Compliance / IETF
IETF RFC Deprecation Track
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
We curated 11 rules from the RFC deprecation trail - RFC 8996 (TLS 1.0 and 1.1), RFC 8429 (3DES and RC4 out of Kerberos), RFC 6151 (MD5) and RFC 6194 (SHA-1). Where a regulator tells you what an auditor expects, these tell you what the internet's own standards body has already retired.
Why does an IETF channel matter?
Regulatory baselines tell you what an auditor expects; the RFC track tells you what the internet itself has retired. A TLS endpoint still negotiating TLS 1.0 is not just a compliance finding, it is running a protocol version the IETF formally deprecated in RFC 8996. Grading against the RFC trail catches this class regardless of which regulator applies to you.
Which RFC retired what, and the rule that finds it
Each row is a deprecation the IETF published and the Korthex rule that detects it. The status column is the rule's own verdict in the baseline registry, not a restatement of the RFC.
| RFC | What it retired | Korthex rule | Status |
|---|---|---|---|
| RFC 8996 | TLS 1.0 | PROTO-E-TLS10 | disallowed |
| RFC 8996 | TLS 1.1 | PROTO-E-TLS11 | disallowed |
| RFC 7568 | SSL 3.0 | PROTO-E-SSL3 | disallowed |
| RFC 6176 | SSL 2.0 | PROTO-E-SSL2 | disallowed |
| RFC 9147 | DTLS 1.0 | PROTO-E-DTLS10 | disallowed |
| RFC 8429 | 3DES in Kerberos | SYM-E-3DES | disallowed |
| RFC 8429 | RC4 in Kerberos | SYM-E-RC4 | disallowed |
| RFC 6151 | MD5 for signatures | HASH-E-MD5 | disallowed |
| RFC 6194 | SHA-1 for signatures | HASH-E-SHA1 | deprecated |
What does the channel track?
- RFC 8996: TLS 1.0 and TLS 1.1 deprecated, TLS 1.2+ required
- RFC 8429: 3DES and RC4 removed from Kerberos suites
- RFC 6151: MD5 no longer acceptable where collision resistance matters
- RFC 6194: SHA-1 security considerations and migration expectations
- Tagged as IETF-Standard on every finding the channel grades
Frequently asked questions
Who should activate the IETF channel?
Everyone running TLS. It is part of the recommended global profile (NIST + BSI + IETF + OWASP) because protocol deprecations apply regardless of jurisdiction.
How does this differ from the TLS audit itself?
The TLS certificate audit finds the configurations; the IETF channel supplies the deprecation rules they are graded against, with the RFC reference attached to each finding.
Is the channel updated when new RFCs land?
Yes, through the same 24-hour signed update cycle as every other channel.