Reply to post: RSA is still here

A third of you slackers out there still aren't using HTTPS by default

yaronf

RSA is still here

The last few paragraphs of this article are confused and confusing, and really should be rewritten. RSA is in ubiquitous use today by both TLS 1.2 and TLS 1.3 for server authentication, what with almost all certificates out there still based on RSA.

What's been removed from TLS 1.3 and is deprecated in TLS 1.2 (see RFC 7525) is the RSA *handshake*, as opposed to "first use Diffie-Hellman to establish an encrypted connection, then authenticate with RSA".

I agree with Scott that people should be moving to ECDSA certificates, but unfortunately this has been slow going.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon