This is the first WG draft since being adopted. Changes to address comments in the adoption call:
* Added text clarifying that RSA *signature* schemes are not deprecated * Added text clarifying that the algorithms are Deprecated but not Prohibited (in the terms of the IANA registry) and that existing specs that use these algorithms can continue to do so, but should consider alternatives Also fixed some minor warnings from xml2rfc. I seem to have lost the link to the original I-D when submitting this WG version. I’ll see if I can fix that. — Neil Begin forwarded message: > From: [email protected] > Date: 4 November 2024 at 06:47:59 GMT > To: [email protected] > Cc: [email protected] > Subject: [jose] I-D Action: draft-ietf-jose-deprecate-none-rsa15-00.txt > Reply-To: [email protected] > > Internet-Draft draft-ietf-jose-deprecate-none-rsa15-00.txt is now available. > It is a work item of the Javascript Object Signing and Encryption (JOSE) WG of > the IETF. > > Title: JOSE: Deprecate 'none' and 'RSA1_5' > Author: Neil Madden > Name: draft-ietf-jose-deprecate-none-rsa15-00.txt > Pages: 7 > Dates: 2024-11-03 > > Abstract: > > This draft updates [RFC7518] to deprecate the JWS algorithm "none" > and the JWE algorithm "RSA1_5". These algorithms have known security > weaknesses. > > The IETF datatracker status page for this Internet-Draft is: > https://datatracker.ietf.org/doc/draft-ietf-jose-deprecate-none-rsa15/ > > There is also an HTML version available at: > https://www.ietf.org/archive/id/draft-ietf-jose-deprecate-none-rsa15-00.html > > Internet-Drafts are also available by rsync at: > rsync.ietf.org::internet-drafts > > > _______________________________________________ > jose mailing list -- [email protected] > To unsubscribe send an email to [email protected]
_______________________________________________ jose mailing list -- [email protected] To unsubscribe send an email to [email protected]
