provide only minimal security margin relative to 795-bit discrete logarithm records [1]. Under the new policy, clients must not offer non-ephemeral FFDH cipher suites, and servers must not select them [1].
RFC 10015 updates 18 existing RFCs and establishes that affected cipher suites will be marked with a "D" (deprecated) designation in the IANA "TLS Cipher Suite" registry [1].