Computer Security Resource Center

Computer Security Resource Center

Computer Security
Resource Center

This is an archive
(replace .gov by .rip)

SP 800-52 Rev. 2 (DRAFT)

Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations (2nd Draft)

Date Published: October 2018
Comments Due: November 16, 2018
Email Comments to:


Kerry McKay (NIST), David Cooper (NIST)


Draft SP 800-52 Revision 2 provides guidance for selecting and configuring Transport Layer Security (TLS) protocol implementations that utilize NIST-recommended cryptographic algorithms and Federal Information Processing Standards (FIPS). This second draft extends the deadline by which agencies are urged to support TLS 1.3 to January 1, 2024. Moreover, it clarifies that TLS 1.3 is intended to coexist with TLS 1.2 rather than replace it. An appendix has also been added to discuss key exchange using RSA key transport and includes a list of cipher suites that may be used if a transition period is needed. The extensions guidance now clarifies which versions of TLS each extension applies to and provides guidance on the raw public keys extension.



information security; network security; SSL; TLS; Transport Layer Security
Control Families

System and Communications Protection;


Draft (2nd) SP 800-52 Rev. 2

Supplemental Material:
None available

Document History:
Draft SP 800-52 Rev. 2 (11/15/17)
Draft SP 800-52 Rev. 2 (10/15/18)