Semi-Static Diffie-Hellman Key Establishment for TLS 1.3

Document Type Expired Internet-Draft (tls WG)
Authors Eric Rescorla  , Nick Sullivan  , Christopher Wood 
Last updated 2020-09-08 (latest revision 2020-03-07)
Replaces draft-rescorla-tls-semistatic-dh
Stream IETF stream
Intended RFC status (None)
Expired & archived
plain text pdf htmlized (tools) htmlized bibtex
Stream WG state WG Document (wg milestone: Jul 2021 - Submit "Semi-Static ... )
Document shepherd No shepherd assigned
IESG IESG state Expired
Consensus Boilerplate Unknown
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


TLS 1.3 [RFC8446] specifies a signed Diffie-Hellman exchange modelled after SIGMA [SIGMA]. This design is suitable for endpoints whose certified credential is a signing key, which is the common situation for current TLS servers. This document describes a mode of TLS 1.3 in which one or both endpoints have a certified DH key which is used to authenticate the exchange. Note to Readers Source for this draft and an issue tracker can be found at (


Eric Rescorla (
Nick Sullivan (
Christopher Wood (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)