IETF 发布了 RFC 9851 标准文档,宣布 TLS 1.2 协议进入功能冻结状态[1]。根据该文档,TLS 1.2 后续仅允许三类更改:紧急安全修复、新的 TLS Exporter 标签和新的 ALPN 协议 ID[1]。这一限制措施不适用于 DTLS[1]。
这项决定旨在推动用户升级至 TLS 1.3,以应对 TLS 1.2 的已知缺陷以及量子计算时代的密码学安全挑战[1]。2024 年 NIST 发布了 ML-KEM、ML-DSA 和 SLH-DSA 等后量子密码学标准[1],其中后量子密码学(PQC)支持工作重点放在 TLS 1.3 或更高版本,不支持 TLS 1.2[1]。此外,任何在 RFC 9851 发布后添加的 TLS 条目应标注为"仅适用于 TLS 1.3 或更高版本"[1]。
The Internet Engineering Task Force (IETF) has released RFC 9851, placing TLS 1.2 into feature freeze status.[1] Under this new constraint, modifications to TLS 1.2 are restricted to three categories: emergency security fixes, new TLS Exporter labels, and new ALPN protocol identifiers.[1] This policy does not apply to DTLS.[1]
The feature freeze represents a strategic effort to encourage migration toward TLS 1.3 and later versions, which incorporate fixes for known TLS 1.2 vulnerabilities.[1] The restriction is particularly significant given the cryptographic landscape shift toward post-quantum security. In 2024, NIST published post-quantum cryptography standards including ML-KEM, ML-DSA, and SLH-DSA.[1] Post-quantum cryptography support efforts are being directed exclusively toward TLS 1.3 or later versions, with no planned support for TLS 1.2.[1] Any new TLS entries added following RFC 9851's publication should be marked as "For TLS 1.3 or later."[1]