RFC 6211-2011
Cryptographic Message Syntax (CMS) Algorithm Identifier Protection Attribute

Standard No.
RFC 6211-2011
Release Date
2011
Published By
IETF - Internet Engineering Task Force
Latest
RFC 6211-2011
Scope
Abstract The Cryptographic Message Syntax (CMS)@ unlike X.509/PKIX certificates@ is vulnerable to algorithm substitution attacks. In an algorithm substitution attack@ the attacker changes either the algorithm being used or the parameters of the algorithm in order to change the result of a signature verification process. In X.509 certificates@ the signature algorithm is protected because it is duplicated in the TBSCertificate.signature field with the proviso that the validator is to compare both fields as part of the signature validation process. This document defines a new attribute that contains a copy of the relevant algorithm identifiers so that they are protected by the signature or authentication process.

RFC 6211-2011 history

  • 2011 RFC 6211-2011 Cryptographic Message Syntax (CMS) Algorithm Identifier Protection Attribute



Copyright ©2024 All Rights Reserved