This version incorporates the feedback from Yaron Sheffer - with thanks! — Neil
> On 2 Apr 2025, at 13:36, [email protected] wrote: > > Internet-Draft draft-ietf-jose-deprecate-none-rsa15-02.txt is now available. > It is a work item of the Javascript Object Signing and Encryption (JOSE) WG of > the IETF. > > Title: JOSE: Deprecate 'none' and 'RSA1_5' > Author: Neil Madden > Name: draft-ietf-jose-deprecate-none-rsa15-02.txt > Pages: 7 > Dates: 2025-04-02 > > Abstract: > > This document updates [RFC7518] to deprecate the JWS algorithm "none" > and the JWE algorithm "RSA1_5". These algorithms have known security > weaknesses. It also updates the Review Instructions for Designated > Experts to establish baseline security requirements that future > algorithm registrations should meet. > > The IETF datatracker status page for this Internet-Draft is: > https://datatracker.ietf.org/doc/draft-ietf-jose-deprecate-none-rsa15/ > > There is also an HTML version available at: > https://www.ietf.org/archive/id/draft-ietf-jose-deprecate-none-rsa15-02.html > > A diff from the previous version is available at: > https://author-tools.ietf.org/iddiff?url2=draft-ietf-jose-deprecate-none-rsa15-02 > > Internet-Drafts are also available by rsync at: > rsync.ietf.org::internet-drafts > > > _______________________________________________ > jose mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ jose mailing list -- [email protected] To unsubscribe send an email to [email protected]
