You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<metaname="dct.abstract" content="The W3C Web Authentication (WebAuthn) specification uses COSE algorithm identifiers. This specification registers algorithms in the IANA "COSE Algorithms" registry that are used by WebAuthn that are not already registered. Also, they are registered in the IANA "JSON Web Signature and Encryption Algorithms" registry, when not already registered there. " />
401
401
<metaname="description" content="The W3C Web Authentication (WebAuthn) specification uses COSE algorithm identifiers. This specification registers algorithms in the IANA "COSE Algorithms" registry that are used by WebAuthn that are not already registered. Also, they are registered in the IANA "JSON Web Signature and Encryption Algorithms" registry, when not already registered there. " />
<p>The W3C Web Authentication (WebAuthn) specification uses COSE algorithm identifiers. This specification registers algorithms in the IANA "COSE Algorithms" registry that are used by WebAuthn that are not already registered. Also, they are registered in the IANA "JSON Web Signature and Encryption Algorithms" registry, when not already registered there. </p>
436
436
<h1id="rfc.status"><ahref="#rfc.status">Status of This Memo</a></h1>
437
437
<p>This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.</p>
438
438
<p>Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.</p>
439
439
<p>Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."</p>
440
-
<p>This Internet-Draft will expire on September 24, 2018.</p>
440
+
<p>This Internet-Draft will expire on November 3, 2018.</p>
<p>Copyright (c) 2018 IETF Trust and the persons identified as the document authors. All rights reserved.</p>
443
443
<p>This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Simplified BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Simplified BSD License.</p>
<li>Reference: <ahref="#RSASSA-PKCS1-v1_5" class="xref">Section 2</a> of this document </li>
582
-
<li>Recommended: No</li>
582
+
<li>Recommended: Deprecated</li>
583
583
</ul>
584
584
585
585
<p></p>
@@ -597,7 +597,7 @@ <h1 id="rfc.section.4.2">
597
597
<h1id="rfc.section.4.3">
598
598
<ahref="#rfc.section.4.3">4.3.</a><ahref="#RSASSA-PKCS1-v1_5_SHA-1_considerations" id="RSASSA-PKCS1-v1_5_SHA-1_considerations">RSASSA-PKCS1-v1_5 with SHA-1 Security Considerations</a>
599
599
</h1>
600
-
<pid="rfc.section.4.3.p.1">The security considerations on the use of the SHA-1 hash function from <ahref="#RFC6194" class="xref">[RFC6194]</a> apply in this specification. For that reason, the "RS1" algorithm is registered as "Not Recommended". It MUST NOT be used by COSE implementations. </p>
600
+
<pid="rfc.section.4.3.p.1">The security considerations on the use of the SHA-1 hash function from <ahref="#RFC6194" class="xref">[RFC6194]</a> apply in this specification. For that reason, the "RS1" algorithm is registered as "Deprecated". It MUST NOT be used by COSE implementations. </p>
601
601
<pid="rfc.section.4.3.p.2">A COSE algorithm identifier for this algorithm is nonetheless being registered because deployed TPMs continue to use it, and therefore WebAuthn implementations need a COSE algorithm identifier for "RS1" when TPM attestations using this algorithm are being represented. </p>
<pid="rfc.section.A.p.1">Thanks to John Fontana, Jeff Hodges, Tony Nadalin, Jim Schaad, Göran Selander, Wendy Seltzer, Sean Turner, and Samuel Weiler for their roles in registering these algorithm identifiers. </p>
0 commit comments