Draft: Cipher Suite Selection for HTTP/2 Negotiation over TLS 1.2

Hi,

I've submitted an individual draft addressing the failure mode noted in Section 9.2.2 of RFC 9113, where HTTP/2 may be negotiated with a prohibited cipher suite.

https://datatracker.ietf.org/doc/draft-gudzenko-httpbis-h2-cipher-selection/

The draft adds a single SHOULD-level procedure: when an h2-compatible cipher suite is available in the negotiation, the server should prefer it. It doesn't change anything normative, and the only subject of this draft is to fill a normative gap that are identified in Section 9.2.2 but not described how the server should behave in an ideal world.

I filed it as Standards Track with updates: 9113, since the gap it closes is in normative text and a SHOULD-level addition doesn't fit BCP or Informational cleanly. That said, I'm genuinely uncertain whether this warrants a standalone update to 9113 or whether WG sees a better path.

Any feedback welcome.

With regards,
Egor Gudzenko

Received on Tuesday, 26 May 2026 10:50:54 UTC