<?xml version='1.0' encoding='utf-8'?>
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" version="3" ipr="trust200902" docName="draft-ietf-tls-rfc8447bis-15" category="std" consensus="true" submissionType="IETF" number="9847" updates="8447" tocInclude="true" sortRefs="true" symRefs="true" prepTime="2025-12-24T10:34:26" indexInclude="true" scripts="Common,Latin" tocDepth="3">
  <link href="https://datatracker.ietf.org/doc/draft-ietf-tls-rfc8447bis-15" rel="prev"/>
  <link href="https://dx.doi.org/10.17487/rfc9847" rel="alternate"/>
  <link href="urn:issn:2070-1721" rel="alternate"/>
  <front>
    <title abbrev="TLS and DTLS IANA Registry Updates">IANA Registry Updates for TLS and DTLS</title>
    <seriesInfo name="RFC" value="9847" stream="IETF"/>
    <author initials="J." surname="Salowey" fullname="Joe Salowey">
      <organization showOnFrontPage="true">CyberArk</organization>
      <address>
        <email>joe@salowey.net</email>
      </address>
    </author>
    <author initials="S." surname="Turner" fullname="Sean Turner">
      <organization showOnFrontPage="true">sn3rd</organization>
      <address>
        <email>sean@sn3rd.com</email>
      </address>
    </author>
    <date month="12" year="2025"/>
    <area>SEC</area>
    <workgroup>TLS</workgroup>
    <abstract pn="section-abstract">
      <t indent="0" pn="section-abstract-1">This document updates the changes to the TLS and DTLS IANA registries
made in RFC 8447. It adds a new value, "D" for discouraged,
to the "Recommended" column of the selected TLS registries and
adds a "Comment" column to all active registries that do not
already have a "Comment" column. Finally, it updates the
registration request instructions.</t>
      <t indent="0" pn="section-abstract-2">This document updates RFC 8447.</t>
    </abstract>
    <boilerplate>
      <section anchor="status-of-memo" numbered="false" removeInRFC="false" toc="exclude" pn="section-boilerplate.1">
        <name slugifiedName="name-status-of-this-memo">Status of This Memo</name>
        <t indent="0" pn="section-boilerplate.1-1">
            This is an Internet Standards Track document.
        </t>
        <t indent="0" pn="section-boilerplate.1-2">
            This document is a product of the Internet Engineering Task Force
            (IETF).  It represents the consensus of the IETF community.  It has
            received public review and has been approved for publication by
            the Internet Engineering Steering Group (IESG).  Further
            information on Internet Standards is available in Section 2 of 
            RFC 7841.
        </t>
        <t indent="0" pn="section-boilerplate.1-3">
            Information about the current status of this document, any
            errata, and how to provide feedback on it may be obtained at
            <eref target="https://www.rfc-editor.org/info/rfc9847" brackets="none"/>.
        </t>
      </section>
      <section anchor="copyright" numbered="false" removeInRFC="false" toc="exclude" pn="section-boilerplate.2">
        <name slugifiedName="name-copyright-notice">Copyright Notice</name>
        <t indent="0" pn="section-boilerplate.2-1">
            Copyright (c) 2025 IETF Trust and the persons identified as the
            document authors. All rights reserved.
        </t>
        <t indent="0" pn="section-boilerplate.2-2">
            This document is subject to BCP 78 and the IETF Trust's Legal
            Provisions Relating to IETF Documents
            (<eref target="https://trustee.ietf.org/license-info" brackets="none"/>) in effect on the date of
            publication of this document. Please review these documents
            carefully, as they describe your rights and restrictions with
            respect to this document. Code Components extracted from this
            document must include Revised BSD License text as described in
            Section 4.e of the Trust Legal Provisions and are provided without
            warranty as described in the Revised BSD License.
        </t>
      </section>
    </boilerplate>
    <toc>
      <section anchor="toc" numbered="false" removeInRFC="false" toc="exclude" pn="section-toc.1">
        <name slugifiedName="name-table-of-contents">Table of Contents</name>
        <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1">
          <li pn="section-toc.1-1.1">
            <t indent="0" keepWithNext="true" pn="section-toc.1-1.1.1"><xref derivedContent="1" format="counter" sectionFormat="of" target="section-1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-introduction">Introduction</xref></t>
          </li>
          <li pn="section-toc.1-1.2">
            <t indent="0" keepWithNext="true" pn="section-toc.1-1.2.1"><xref derivedContent="2" format="counter" sectionFormat="of" target="section-2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-terminology">Terminology</xref></t>
          </li>
          <li pn="section-toc.1-1.3">
            <t indent="0" pn="section-toc.1-1.3.1"><xref derivedContent="3" format="counter" sectionFormat="of" target="section-3"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-updating-recommended-column">Updating "Recommended" Column's Values</xref></t>
            <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.3.2">
              <li pn="section-toc.1-1.3.2.1">
                <t indent="0" keepWithNext="true" pn="section-toc.1-1.3.2.1.1"><xref derivedContent="3.1" format="counter" sectionFormat="of" target="section-3.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-recommended-note">Recommended Note</xref></t>
              </li>
            </ul>
          </li>
          <li pn="section-toc.1-1.4">
            <t indent="0" pn="section-toc.1-1.4.1"><xref derivedContent="4" format="counter" sectionFormat="of" target="section-4"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-extensiontype-values-re">TLS ExtensionType Values Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.5">
            <t indent="0" pn="section-toc.1-1.5.1"><xref derivedContent="5" format="counter" sectionFormat="of" target="section-5"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-cipher-suites-registry">TLS Cipher Suites Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.6">
            <t indent="0" pn="section-toc.1-1.6.1"><xref derivedContent="6" format="counter" sectionFormat="of" target="section-6"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-supported-groups-regist">TLS Supported Groups Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.7">
            <t indent="0" pn="section-toc.1-1.7.1"><xref derivedContent="7" format="counter" sectionFormat="of" target="section-7"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-exporter-labels-registr">TLS Exporter Labels Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.8">
            <t indent="0" pn="section-toc.1-1.8.1"><xref derivedContent="8" format="counter" sectionFormat="of" target="section-8"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-certificate-types-regis">TLS Certificate Types Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.9">
            <t indent="0" pn="section-toc.1-1.9.1"><xref derivedContent="9" format="counter" sectionFormat="of" target="section-9"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-hashalgorithm-registry">TLS HashAlgorithm Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.10">
            <t indent="0" pn="section-toc.1-1.10.1"><xref derivedContent="10" format="counter" sectionFormat="of" target="section-10"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-signaturealgorithm-regi">TLS SignatureAlgorithm Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.11">
            <t indent="0" pn="section-toc.1-1.11.1"><xref derivedContent="11" format="counter" sectionFormat="of" target="section-11"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-clientcertificatetype-i">TLS ClientCertificateType Identifiers Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.12">
            <t indent="0" pn="section-toc.1-1.12.1"><xref derivedContent="12" format="counter" sectionFormat="of" target="section-12"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-pskkeyexchangemode-regi">TLS PskKeyExchangeMode Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.13">
            <t indent="0" pn="section-toc.1-1.13.1"><xref derivedContent="13" format="counter" sectionFormat="of" target="section-13"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-tls-signaturescheme-registr">TLS SignatureScheme Registry</xref></t>
          </li>
          <li pn="section-toc.1-1.14">
            <t indent="0" pn="section-toc.1-1.14.1"><xref derivedContent="14" format="counter" sectionFormat="of" target="section-14"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-adding-comment-column">Adding "Comment" Column</xref></t>
          </li>
          <li pn="section-toc.1-1.15">
            <t indent="0" pn="section-toc.1-1.15.1"><xref derivedContent="15" format="counter" sectionFormat="of" target="section-15"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-expert-review-of-current-an">Expert Review of Current and Potential IETF and IRTF Documents</xref></t>
          </li>
          <li pn="section-toc.1-1.16">
            <t indent="0" pn="section-toc.1-1.16.1"><xref derivedContent="16" format="counter" sectionFormat="of" target="section-16"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-registration-requests">Registration Requests</xref></t>
          </li>
          <li pn="section-toc.1-1.17">
            <t indent="0" pn="section-toc.1-1.17.1"><xref derivedContent="17" format="counter" sectionFormat="of" target="section-17"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-security-considerations">Security Considerations</xref></t>
          </li>
          <li pn="section-toc.1-1.18">
            <t indent="0" pn="section-toc.1-1.18.1"><xref derivedContent="18" format="counter" sectionFormat="of" target="section-18"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-iana-considerations">IANA Considerations</xref></t>
          </li>
          <li pn="section-toc.1-1.19">
            <t indent="0" pn="section-toc.1-1.19.1"><xref derivedContent="19" format="counter" sectionFormat="of" target="section-19"/>. <xref derivedContent="" format="title" sectionFormat="of" target="name-normative-references">Normative References</xref></t>
          </li>
          <li pn="section-toc.1-1.20">
            <t indent="0" pn="section-toc.1-1.20.1"><xref derivedContent="" format="none" sectionFormat="of" target="section-appendix.a"/><xref derivedContent="" format="title" sectionFormat="of" target="name-authors-addresses">Authors' Addresses</xref></t>
          </li>
        </ul>
      </section>
    </toc>
  </front>
  <middle>
    <section anchor="introduction" numbered="true" removeInRFC="false" toc="include" pn="section-1">
      <name slugifiedName="name-introduction">Introduction</name>
      <t indent="0" pn="section-1-1">This document instructs IANA to make changes to a number of the IANA
registries related to Transport Layer Security (TLS) and Datagram
Transport Layer Security (DTLS). These changes update the changes made
in <xref target="RFC8447" format="default" sectionFormat="of" derivedContent="RFC8447"/>.</t>
      <t indent="0" pn="section-1-2">This specification adds a new value, "D" for discouraged, to the "Recommended"
column of the selected TLS registries and adds a "Comment" column to all
active registries that do not already have a "Comment" column.</t>
      <t indent="0" pn="section-1-3">This specification also updates the registration request instructions.</t>
    </section>
    <section anchor="terminology" numbered="true" removeInRFC="false" toc="include" pn="section-2">
      <name slugifiedName="name-terminology">Terminology</name>
      <t indent="0" pn="section-2-1">The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119" format="default" sectionFormat="of" derivedContent="RFC2119"/> <xref target="RFC8174" format="default" sectionFormat="of" derivedContent="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
    </section>
    <section anchor="updating-recommended-columns-values" numbered="true" removeInRFC="false" toc="include" pn="section-3">
      <name slugifiedName="name-updating-recommended-column">Updating "Recommended" Column's Values</name>
      <t indent="0" pn="section-3-1">The instructions in this document update the "Recommended" column,
originally added in <xref target="RFC8447" format="default" sectionFormat="of" derivedContent="RFC8447"/> to add a third value, "D",
indicating that a value is discouraged. The permitted values
of the "Recommended" column are:</t>
      <dl indent="3" newline="false" spacing="normal" pn="section-3-2">
        <dt pn="section-3-2.1">Y:</dt>
        <dd pn="section-3-2.2">
          <t indent="0" pn="section-3-2.2.1">Indicates that the IETF has consensus that the
  item is <bcp14>RECOMMENDED</bcp14>. This only means that the associated
  mechanism is fit for the purpose for which it was defined.
  Careful reading of the documentation for the mechanism is
  necessary to understand the applicability of that mechanism.
  The IETF could recommend mechanisms that have limited
  applicability but will provide applicability statements that
  describe any limitations of the mechanism or necessary constraints
  on its use.</t>
        </dd>
        <dt pn="section-3-2.3">N:</dt>
        <dd pn="section-3-2.4">
          <t indent="0" pn="section-3-2.4.1">Indicates that the item has not been evaluated by
  the IETF and that the IETF has made no statement about the
  suitability of the associated mechanism. This does not necessarily
  mean that the mechanism is flawed, only that no consensus exists.
  The IETF might have consensus to leave an item marked as "N" on
  the basis of the item having limited applicability or usage constraints.</t>
        </dd>
        <dt pn="section-3-2.5">D:</dt>
        <dd pn="section-3-2.6">
          <t indent="0" pn="section-3-2.6.1">Indicates that the item is discouraged. This marking could be used to identify
  mechanisms that might result in problems if they are used, such as
  a weak cryptographic algorithm or a mechanism that might cause
  interoperability problems in deployment. When marking a registry entry as
  "D", either the "Reference" or the "Comment" column <bcp14>MUST</bcp14> include sufficient
  information to determine why the marking has been applied. Implementers and
  users <bcp14>SHOULD</bcp14> consult the linked references associated with the item to
  determine the conditions under which the item <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</t>
        </dd>
      </dl>
      <t indent="0" pn="section-3-3">Setting a value to "Y" or "D" or transitioning the value from "Y" or "D" in the "Recommended" column requires
IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>. Not all items defined
in Standards Track RFCs need to be set
to "Y" or "D". Any item not otherwise specified is set to "N". The column is
blank for values that are unassigned or reserved unless specifically set.</t>
      <section anchor="rec-note" numbered="true" removeInRFC="false" toc="include" pn="section-3.1">
        <name slugifiedName="name-recommended-note">Recommended Note</name>
        <t indent="0" pn="section-3.1-1">Existing registries have a note on the meaning of the "Recommended" column. For the
registries discussed in the subsequent sections, this note is updated
with a sentence describing the "D" value as follows:</t>
        <blockquote pn="section-3.1-2">
          <t indent="0" pn="section-3.1-2.1">Note: If the "Recommended" column is set to "N", it does not necessarily mean
that it is flawed; rather, it indicates that the item has not
been through the IETF consensus process, has limited applicability, or
is intended only for specific use cases.  If the "Recommended" column
is set to "D", the item is discouraged and <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used,
depending upon the situation; consult the item's references for clarity.</t>
        </blockquote>
      </section>
    </section>
    <section anchor="tls-extensiontype-values-registry" numbered="true" removeInRFC="false" toc="include" pn="section-4">
      <name slugifiedName="name-tls-extensiontype-values-re">TLS ExtensionType Values Registry</name>
      <t indent="0" pn="section-4-1">In order to reflect the changes in the "Recommended" column allocation,
IANA has updated the "TLS ExtensionType Values" registry as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-4-2">
        <li pn="section-4-2.1">
          <t indent="0" pn="section-4-2.1.1">Adjusted the registration procedure related to setting the "Recommended" column as follows:  </t>
          <t indent="0" pn="section-4-2.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D" in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-4-2.2">
          <t indent="0" pn="section-4-2.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-4-2.3">
          <t indent="0" pn="section-4-2.3.1">Updated the "Recommended" column with the changes listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in the following table.
IANA has added a reference to this document for these entries.</t>
        </li>
      </ul>
      <table align="center" pn="table-1">
        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Value</th>
            <th align="left" colspan="1" rowspan="1">Extension Name</th>
            <th align="right" colspan="1" rowspan="1">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">4</td>
            <td align="left" colspan="1" rowspan="1">truncated_hmac</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">40</td>
            <td align="left" colspan="1" rowspan="1">Reserved</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">46</td>
            <td align="left" colspan="1" rowspan="1">Reserved</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">53</td>
            <td align="left" colspan="1" rowspan="1">connection_id (deprecated)</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-4-4">
        <li pn="section-4-4.1">
          <t indent="0" pn="section-4-4.1.1">Updated the note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
        <li pn="section-4-4.2">
          <t indent="0" pn="section-4-4.2.1">For the truncated_hmac, added the following link to the "Reference" column: <eref target="https://www.iacr.org/archive/asiacrypt2011/70730368/70730368.pdf" brackets="none"/>.</t>
        </li>
        <li pn="section-4-4.3">
          <t indent="0" pn="section-4-4.3.1">For the two Reserved values above, added the following link in the "Reference" column: <eref target="https://mailarchive.ietf.org/arch/msg/tls-reg-review/5BD62HBFjo_AsW-Y8ohVuWEe1gI/" brackets="none"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-cipher-suites-registry" numbered="true" removeInRFC="false" toc="include" pn="section-5">
      <name slugifiedName="name-tls-cipher-suites-registry">TLS Cipher Suites Registry</name>
      <t indent="0" pn="section-5-1">Several categories of cipher suites are discouraged for general use and
are marked as "D".</t>
      <t indent="0" pn="section-5-2">Cipher suites that use NULL encryption do not provide the confidentiality
normally expected of TLS. Protocols and applications are often designed
to require confidentiality as a security property. These
cipher suites <bcp14>MUST NOT</bcp14> be used in those cases.</t>
      <t indent="0" pn="section-5-3">Cipher suites marked as EXPORT use weak ciphers and were deprecated in
TLS 1.1 <xref target="RFC4346" format="default" sectionFormat="of" derivedContent="RFC4346"/>.</t>
      <t indent="0" pn="section-5-4">Cipher suites marked as anon do not provide any authentication, are
vulnerable to on-path attacks, and were deprecated in TLS 1.1
<xref target="RFC4346" format="default" sectionFormat="of" derivedContent="RFC4346"/>.</t>
      <t indent="0" pn="section-5-5">RC4 is a weak cipher and is deprecated in <xref target="RFC7465" format="default" sectionFormat="of" derivedContent="RFC7465"/>.</t>
      <t indent="0" pn="section-5-6">DES and the International Data Encryption Algorithm (IDEA) are not considered secure for general use and were deprecated in <xref target="RFC5469" format="default" sectionFormat="of" derivedContent="RFC5469"/>. MD5 and SHA-1 are also not secure for general use and were deprecated in <xref target="RFC9155" format="default" sectionFormat="of" derivedContent="RFC9155"/>.</t>
      <t indent="0" pn="section-5-7">In order to reflect the changes in the "Recommended" column allocation,
IANA has updated the "TLS Cipher Suites" registry as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-5-8">
        <li pn="section-5-8.1">
          <t indent="0" pn="section-5-8.1.1">Adjusted the registration procedure related to setting the "Recommended" column as follows:  </t>
          <t indent="0" pn="section-5-8.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D" in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-5-8.2">
          <t indent="0" pn="section-5-8.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-5-8.3">
          <t indent="0" pn="section-5-8.3.1">Updated the "Recommended" column with the changes listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
IANA has added a reference to this document for these entries. This document does not
make any changes to the "DTLS-OK" column.</t>
        </li>
      </ul>
      <table align="center" pn="table-2">
        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Value</th>
            <th align="left" colspan="1" rowspan="1">Description</th>
            <th align="right" colspan="1" rowspan="1">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x1E</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_WITH_DES_CBC_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x20</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_WITH_RC4_128_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x21</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_WITH_IDEA_CBC_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x22</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_WITH_DES_CBC_MD5</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x24</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_WITH_RC4_128_MD5</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x25</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_WITH_IDEA_CBC_MD5</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x26</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x27</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x28</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_EXPORT_WITH_RC4_40_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x29</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x2A</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x2B</td>
            <td align="left" colspan="1" rowspan="1">TLS_KRB5_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x2C</td>
            <td align="left" colspan="1" rowspan="1">TLS_PSK_WITH_NULL_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0x8A</td>
            <td align="left" colspan="1" rowspan="1">TLS_PSK_WITH_RC4_128_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0xB0</td>
            <td align="left" colspan="1" rowspan="1">TLS_PSK_WITH_NULL_SHA256</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0x00,0xB1</td>
            <td align="left" colspan="1" rowspan="1">TLS_PSK_WITH_NULL_SHA384</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0x06</td>
            <td align="left" colspan="1" rowspan="1">TLS_ECDHE_ECDSA_WITH_NULL_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0x07</td>
            <td align="left" colspan="1" rowspan="1">TLS_ECDHE_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0x10</td>
            <td align="left" colspan="1" rowspan="1">TLS_ECDHE_RSA_WITH_NULL_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0x11</td>
            <td align="left" colspan="1" rowspan="1">TLS_ECDHE_RSA_WITH_RC4_128_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0x33</td>
            <td align="left" colspan="1" rowspan="1">TLS_ECDHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0x39</td>
            <td align="left" colspan="1" rowspan="1">TLS_ECDHE_PSK_WITH_NULL_SHA</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0x3A</td>
            <td align="left" colspan="1" rowspan="1">TLS_ECDHE_PSK_WITH_NULL_SHA256</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0x3B</td>
            <td align="left" colspan="1" rowspan="1">TLS_ECDHE_PSK_WITH_NULL_SHA384</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0xB4</td>
            <td align="left" colspan="1" rowspan="1">TLS_SHA256_SHA256</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">0xC0,0xB5</td>
            <td align="left" colspan="1" rowspan="1">TLS_SHA384_SHA384</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-5-10">
        <li pn="section-5-10.1">
          <t indent="0" pn="section-5-10.1.1">Updated the note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-supported-groups-registry" numbered="true" removeInRFC="false" toc="include" pn="section-6">
      <name slugifiedName="name-tls-supported-groups-regist">TLS Supported Groups Registry</name>
      <t indent="0" pn="section-6-1">In order to reflect the changes in the "Recommended" column allocation,
IANA has updated the "TLS Supported Groups" registry as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-6-2">
        <li pn="section-6-2.1">
          <t indent="0" pn="section-6-2.1.1">Updated the registration policy to include:  </t>
          <t indent="0" pn="section-6-2.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D" in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-6-2.2">
          <t indent="0" pn="section-6-2.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-6-2.3">
          <t indent="0" pn="section-6-2.3.1">Updated the "Recommended" column with the changes listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
IANA has added a reference to this document for these entries.</t>
        </li>
      </ul>
      <table align="center" pn="table-3">
        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Value</th>
            <th align="left" colspan="1" rowspan="1">Description</th>
            <th align="right" colspan="1" rowspan="1">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">1</td>
            <td align="left" colspan="1" rowspan="1">sect163k1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">2</td>
            <td align="left" colspan="1" rowspan="1">sect163r1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">3</td>
            <td align="left" colspan="1" rowspan="1">sect163r2</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">4</td>
            <td align="left" colspan="1" rowspan="1">sect193r1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">5</td>
            <td align="left" colspan="1" rowspan="1">sect193r2</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">6</td>
            <td align="left" colspan="1" rowspan="1">sect233k1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">7</td>
            <td align="left" colspan="1" rowspan="1">sect233r1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">8</td>
            <td align="left" colspan="1" rowspan="1">sect239k1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">15</td>
            <td align="left" colspan="1" rowspan="1">secp160k1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">16</td>
            <td align="left" colspan="1" rowspan="1">secp160r1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">17</td>
            <td align="left" colspan="1" rowspan="1">secp160r2</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">18</td>
            <td align="left" colspan="1" rowspan="1">secp192k1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">19</td>
            <td align="left" colspan="1" rowspan="1">secp192r1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">20</td>
            <td align="left" colspan="1" rowspan="1">secp224k1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">21</td>
            <td align="left" colspan="1" rowspan="1">secp224r1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-6-4">
        <li pn="section-6-4.1">
          <t indent="0" pn="section-6-4.1.1">Updated the note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
        <li pn="section-6-4.2">
          <t indent="0" pn="section-6-4.2.1">Removed the "Elliptic curve groups" note from the registration
procedures table.</t>
        </li>
        <li pn="section-6-4.3">
          <t indent="0" pn="section-6-4.3.1">For each of the entries above, added the following link to the
"Comment" column: <eref target="https://datatracker.ietf.org/meeting/118/materials/slides-118-tls-rfc8447bis-00" brackets="none"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-exporter-labels-registry" numbered="true" removeInRFC="false" toc="include" pn="section-7">
      <name slugifiedName="name-tls-exporter-labels-registr">TLS Exporter Labels Registry</name>
      <t indent="0" pn="section-7-1">This document updates the registration procedure for the "TLS Exporter
Labels" registry and updates the "Recommended" column allocation.
IANA has updated the "TLS Exporter Labels" registry as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-7-2">
        <li pn="section-7-2.1">
          <t indent="0" pn="section-7-2.1.1">Changed the registration procedure from Specification Required to
Expert Review and updated it to include:  </t>
          <t indent="0" pn="section-7-2.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D" in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-7-2.2">
          <t indent="0" pn="section-7-2.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-7-2.3">
          <t indent="0" pn="section-7-2.3.1">Entries kept their existing "Recommended" column "Y" and "N" entries.</t>
        </li>
        <li pn="section-7-2.4">
          <t indent="0" pn="section-7-2.4.1">Updated the note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
        <li pn="section-7-2.5">
          <t indent="0" pn="section-7-2.5.1">Updated the note on the role of the expert reviewer as follows.</t>
        </li>
      </ul>
      <blockquote pn="section-7-3">
        <t indent="0" pn="section-7-3.1">Note: The role of the designated expert is described in <xref section="17" sectionFormat="of" target="RFC8447" format="default" derivedLink="https://rfc-editor.org/rfc/rfc8447#section-17" derivedContent="RFC8447"/>.
Even though this registry does not require a specification, the
designated expert <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/> will strongly encourage registrants
to provide a link to a publicly available specification. An
Internet-Draft (that is posted and never published as an RFC)
or a document from another standards body, industry consortium,
university site, etc. is suitable for these purposes.
The expert may provide more in-depth reviews, but their approval
should not be taken as an endorsement of the exporter label.  The
expert also verifies that the label is a string consisting of
printable ASCII characters beginning with "EXPORTER".  IANA <bcp14>MUST</bcp14>
also verify that one label is not a prefix of any other label.
For example, labels "key" or "master secretary" are forbidden.</t>
      </blockquote>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-7-4">
        <li pn="section-7-4.1">
          <t indent="0" pn="section-7-4.1.1">Renamed the "Note" column to "Comment".</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-certificate-types-registry" numbered="true" removeInRFC="false" toc="include" pn="section-8">
      <name slugifiedName="name-tls-certificate-types-regis">TLS Certificate Types Registry</name>
      <t indent="0" pn="section-8-1">In order to reflect the changes in the "Recommended" column allocation,
IANA has updated the "TLS Certificate Types" registry as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-8-2">
        <li pn="section-8-2.1">
          <t indent="0" pn="section-8-2.1.1">Adjusted the registration procedure related to setting the "Recommended" column as follows:  </t>
          <t indent="0" pn="section-8-2.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D" in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-8-2.2">
          <t indent="0" pn="section-8-2.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-8-2.3">
          <t indent="0" pn="section-8-2.3.1">Entries kept their existing "Recommended" column "Y" and "N" entries.</t>
        </li>
        <li pn="section-8-2.4">
          <t indent="0" pn="section-8-2.4.1">Updated the note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-hashalgorithm-registry" numbered="true" removeInRFC="false" toc="include" pn="section-9">
      <name slugifiedName="name-tls-hashalgorithm-registry">TLS HashAlgorithm Registry</name>
      <t indent="0" pn="section-9-1">TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996" format="default" sectionFormat="of" derivedContent="RFC8996"/>; TLS 1.2 will
be in use for some time. In order to reflect the changes in the "Recommended"
column allocation, IANA has updated the "TLS HashAlgorithm" registry
as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-9-2">
        <li pn="section-9-2.1">
          <t indent="0" pn="section-9-2.1.1">Updated the registration procedure to include:  </t>
          <t indent="0" pn="section-9-2.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D"  in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-9-2.2">
          <t indent="0" pn="section-9-2.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-9-2.3">
          <t indent="0" pn="section-9-2.3.1">Updated the "TLS HashAlgorithm" registry to add a "Recommended" column
as follows:</t>
        </li>
      </ul>
      <table align="center" pn="table-4">
        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Value</th>
            <th align="left" colspan="1" rowspan="1">Description</th>
            <th align="right" colspan="1" rowspan="1">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">0</td>
            <td align="left" colspan="1" rowspan="1">none</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">1</td>
            <td align="left" colspan="1" rowspan="1">md5</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">2</td>
            <td align="left" colspan="1" rowspan="1">sha1</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">3</td>
            <td align="left" colspan="1" rowspan="1">sha224</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">4</td>
            <td align="left" colspan="1" rowspan="1">sha256</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">5</td>
            <td align="left" colspan="1" rowspan="1">sha384</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">6</td>
            <td align="left" colspan="1" rowspan="1">sha512</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">8</td>
            <td align="left" colspan="1" rowspan="1">Intrinsic</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-9-4">
        <li pn="section-9-4.1">
          <t indent="0" pn="section-9-4.1.1">Added a note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-signaturealgorithm-registry" numbered="true" removeInRFC="false" toc="include" pn="section-10">
      <name slugifiedName="name-tls-signaturealgorithm-regi">TLS SignatureAlgorithm Registry</name>
      <t indent="0" pn="section-10-1">TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996" format="default" sectionFormat="of" derivedContent="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to reflect the changes in the "Recommended"
column allocation, IANA has updated the "TLS SignatureAlgorithm" registry
as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-10-2">
        <li pn="section-10-2.1">
          <t indent="0" pn="section-10-2.1.1">Updated the registration procedure to include:  </t>
          <t indent="0" pn="section-10-2.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D"  in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-10-2.2">
          <t indent="0" pn="section-10-2.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-10-2.3">
          <t indent="0" pn="section-10-2.3.1">Updated the "TLS SignatureAlgorithm" registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table align="center" pn="table-5">
        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Value</th>
            <th align="left" colspan="1" rowspan="1">Description</th>
            <th align="right" colspan="1" rowspan="1">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">0</td>
            <td align="left" colspan="1" rowspan="1">anonymous</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">1</td>
            <td align="left" colspan="1" rowspan="1">rsa</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">2</td>
            <td align="left" colspan="1" rowspan="1">dsa</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">3</td>
            <td align="left" colspan="1" rowspan="1">ecdsa</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">7</td>
            <td align="left" colspan="1" rowspan="1">ed25519</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">8</td>
            <td align="left" colspan="1" rowspan="1">ed448</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">64</td>
            <td align="left" colspan="1" rowspan="1">gostr34102012_256</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">65</td>
            <td align="left" colspan="1" rowspan="1">gostr34102012_512</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-10-4">
        <li pn="section-10-4.1">
          <t indent="0" pn="section-10-4.1.1">Added a note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-clientcertificatetype-identifiers-registry" numbered="true" removeInRFC="false" toc="include" pn="section-11">
      <name slugifiedName="name-tls-clientcertificatetype-i">TLS ClientCertificateType Identifiers Registry</name>
      <t indent="0" pn="section-11-1">TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996" format="default" sectionFormat="of" derivedContent="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to reflect the changes in the "Recommended"
column allocation, IANA has updated the "TLS ClientCertificateType Identifiers"
registry as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-11-2">
        <li pn="section-11-2.1">
          <t indent="0" pn="section-11-2.1.1">Updated the registration procedure to include:  </t>
          <t indent="0" pn="section-11-2.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D"  in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-11-2.2">
          <t indent="0" pn="section-11-2.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-11-2.3">
          <t indent="0" pn="section-11-2.3.1">Updated the "TLS ClientCertificateType Identifiers" registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table align="center" pn="table-6">
        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Value</th>
            <th align="left" colspan="1" rowspan="1">Description</th>
            <th align="right" colspan="1" rowspan="1">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">1</td>
            <td align="left" colspan="1" rowspan="1">rsa_sign</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">2</td>
            <td align="left" colspan="1" rowspan="1">dss_sign</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">3</td>
            <td align="left" colspan="1" rowspan="1">rsa_fixed_dh</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">4</td>
            <td align="left" colspan="1" rowspan="1">dss_fixed_dh</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">5</td>
            <td align="left" colspan="1" rowspan="1">rsa_ephemeral_dh_RESERVED</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">6</td>
            <td align="left" colspan="1" rowspan="1">dss_ephemeral_dh_RESERVED</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">20</td>
            <td align="left" colspan="1" rowspan="1">fortezza_dms_RESERVED</td>
            <td align="right" colspan="1" rowspan="1">D</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">64</td>
            <td align="left" colspan="1" rowspan="1">ecdsa_sign</td>
            <td align="right" colspan="1" rowspan="1">Y</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">65</td>
            <td align="left" colspan="1" rowspan="1">rsa_fixed_ecdh</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">66</td>
            <td align="left" colspan="1" rowspan="1">ecdsa_fixed_ecdh</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">67</td>
            <td align="left" colspan="1" rowspan="1">gost_sign256</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">68</td>
            <td align="left" colspan="1" rowspan="1">gost_sign512</td>
            <td align="right" colspan="1" rowspan="1">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-11-4">
        <li pn="section-11-4.1">
          <t indent="0" pn="section-11-4.1.1">Added a note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-pskkeyexchangemode-registry" numbered="true" removeInRFC="false" toc="include" pn="section-12">
      <name slugifiedName="name-tls-pskkeyexchangemode-regi">TLS PskKeyExchangeMode Registry</name>
      <t indent="0" pn="section-12-1">In order to reflect the changes in the "Recommended" column allocation,
IANA has updated the "TLS PskKeyExchangeMode" registry as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-12-2">
        <li pn="section-12-2.1">
          <t indent="0" pn="section-12-2.1.1">Updated the registration procedure to include:  </t>
          <t indent="0" pn="section-12-2.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D"  in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-12-2.2">
          <t indent="0" pn="section-12-2.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-12-2.3">
          <t indent="0" pn="section-12-2.3.1">Entries kept their existing "Recommended" column "Y" and "N" entries.</t>
        </li>
        <li pn="section-12-2.4">
          <t indent="0" pn="section-12-2.4.1">Updated note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-signaturescheme-registry" numbered="true" removeInRFC="false" toc="include" pn="section-13">
      <name slugifiedName="name-tls-signaturescheme-registr">TLS SignatureScheme Registry</name>
      <t indent="0" pn="section-13-1">In order to reflect the changes in the "Recommended" column allocation,
IANA has updated the "TLS SignatureScheme" registry as follows:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-13-2">
        <li pn="section-13-2.1">
          <t indent="0" pn="section-13-2.1.1">Updated the registration procedure to include:  </t>
          <t indent="0" pn="section-13-2.1.2">
Setting a value to "Y" or "D" or transitioning the value from
  "Y" or "D"  in the "Recommended" column requires
  IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/>.</t>
        </li>
        <li pn="section-13-2.2">
          <t indent="0" pn="section-13-2.2.1">Added a reference to this document under the reference heading.</t>
        </li>
        <li pn="section-13-2.3">
          <t indent="0" pn="section-13-2.3.1">Entries kept their existing "Recommended" column "Y" and "N" entries.</t>
        </li>
        <li pn="section-13-2.4">
          <t indent="0" pn="section-13-2.4.1">Updated note on the "Recommended" column with text in <xref target="rec-note" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="adding-comment-column" numbered="true" removeInRFC="false" toc="include" pn="section-14">
      <name slugifiedName="name-adding-comment-column">Adding "Comment" Column</name>
      <t indent="0" pn="section-14-1">IANA has added a "Comment" column to the following registries:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-14-2">
        <li pn="section-14-2.1">
          <t indent="0" pn="section-14-2.1.1">TLS ExtensionType Values</t>
        </li>
        <li pn="section-14-2.2">
          <t indent="0" pn="section-14-2.2.1">TLS Application-Layer Protocol Negotiation (ALPN) Protocol IDs</t>
        </li>
        <li pn="section-14-2.3">
          <t indent="0" pn="section-14-2.3.1">TLS CachedInformationType Values</t>
        </li>
        <li pn="section-14-2.4">
          <t indent="0" pn="section-14-2.4.1">TLS Certificate Compression Algorithm IDs</t>
        </li>
        <li pn="section-14-2.5">
          <t indent="0" pn="section-14-2.5.1">TLS ClientCertificateType Identifiers</t>
        </li>
        <li pn="section-14-2.6">
          <t indent="0" pn="section-14-2.6.1">TLS Cipher Suites</t>
        </li>
        <li pn="section-14-2.7">
          <t indent="0" pn="section-14-2.7.1">TLS ContentType</t>
        </li>
        <li pn="section-14-2.8">
          <t indent="0" pn="section-14-2.8.1">TLS EC Point Formats</t>
        </li>
        <li pn="section-14-2.9">
          <t indent="0" pn="section-14-2.9.1">TLS EC Curve Types</t>
        </li>
        <li pn="section-14-2.10">
          <t indent="0" pn="section-14-2.10.1">TLS Supplemental Data Formats (SupplementalDataType)</t>
        </li>
        <li pn="section-14-2.11">
          <t indent="0" pn="section-14-2.11.1">TLS UserMappingType Values</t>
        </li>
        <li pn="section-14-2.12">
          <t indent="0" pn="section-14-2.12.1">TLS SignatureAlgorithm</t>
        </li>
        <li pn="section-14-2.13">
          <t indent="0" pn="section-14-2.13.1">TLS HashAlgorithm</t>
        </li>
        <li pn="section-14-2.14">
          <t indent="0" pn="section-14-2.14.1">TLS Authorization Data Formats</t>
        </li>
        <li pn="section-14-2.15">
          <t indent="0" pn="section-14-2.15.1">TLS Heartbeat Message Types</t>
        </li>
        <li pn="section-14-2.16">
          <t indent="0" pn="section-14-2.16.1">TLS Heartbeat Modes</t>
        </li>
        <li pn="section-14-2.17">
          <t indent="0" pn="section-14-2.17.1">TLS SignatureScheme</t>
        </li>
        <li pn="section-14-2.18">
          <t indent="0" pn="section-14-2.18.1">TLS PskKeyExchangeMode</t>
        </li>
        <li pn="section-14-2.19">
          <t indent="0" pn="section-14-2.19.1">TLS KDF Identifiers</t>
        </li>
        <li pn="section-14-2.20">
          <t indent="0" pn="section-14-2.20.1">TLS SSLKEYLOGFILE Labels</t>
        </li>
      </ul>
      <t indent="0" pn="section-14-3">This list of registries is all registries that do not already have a
"Comment" or "Note" column or that were not orphaned by TLS 1.3.</t>
    </section>
    <section anchor="expert-review-of-current-and-potential-ietf-and-irtf-documents" numbered="true" removeInRFC="false" toc="include" pn="section-15">
      <name slugifiedName="name-expert-review-of-current-an">Expert Review of Current and Potential IETF and IRTF Documents</name>
      <t indent="0" pn="section-15-1">The intent of the Specification Required choice for TLS codepoints
is to allow for easy registration for codepoints associated with
protocols and algorithms that are not being actively developed inside
the IETF or IRTF. When TLS-based technologies are being developed inside
the IETF or IRTF, they should be done in coordination with the TLS WG in
order to provide appropriate review. For this reason, unless the TLS WG
Chairs indicate otherwise via email, designated
experts should decline codepoint registrations for documents that
have already been adopted or are being proposed for adoption by IETF
working groups or IRTF research groups.</t>
    </section>
    <section anchor="registration-requests" numbered="true" removeInRFC="false" toc="include" pn="section-16">
      <name slugifiedName="name-registration-requests">Registration Requests</name>
      <t indent="0" pn="section-16-1">Registration requests <bcp14>MUST</bcp14> be submitted in one of two ways:</t>
      <ol spacing="normal" type="1" indent="adaptive" start="1" pn="section-16-2"><li pn="section-16-2.1" derivedCounter="1.">
          <t indent="0" pn="section-16-2.1.1">By sending email to iana@iana.org; this email <bcp14>SHOULD</bcp14>
use an appropriate subject (e.g., "Request to register value in TLS
bar registry").</t>
        </li>
        <li pn="section-16-2.2" derivedCounter="2.">
          <t indent="0" pn="section-16-2.2.1">Using the online form at <eref target="https://www.iana.org/form/protocol-assignment" brackets="none"/>.</t>
        </li>
      </ol>
      <t indent="0" pn="section-16-3">Specification Required <xref target="RFC8126" format="default" sectionFormat="of" derivedContent="RFC8126"/> registry requests are registered after
a three-week review period on the advice of one or more designated
experts. However, to allow for the allocation of values prior to
publication, the designated experts may approve registration once they
are satisfied that such a specification will be published.</t>
    </section>
    <section anchor="security-considerations" numbered="true" removeInRFC="false" toc="include" pn="section-17">
      <name slugifiedName="name-security-considerations">Security Considerations</name>
      <t indent="0" pn="section-17-1">Recommended algorithms are regarded as secure for general use at the
time of registration; however, cryptographic algorithms and parameters
will be broken or weakened over time.  It is possible that the
"Recommended" status in the registry lags behind the most recent advances
in cryptanalysis.  Implementers and users need to check that the
cryptographic algorithms listed continue to provide the expected level
of security.</t>
      <t indent="0" pn="section-17-2">Designated experts ensure the specification is publicly available.  They may
provide more in-depth reviews.  Their review should not be taken as an
endorsement of the cipher suite, extension, supported group, etc.</t>
    </section>
    <section anchor="iana-considerations" numbered="true" removeInRFC="false" toc="include" pn="section-18">
      <name slugifiedName="name-iana-considerations">IANA Considerations</name>
      <t indent="0" pn="section-18-1">This document is entirely about changes to TLS-related IANA registries.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-normative-references" pn="section-19">
      <name slugifiedName="name-normative-references">Normative References</name>
      <reference anchor="RFC2119" target="https://www.rfc-editor.org/info/rfc2119" quoteTitle="true" derivedAnchor="RFC2119">
        <front>
          <title>Key words for use in RFCs to Indicate Requirement Levels</title>
          <author fullname="S. Bradner" initials="S." surname="Bradner"/>
          <date month="March" year="1997"/>
          <abstract>
            <t indent="0">In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="2119"/>
        <seriesInfo name="DOI" value="10.17487/RFC2119"/>
      </reference>
      <reference anchor="RFC4346" target="https://www.rfc-editor.org/info/rfc4346" quoteTitle="true" derivedAnchor="RFC4346">
        <front>
          <title>The Transport Layer Security (TLS) Protocol Version 1.1</title>
          <author fullname="T. Dierks" initials="T." surname="Dierks"/>
          <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
          <date month="April" year="2006"/>
          <abstract>
            <t indent="0">This document specifies Version 1.1 of the Transport Layer Security (TLS) protocol. The TLS protocol provides communications security over the Internet. The protocol allows client/server applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="4346"/>
        <seriesInfo name="DOI" value="10.17487/RFC4346"/>
      </reference>
      <reference anchor="RFC5469" target="https://www.rfc-editor.org/info/rfc5469" quoteTitle="true" derivedAnchor="RFC5469">
        <front>
          <title>DES and IDEA Cipher Suites for Transport Layer Security (TLS)</title>
          <author fullname="P. Eronen" initials="P." role="editor" surname="Eronen"/>
          <date month="February" year="2009"/>
          <abstract>
            <t indent="0">Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346) include cipher suites based on DES (Data Encryption Standard) and IDEA (International Data Encryption Algorithm) algorithms. DES (when used in single-DES mode) and IDEA are no longer recommended for general use in TLS, and have been removed from TLS version 1.2 (RFC 5246). This document specifies these cipher suites for completeness and discusses reasons why their use is no longer recommended. This memo provides information for the Internet community.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="5469"/>
        <seriesInfo name="DOI" value="10.17487/RFC5469"/>
      </reference>
      <reference anchor="RFC7465" target="https://www.rfc-editor.org/info/rfc7465" quoteTitle="true" derivedAnchor="RFC7465">
        <front>
          <title>Prohibiting RC4 Cipher Suites</title>
          <author fullname="A. Popov" initials="A." surname="Popov"/>
          <date month="February" year="2015"/>
          <abstract>
            <t indent="0">This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections. This applies to all TLS versions. This document updates RFCs 5246, 4346, and 2246.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="7465"/>
        <seriesInfo name="DOI" value="10.17487/RFC7465"/>
      </reference>
      <reference anchor="RFC8126" target="https://www.rfc-editor.org/info/rfc8126" quoteTitle="true" derivedAnchor="RFC8126">
        <front>
          <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
          <author fullname="M. Cotton" initials="M." surname="Cotton"/>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <author fullname="T. Narten" initials="T." surname="Narten"/>
          <date month="June" year="2017"/>
          <abstract>
            <t indent="0">Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
            <t indent="0">To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed. This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
            <t indent="0">This is the third edition of this document; it obsoletes RFC 5226.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="26"/>
        <seriesInfo name="RFC" value="8126"/>
        <seriesInfo name="DOI" value="10.17487/RFC8126"/>
      </reference>
      <reference anchor="RFC8174" target="https://www.rfc-editor.org/info/rfc8174" quoteTitle="true" derivedAnchor="RFC8174">
        <front>
          <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <date month="May" year="2017"/>
          <abstract>
            <t indent="0">RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="8174"/>
        <seriesInfo name="DOI" value="10.17487/RFC8174"/>
      </reference>
      <reference anchor="RFC8447" target="https://www.rfc-editor.org/info/rfc8447" quoteTitle="true" derivedAnchor="RFC8447">
        <front>
          <title>IANA Registry Updates for TLS and DTLS</title>
          <author fullname="J. Salowey" initials="J." surname="Salowey"/>
          <author fullname="S. Turner" initials="S." surname="Turner"/>
          <date month="August" year="2018"/>
          <abstract>
            <t indent="0">This document describes a number of changes to TLS and DTLS IANA registries that range from adding notes to the registry all the way to changing the registration policy. These changes were mostly motivated by WG review of the TLS- and DTLS-related registries undertaken as part of the TLS 1.3 development process.</t>
            <t indent="0">This document updates the following RFCs: 3749, 5077, 4680, 5246, 5705, 5878, 6520, and 7301.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="8447"/>
        <seriesInfo name="DOI" value="10.17487/RFC8447"/>
      </reference>
      <reference anchor="RFC8996" target="https://www.rfc-editor.org/info/rfc8996" quoteTitle="true" derivedAnchor="RFC8996">
        <front>
          <title>Deprecating TLS 1.0 and TLS 1.1</title>
          <author fullname="K. Moriarty" initials="K." surname="Moriarty"/>
          <author fullname="S. Farrell" initials="S." surname="Farrell"/>
          <date month="March" year="2021"/>
          <abstract>
            <t indent="0">This document formally deprecates Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346). Accordingly, those documents have been moved to Historic status. These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008 (subsequently being obsoleted by TLS version 1.3 in 2018), providing sufficient time to transition away from older versions. Removing support for older versions from implementations reduces the attack surface, reduces opportunity for misconfiguration, and streamlines library and product maintenance.</t>
            <t indent="0">This document also deprecates Datagram TLS (DTLS) version 1.0 (RFC 4347) but not DTLS version 1.2, and there is no DTLS version 1.1.</t>
            <t indent="0">This document updates many RFCs that normatively refer to TLS version 1.0 or TLS version 1.1, as described herein. This document also updates the best practices for TLS usage in RFC 7525; hence, it is part of BCP 195.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="195"/>
        <seriesInfo name="RFC" value="8996"/>
        <seriesInfo name="DOI" value="10.17487/RFC8996"/>
      </reference>
      <reference anchor="RFC9155" target="https://www.rfc-editor.org/info/rfc9155" quoteTitle="true" derivedAnchor="RFC9155">
        <front>
          <title>Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2</title>
          <author fullname="L. Velvindron" initials="L." surname="Velvindron"/>
          <author fullname="K. Moriarty" initials="K." surname="Moriarty"/>
          <author fullname="A. Ghedini" initials="A." surname="Ghedini"/>
          <date month="December" year="2021"/>
          <abstract>
            <t indent="0">The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digital signatures. However, this document does not deprecate SHA-1 with Hashed Message Authentication Code (HMAC), as used in record protection. This document updates RFC 5246.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="9155"/>
        <seriesInfo name="DOI" value="10.17487/RFC9155"/>
      </reference>
    </references>
    <section anchor="authors-addresses" numbered="false" removeInRFC="false" toc="include" pn="section-appendix.a">
      <name slugifiedName="name-authors-addresses">Authors' Addresses</name>
      <author initials="J." surname="Salowey" fullname="Joe Salowey">
        <organization showOnFrontPage="true">CyberArk</organization>
        <address>
          <email>joe@salowey.net</email>
        </address>
      </author>
      <author initials="S." surname="Turner" fullname="Sean Turner">
        <organization showOnFrontPage="true">sn3rd</organization>
        <address>
          <email>sean@sn3rd.com</email>
        </address>
      </author>
    </section>
  </back>
</rfc>
