@techreport{ietf-uta-require-tls13-12, number = {draft-ietf-uta-require-tls13-12}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-uta-require-tls13/12/}, author = {Rich Salz and Nimrod Aviram}, title = {{New Protocols Using TLS Must Require TLS 1.3}}, pagetotal = 8, year = 2025, month = apr, day = 14, abstract = {TLS 1.3 use is widespread, it has had comprehensive security proofs, and it improves both security and privacy over TLS 1.2. Therefore, new protocols that use TLS must require TLS 1.3. As DTLS 1.3 is not widely available or deployed, this prescription does not pertain to DTLS (in any DTLS version); it pertains to TLS only. This document updates RFC9325 and discusses post-quantum cryptography and the security and privacy improvements over TLS 1.2 as a rationale for that update.}, }