ietf-corpus

rfc-9155

Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2

L. Velvindron, K. Moriarty, A. Ghedini
date2021-12 streamIETF areasec wgtls statusPROPOSED STANDARD pages5 canonicalhttps://www.rfc-editor.org/rfc/rfc9155 doi10.17487/RFC9155
The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digital signatures. However, this document does not deprecate SHA-1 with Hashed Message Authentication Code (HMAC), as used in record protection. This document updates RFC 5246.

updates

Extracted elements (12)

design-rationale §1

MD5 and SHA-1 are deprecated for TLS 1.2 digital signatures because collision attacks against both algorithms have been proven practical: NIST disallowed SHA-1 for digital signatures after 2013, transcript collision attacks on TLS were identified in 2016, and full SHA-1 collisions were demonstrated in 2017 by Google and CWI Amsterdam.

tls, crypto, security

design-rationale §1

SHA-1 with HMAC as used in TLS record protection is explicitly not deprecated by this document; the deprecation applies only to digital signatures. The HMAC construction provides a distinct security profile from bare SHA-1 hashing used for signing.

tls, crypto, security

interoperability-note §1

This document updates RFC 5246 (TLS 1.2) to prohibit MD5 and SHA-1 in digital signatures. Implementations that previously negotiated these hash algorithms based on RFC 5246 behavior must be updated to comply with these stricter requirements.

tls, security

normative-requirement §2 MUST NOT

Clients MUST include the signature_algorithms extension in TLS 1.2 ClientHello messages. Clients MUST NOT include MD5 and SHA-1 in this extension.

tls, crypto, security

normative-requirement §5 MUST NOT

Clients MUST NOT include MD5 and SHA-1 in CertificateVerify messages.

tls, crypto, security

normative-requirement §4 MUST

If a client receives a ServerKeyExchange message indicating MD5 or SHA-1 as the signature hash, it MUST abort the connection with an illegal_parameter alert.

tls, crypto, security

normative-requirement §5 MUST

If a server receives a CertificateVerify message with MD5 or SHA-1, it MUST abort the connection with an illegal_parameter alert.

tls, crypto, security

normative-requirement §4 MUST NOT

Servers MUST NOT include MD5 and SHA-1 in ServerKeyExchange messages.

tls, crypto, security

normative-requirement §3 SHOULD NOT

Servers SHOULD NOT include MD5 and SHA-1 in CertificateRequest messages.

tls, crypto, security

registry §6

IANA updated the references for the TLS SignatureAlgorithm and TLS HashAlgorithm registries to include RFC 9155 in addition to RFCs 5246 and 8447.

tls, registry

registry §6

IANA updated the TLS SignatureScheme registry by changing the recommended status of rsa_pkcs1_sha1 (0x0201) and ecdsa_sha1 (0x0203) to 'N' (not recommended), referencing both RFC 8446 and RFC 9155.

tls, registry, crypto

security-consideration §7

Concerns exist with TLS 1.2 implementations falling back to SHA-1 signatures. This document deprecates MD5 and SHA-1 for digital signatures in TLS 1.2 and DTLS 1.2 to address those concerns.

tls, crypto, security