Internet Engineering Task Force (IETF) S. Turner
Request for Comments: 6176 IECA
Updates: 2246, 4346, 5246 T. Polk
Category: Standards Track NIST
ISSN: 2070-1721 March 2011
Prohibiting Secure Sockets Layer (SSL) Version 2.0
Turner & Polk Standards Track [Page 1]
RFC 6176 Prohibiting SSL 2.0 March 2011 1. IntroductionMany protocols specified in the IETF rely on Transport Layer Security (TLS) [TLS1.0][TLS1.1][TLS1.2] for security services. This is a good thing, but some TLS clients and servers also support negotiating the use of Secure Sockets Layer (SSL) version 2.0 [SSL2]; however, this version does not provide a sufficiently high level of security. SSL version 2.0 has known deficiencies. This document describes those deficiencies, and it requires that TLS clients and servers never negotiate the use of SSL version 2.0.
1.1. Requirements Terminology
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
2. SSL 2.0 Deficiencies
SSL version 2.0 [SSL2] deficiencies include the following:
Turner & Polk Standards Track [Page 2]
RFC 6176 Prohibiting SSL 2.0 March 2011 3. Changes to TLSBecause of the deficiencies noted in the previous section:
4. Security Considerations
This entire document is about security considerations.
5. Acknowledgements
The idea for this document was inspired by discussions between Peter Saint Andre, Simon Josefsson, and others on the Extensible Messaging and Presence Protocol (XMPP) mailing list.
Turner & Polk Standards Track [Page 3]
RFC 6176 Prohibiting SSL 2.0 March 2011 6. References 6.1. Normative References[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
6.2. Informative References
[MD5] Rivest, R., "The MD5 Message-Digest Algorithm", RFC 1321,