
TLS 1.2 isn't end of life, but it will be soon
RFC 10015 landed in July and makes the RSA key exchange and finite-field Diffie-Hellman MUST NOT in TLS 1.2. RFC 9851 froze TLS 1.2 entirely, so it never gets post-quantum.
We scanned certkit.io while writing this up. Grade A on SSL Labs, and three of our nine TLS 1.2 suites still started with `TLS_RSA_`. A cipher list change and a reload fixed it, no certificate work at all.
Full writeup with the SSL Labs screenshots: https://www.certkit.io/blog/tls-1-2-end-of-life
u/certkit — 2 days ago