KORTHEXkorthex.io

Compliance / IETF

IETF RFC Deprecation Track

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

We curated 11 rules from the RFC deprecation trail - RFC 8996 (TLS 1.0 and 1.1), RFC 8429 (3DES and RC4 out of Kerberos), RFC 6151 (MD5) and RFC 6194 (SHA-1). Where a regulator tells you what an auditor expects, these tell you what the internet's own standards body has already retired.

Why does an IETF channel matter?

Regulatory baselines tell you what an auditor expects; the RFC track tells you what the internet itself has retired. A TLS endpoint still negotiating TLS 1.0 is not just a compliance finding, it is running a protocol version the IETF formally deprecated in RFC 8996. Grading against the RFC trail catches this class regardless of which regulator applies to you.

Which RFC retired what, and the rule that finds it

Each row is a deprecation the IETF published and the Korthex rule that detects it. The status column is the rule's own verdict in the baseline registry, not a restatement of the RFC.

IETF deprecations mapped to Korthex rule IDs.
RFCWhat it retiredKorthex ruleStatus
RFC 8996TLS 1.0PROTO-E-TLS10disallowed
RFC 8996TLS 1.1PROTO-E-TLS11disallowed
RFC 7568SSL 3.0PROTO-E-SSL3disallowed
RFC 6176SSL 2.0PROTO-E-SSL2disallowed
RFC 9147DTLS 1.0PROTO-E-DTLS10disallowed
RFC 84293DES in KerberosSYM-E-3DESdisallowed
RFC 8429RC4 in KerberosSYM-E-RC4disallowed
RFC 6151MD5 for signaturesHASH-E-MD5disallowed
RFC 6194SHA-1 for signaturesHASH-E-SHA1deprecated

What does the channel track?

  • RFC 8996: TLS 1.0 and TLS 1.1 deprecated, TLS 1.2+ required
  • RFC 8429: 3DES and RC4 removed from Kerberos suites
  • RFC 6151: MD5 no longer acceptable where collision resistance matters
  • RFC 6194: SHA-1 security considerations and migration expectations
  • Tagged as IETF-Standard on every finding the channel grades

Frequently asked questions

Who should activate the IETF channel?

Everyone running TLS. It is part of the recommended global profile (NIST + BSI + IETF + OWASP) because protocol deprecations apply regardless of jurisdiction.

How does this differ from the TLS audit itself?

The TLS certificate audit finds the configurations; the IETF channel supplies the deprecation rules they are graded against, with the RFC reference attached to each finding.

Is the channel updated when new RFCs land?

Yes, through the same 24-hour signed update cycle as every other channel.