- From: Demi Marie Obenour <demiobenour@gmail.com>
- Date: Mon, 8 Jun 2026 15:05:39 -0400
- To: Egor Gudzenko <egor@egl.sh>, "ietf-http-wg@w3.org" <ietf-http-wg@w3.org>
Received on Monday, 8 June 2026 19:05:50 UTC
On 5/23/26 09:32, Egor Gudzenko wrote: > Hi, > > I've submitted an individual draft addressing the failure mode noted in Section 9.2.2 of RFC 9113, where HTTP/2 may be negotiated with a prohibited cipher suite. > > https://datatracker.ietf.org/doc/draft-gudzenko-httpbis-h2-cipher-selection/ > > The draft adds a single SHOULD-level procedure: when an h2-compatible cipher suite is available in the negotiation, the server should prefer it. It doesn't change anything normative, and the only subject of this draft is to fill a normative gap that are identified in Section 9.2.2 but not described how the server should behave in an ideal world. > > I filed it as Standards Track with updates: 9113, since the gap it closes is in normative text and a SHOULD-level addition doesn't fit BCP or Informational cleanly. That said, I'm genuinely uncertain whether this warrants a standalone update to 9113 or whether WG sees a better path. > > Any feedback welcome. > > With regards, > Egor Gudzenko What about deprecating TLS 1.2 instead? It isn't going to get PQC support. -- Sincerely, Demi Marie Obenour (she/her/hers)
Received on Monday, 8 June 2026 19:05:50 UTC