<?xml version="1.0" encoding="US-ASCII"?>

<!DOCTYPE rfc SYSTEM "rfc2629.dtd" []>
<?xml-stylesheet type='text/xsl' href='rfc2629.xslt' ?>

<?rfc toc="yes"?>
<?rfc tocdepth="4"?>
<?rfc symrefs="yes"?>
<?rfc sortrefs="yes" ?>
<?rfc compact="yes" ?>
<?rfc subcompact="no" ?>
<?rfc rfcedstyle="yes" ?>

<rfc number="7465"
     category="std" 
     submissionType="IETF"
     consensus="yes"
     ipr="trust200902" 
     updates="5246, 4346, 2246">

  <front>

    <title>Prohibiting RC4 Cipher Suites</title>
    <author fullname="Andrei Popov" initials="A."
            surname="Popov">
      <organization>Microsoft Corp.</organization>

      <address>
        <postal>
          <street>One Microsoft Way</street>
          <city>Redmond</city>
          <region>WA</region>
          <code>98052</code>
          <country>USA</country>
        </postal>
        <email>andreipo@microsoft.com</email>
      </address>
    </author>

    <date month="February" year="2015" />

    <area>General</area>
    <workgroup>Internet Engineering Task Force</workgroup>
    <keyword>TLS</keyword>

    <abstract>
      <t>This document requires that Transport Layer Security (TLS) clients and servers 
      never negotiate the use of RC4 cipher suites when they establish connections. This 
      applies to all TLS versions.  This document updates RFCs 5246, 4346, and 2246.</t>
    </abstract>
  </front>

  <middle>
    <section anchor="Introduction" title="Introduction">
      <t>RC4 is a stream cipher that is described in <xref target="SCH" />; it is widely 
      supported, and often preferred by TLS servers. However, RC4 has long been known 
      to have a variety of cryptographic weaknesses, e.g., see <xref target="PAU" />, 
      <xref target="MAN" />, and <xref target="FLU" />. Recent cryptanalysis results 
      <xref target="ALF" /> exploit biases in the RC4 keystream to recover repeatedly 
      encrypted plaintexts.</t>

      <t>These recent results are on the verge of becoming practically exploitable; 
      currently, they require 2^26 sessions or 13x2^30 encryptions. As a result, RC4 can 
      no longer be seen as providing a sufficient level of security for TLS sessions.</t>

      <t>This document requires that TLS (<xref target="RFC5246" /> 
      <xref target="RFC4346" /> <xref target="RFC2246" />) clients and servers never 
      negotiate the use of RC4 cipher suites.</t>

      <section title="Requirements Language">
        <t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
        "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this
        document are to be interpreted as described in <xref target="RFC2119" />.</t>
      </section>
    </section>

    <section title="Changes to TLS">
      <t>Because of the RC4 deficiencies noted in <xref target="Introduction"
      />, the following apply:</t>

      <t>
        <list style="symbols">
          <t>TLS clients MUST NOT include RC4 cipher suites in the ClientHello message.</t>

          <t>TLS servers MUST NOT select an RC4 cipher suite when a TLS client sends such a 
          cipher suite in the ClientHello message.</t>

          <t>If the TLS client only offers RC4 cipher suites, the TLS server MUST terminate 
          the handshake. The TLS server MAY send the insufficient_security fatal alert in this 
          case.</t>
        </list>
      </t>

      <t><xref target="app-rc4-cipher-suites" /> lists the RC4 cipher suites defined for 
      TLS.</t>
    </section>

    <section anchor="Security" title="Security Considerations">
      <t>This document helps maintain the security guarantees of the TLS protocol by prohibiting 
      the use of the RC4-based cipher suites (listed in <xref target="app-rc4-cipher-suites" />), 
      which do not provide a sufficiently high level of security.</t>
    </section>
  </middle>

  <back>

    <references title="Normative References">

    <reference  anchor='RFC2119' 
		target='http://www.rfc-editor.org/info/rfc2119'>
    <front>
    <title>Key words for use in RFCs to Indicate Requirement Levels</title>
    <author initials='S.' surname='Bradner' fullname='S. Bradner'><organization /></author>
    <date year='1997' month='March' />
    </front>
    <seriesInfo name='BCP' value='14'/>
    <seriesInfo name='RFC' value='2119'/>
    <format type='ASCII' octets='4723'/>
    </reference>

    <reference  anchor='RFC5246' 
		target='http://www.rfc-editor.org/info/rfc5246'>
    <front>
    <title>The Transport Layer Security (TLS) Protocol Version 1.2</title>
    <author initials='T.' surname='Dierks' fullname='T. Dierks'><organization /></author>
    <author initials='E.' surname='Rescorla' fullname='E. Rescorla'><organization /></author>
    <date year='2008' month='August' />
    </front>
    <seriesInfo name='RFC' value='5246'/>
    <format type='ASCII' octets='222395'/>
    </reference>

    <reference  anchor='RFC4346' 
		target='http://www.rfc-editor.org/info/rfc4346'>
    <front>
    <title>The Transport Layer Security (TLS) Protocol Version 1.1</title>
    <author initials='T.' surname='Dierks' fullname='T. Dierks'><organization /></author>
    <author initials='E.' surname='Rescorla' fullname='E. Rescorla'><organization /></author>
    <date year='2006' month='April' />
    </front>
    <seriesInfo name='RFC' value='4346'/>
    <format type='ASCII' octets='187041'/>
    </reference>

    <reference  anchor='RFC2246' 
		target='http://www.rfc-editor.org/info/rfc2246'>
    <front>
    <title>The TLS Protocol Version 1.0</title>
    <author initials='T.' surname='Dierks' fullname='T. Dierks'><organization /></author>
    <author initials='C.' surname='Allen' fullname='C. Allen'><organization /></author>
    <date year='1999' month='January' />
    </front>
    <seriesInfo name='RFC' value='2246'/>
    <format type='ASCII' octets='170401'/>
    </reference>
    </references>

    <references title="Informative References">

      <reference anchor="PAU">
        <front>
          <title>Permutation after RC4 Key Scheduling Reveals the Secret Key</title>
          <author initials="G." surname="Paul">
            <organization></organization>
          </author>
          <author initials="S." surname="Maitra">
            <organization></organization>
          </author>
          <date year="2007" />
        </front>
	<seriesInfo name="Selected Areas of Cryptography: SAC 2007,"
		    value="Lecture Notes on Computer Science, Vol. 4876, pp 360-337"/>
      </reference>

      <reference anchor="MAN">
        <front>
          <title>A Practical Attack on Broadcast RC4</title>
          <author initials="I." surname="Mantin">
            <organization></organization>
          </author>
          <author initials="A." surname="Shamir">
            <organization></organization>
          </author>
          <date year="2002" />
        </front>
	<seriesInfo name="Fast Software Encryption: FSE 2001," 
		    value="Lecture Notes in Computer Science Vol. 2355, pp 152-164"/>
      </reference>

      <reference anchor="FLU">
        <front>
          <title>Weaknesses in the Key Scheduling Algorithm of RC4</title>

          <author initials="S. R." surname="Fluhrer">
            <organization></organization>
          </author>
          <author initials="I." surname="Mantin">
            <organization></organization>
          </author>
          <author initials="A." surname="Shamir">
            <organization></organization>
          </author>
          <date year="2001" />
        </front>
	<seriesInfo name="Selected Areas of Cryptography: SAC 2001,"
		    value="Lecture Notes in Computer Science Vol. 2259, pp 1-24"/>
      </reference>

      <reference anchor="ALF" 
		 target="https://www.usenix.org/conference/usenixsecurity13/security-rc4-tls">
        <front>
          <title>On the Security of RC4 in TLS and WPA</title>
          <author initials="N. J." surname="AlFardan">
            <organization></organization>
          </author>
          <author initials="D. J." surname="Bernstein">
            <organization></organization>
          </author>
          <author initials="K. G." surname="Paterson">
            <organization></organization>
          </author>
          <author initials="B." surname="Poettering">
            <organization></organization>
          </author>
          <author initials="J. C. N." surname="Schuldt">
            <organization></organization>
          </author>
          <date month="July" year="2013" />
        </front>
	<seriesInfo name="USENIX" value="Security Symposium"/>
      </reference>

      <reference anchor="SCH">
        <front>
          <title>Applied Cryptography: Protocols, Algorithms, and Source Code in C</title>
          <author initials="B." surname="Schneier">
            <organization></organization>
          </author>
          <date year="1996" />
        </front>
	<seriesInfo name="2nd" value="Edition"/>
      </reference>

    </references>

    <section anchor="app-rc4-cipher-suites" title="RC4 Cipher Suites">
      <t>The following cipher suites defined for TLS use RC4:</t>

      <t>
        <list style="symbols">

          <t>TLS_RSA_EXPORT_WITH_RC4_40_MD5</t>

          <t>TLS_RSA_WITH_RC4_128_MD5</t>

          <t>TLS_RSA_WITH_RC4_128_SHA</t>

          <t>TLS_DH_anon_EXPORT_WITH_RC4_40_MD5</t>

          <t>TLS_DH_anon_WITH_RC4_128_MD5</t>

          <t>TLS_KRB5_WITH_RC4_128_SHA</t>

          <t>TLS_KRB5_WITH_RC4_128_MD5</t>

          <t>TLS_KRB5_EXPORT_WITH_RC4_40_SHA</t>

          <t>TLS_KRB5_EXPORT_WITH_RC4_40_MD5</t>

          <t>TLS_PSK_WITH_RC4_128_SHA</t>

          <t>TLS_DHE_PSK_WITH_RC4_128_SHA</t>

          <t>TLS_RSA_PSK_WITH_RC4_128_SHA</t>

          <t>TLS_ECDH_ECDSA_WITH_RC4_128_SHA</t>

          <t>TLS_ECDHE_ECDSA_WITH_RC4_128_SHA</t>

          <t>TLS_ECDH_RSA_WITH_RC4_128_SHA</t>

          <t>TLS_ECDHE_RSA_WITH_RC4_128_SHA</t>

          <t>TLS_ECDH_anon_WITH_RC4_128_SHA</t>

          <t>TLS_ECDHE_PSK_WITH_RC4_128_SHA</t>

        </list>
      </t>
    </section>
<section title="Acknowledgements" anchor="ack_1">
<t>This document was inspired by discussions with Magnus Nystrom, Eric
   Rescorla, Joseph Salowey, Yaron Sheffer, Nagendra Modadugu, and others
   on the TLS mailing list.</t>
</section>
  </back>
</rfc>
