TLS 1.3 default for new protocols

신규 프로토콜의 TLS 1.3 기본 요구

A 2026 best practice requires new TLS-based protocols to specify TLS 1.3 as the default.

···
html
<div class="n-demo"><div class="n-head"><strong>NEW PROTOCOL · TLS POLICY</strong><span>LIVE TRACE</span></div><div class="n-stage"><div class="min-tls"><div class="n-box">NEW PROTOCOL</div><div class="min-branch"><div id="mt13" class="n-box">TLS 1.3<br><small>DEFAULT</small></div><div id="mt12" class="n-box">TLS 1.2<br><small>OPTIONAL</small></div></div><div id="mt-note">default route → 1.3</div></div></div><div class="n-foot">tap to step · auto replay</div></div>
css
.n-demo{width:min(94vw,760px);height:min(88vh,324px);padding:clamp(9px,2.2vmin,18px);border:1px solid var(--line);border-radius:13px;background:var(--surface);display:flex;flex-direction:column;gap:clamp(5px,1.3vmin,10px);font:600 clamp(12px,2.4vmin,16px)/1.3 "Pretendard Variable",Pretendard,-apple-system,BlinkMacSystemFont,"Apple SD Gothic Neo",sans-serif;overflow:hidden}.n-head,.n-foot{display:flex;justify-content:space-between;align-items:center;color:var(--muted)}.n-head strong{color:var(--accent)}.n-head span,.n-foot{font-size:12px}.n-stage{flex:1;min-height:0;position:relative;display:flex;align-items:center;justify-content:center;gap:clamp(4px,1vmin,10px)}.mono{font-family:ui-monospace,SFMono-Regular,Consolas,monospace}.n-box{padding:clamp(5px,1.5vmin,11px);border:1px solid var(--line);border-radius:8px;background:var(--bg);text-align:center}.n-on{border-color:var(--accent)!important;color:var(--accent)!important;background:color-mix(in srgb,var(--accent) 12%,var(--surface))!important}.n-muted{color:var(--muted)}@media(max-width:400px){.n-head span{display:none}}.min-tls{width:96%;display:grid;gap:8px;justify-items:center}.min-branch{display:flex;gap:6px;width:100%}.min-branch .n-box{width:50%;padding:7px 3px}.min-branch small{font-size:10px}.min-tls #mt-note{color:var(--muted);font-size:12px}@media(min-width:500px){.min-branch small{font-size:12px}}
js
let step=0;function advance(){document.getElementById('mt13').classList.toggle('n-on',step!==2);document.getElementById('mt12').classList.toggle('n-on',step===2);document.getElementById('mt-note').textContent=step===2?'optional compatibility → 1.2':'default route → 1.3';step=(step+1)%3}
const clickTarget=document.querySelector('.n-demo');if(clickTarget&&typeof advance==='function'){advance();const timer=setInterval(advance,1050);clickTarget.addEventListener('pointerdown',()=>{clearInterval(timer);advance()})}

RFC 9852 requires a new protocol using TLS to specify TLS 1.3 as its default. TLS 1.2 may remain an additional, non-default deployment option. The guidance does not apply to DTLS.

The demo routes a new protocol through TLS 1.3 by default and keeps 1.2 as an optional compatibility path. It does not order existing services to disable 1.2 immediately.

When to use

Apply it when designing a new TLS-based protocol or its version negotiation defaults.

Open as page ↗