This message starts a WG Last Call for: draft-ietf-jose-deprecate-none-rsa15-04
This Working Group Last Call ends on 2026-05-20 Abstract: This document updates [RFC7518] to deprecate the JWS algorithm "none" and the JWE algorithm "RSA1_5". These algorithms have known security weaknesses. It also updates the Review Instructions for Designated Experts to establish baseline security requirements that future algorithm registrations should meet. Please review and indicate your support or objection to proceed with the publication of this document by replying to this email keeping [email protected] in copy. Objections should be explained and suggestions to resolve them are highly appreciated. Authors, and WG participants in general, are reminded of the Intellectual Property Rights (IPR) disclosure obligations described in BCP 79 [1]. Appropriate IPR disclosures required for full conformance with the provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. Sanctions available for application to violators of IETF IPR Policy can be found at [3]. Thank you. [1] https://datatracker.ietf.org/doc/bcp78/ [2] https://datatracker.ietf.org/doc/bcp79/ [3] https://datatracker.ietf.org/doc/rfc6701/ The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ietf-jose-deprecate-none-rsa15/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-ietf-jose-deprecate-none-rsa15-04.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-ietf-jose-deprecate-none-rsa15-04 _______________________________________________ jose mailing list -- [email protected] To unsubscribe send an email to [email protected]
