<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.38 (Ruby 2.6.10) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-lamps-rfc6211-update-04" category="std" consensus="true" submissionType="IETF" updates="6211" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Update to RFC 6211">Update to the Cryptographic Message Syntax (CMS) Algorithm Identifier Protection Attribute</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-lamps-rfc6211-update-04"/>
    <author initials="R." surname="Housley" fullname="Russ Housley">
      <organization abbrev="Vigil Security">Vigil Security, LLC</organization>
      <address>
        <postal>
          <city>Herndon, VA</city>
          <country>US</country>
        </postal>
        <email>housley@vigilsec.com</email>
      </address>
    </author>
    <author initials="S." surname="Turner" fullname="Sean Turner">
      <organization abbrev="sn3rd">sn3rd llc</organization>
      <address>
        <postal>
          <city>Washington, DC</city>
          <country>US</country>
        </postal>
        <email>sean@sn3rd.com</email>
      </address>
    </author>
    <date year="2026" month="October" day="04"/>
    <workgroup>LAMPS</workgroup>
    <keyword>CMS</keyword>
    <keyword>attribute</keyword>
    <keyword>algorithm identifier</keyword>
    <abstract>
      <?line 54?>

<t>This document updates RFC 6211. It corrects errors in the definition
of the id-aa-cmsAlgorithmProtect ASN.1 object identifier. The IANA
registry entry has always been correct.</t>
    </abstract>
  </front>
  <middle>
    <?line 60?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This document corrects errors in <xref target="RFC6211"/>, especially an error in the
definition of the id-aa-cmsAlgorithmProtect ASN.1 object identifier. The
IANA registry entry for this ASN.1 object identifier does not need to be
updated; it has always been correct.</t>
      <t>The authors are aware of two implementations of RFC 6211, but they did not
interoperate because one used the ASN.1 object identifier from RFC 6211 and
the other used the ASN.1 object identifier from the IANA registry.</t>
      <t>The ASN.1 object identifier error was reported in <xref target="Err9144"/> and <xref target="Err9145"/>.</t>
      <t>In addition, the body of the <xref target="RFC6211"/> says that a set of attributes will
"include only one instance of the algorithm protection attribute" and that
there "MUST NOT be zero or multiple instances of AttributeValue present" in
the attribute instance. The second requirement can be included as guidance
in the ASN.1 definition, but neither requirement can be automatically enforced.</t>
      <t>This update to RFC 6211 will hopefully resolve future interoperability troubles.</t>
    </section>
    <section anchor="update-to-section-2-of-rfc-6211">
      <name>Update to Section 2 of RFC 6211</name>
      <t>OLD:</t>
      <artwork><![CDATA[
       aa-cmsAlgorithmProtection ATTRIBUTE ::= {
           TYPE CMSAlgorithmProtection
           IDENTIFIED BY { id-aa-CMSAlgorithmProtection }
       }

   The following object identifier identifies the algorithm protection
   attribute:

       id-aa-CMSAlgorithmProtection OBJECT IDENTIFIER ::= { iso(1)
            member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9) 52 }
]]></artwork>
      <t>NEW:</t>
      <artwork><![CDATA[
       aa-cmsAlgorithmProtection ATTRIBUTE ::= {
           TYPE CMSAlgorithmProtection
           COUNTS MAX 1
           IDENTIFIED BY id-aa-cmsAlgorithmProtect
       }

   The following object identifier identifies the algorithm protection
   attribute:

       id-aa-cmsAlgorithmProtect OBJECT IDENTIFIER ::= { iso(1)
            member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
            smime(16) aa(2) 52 }
]]></artwork>
    </section>
    <section anchor="update-to-appendix-a-of-rfc-6211">
      <name>Update to Appendix A of RFC 6211</name>
      <t>OLD:</t>
      <artwork><![CDATA[
     aa-cmsAlgorithmProtection ATTRIBUTE ::= {
        TYPE CMSAlgorithmProtection
        IDENTIFIED BY { id-aa-cmsAlgorithmProtect }
     }

     id-aa-cmsAlgorithmProtect OBJECT IDENTIFIER ::= {
        iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1)
        pkcs9(9) 52 }
]]></artwork>
      <t>NEW:</t>
      <artwork><![CDATA[
     aa-cmsAlgorithmProtection ATTRIBUTE ::= {
           TYPE CMSAlgorithmProtection
           COUNTS MAX 1
           IDENTIFIED BY id-aa-cmsAlgorithmProtect
     }

     id-aa-cmsAlgorithmProtect OBJECT IDENTIFIER ::= {
        iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1)
        pkcs9(9) smime(16) aa(2) 52 }
]]></artwork>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>No IANA registry updates are needed. The IANA registry is correct.</t>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The CMS attribute specified in <xref target="RFC6211"/> is designed to address the
security issue of algorithm substitutions. That is, the originator uses
one algorithm, an attacker modifies the message, and then the validator
uses a different algorithm. The specified protection is not successful
unless all implementers use the same ASN.1 object identifier for the
attribute.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC6211">
          <front>
            <title>Cryptographic Message Syntax (CMS) Algorithm Identifier Protection Attribute</title>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="April" year="2011"/>
            <abstract>
              <t>The Cryptographic Message Syntax (CMS), unlike X.509/PKIX certificates, is vulnerable to algorithm substitution attacks. In an algorithm substitution attack, the attacker changes either the algorithm being used or the parameters of the algorithm in order to change the result of a signature verification process. In X.509 certificates, the signature algorithm is protected because it is duplicated in the TBSCertificate.signature field with the proviso that the validator is to compare both fields as part of the signature validation process. This document defines a new attribute that contains a copy of the relevant algorithm identifiers so that they are protected by the signature or authentication process. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6211"/>
          <seriesInfo name="DOI" value="10.17487/RFC6211"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="Err9144" target="https://errata.rfc-editor.org/eid9144/">
          <front>
            <title>RFC 6211 Errata Report ID 9144</title>
            <author>
              <organization>RFC Editor</organization>
            </author>
            <date year="2026" month="August" day="19"/>
          </front>
        </reference>
        <reference anchor="Err9145" target="https://errata.rfc-editor.org/eid9145/">
          <front>
            <title>RFC 6211 Errata Report ID 9145</title>
            <author>
              <organization>RFC Editor</organization>
            </author>
            <date year="2026" month="August" day="19"/>
          </front>
        </reference>
      </references>
    </references>
    <?line 159?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Thanks to Paul Timmel for being the first person to spot the error in <xref target="RFC6211"/>.</t>
      <t>Thanks to Corey Bonnell, Mike StJohns, Daniel Van Geest, Carl Wallace, and
François Rousseau for their careful review and constructive comments. The
document is much better because of their review.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIADJywmoAA81YbW8aRxD+vr9iRL/YEkeMY0cxVaUQTFqi2IkMTtuPy+0A
W9/tXnf3TKhF/k5/SP9YZ/aOA6fYrRW1qiXDvezMzjzz9ixJkoigQ4Y9aF0X
SgaEYCEsEAZuVQQ7d7JY6BQu0Hs5RxivTJCf4GBwMT6Efja3TodFDiOFJuiZ
RgcfnA2YBm0N9ENweloGbAk5nTq8vbfJ1ZsBvDjudltCF47eBFf6cHx0dHZ0
3BIpLSLlqx74oISyqZE52aicnIVEY5glmcwLn7hZyjqSMqpNjk5EdeV7Ubfw
5TTX3pM1YVWQgtFw8kbwgh4cHx2/SLpHLJNa49H4kqTIChRk6HPxDUiHsgdj
TEvyciWW8x686198GIsbXC2tUz0BCRAS/CU3vsabBhjdACOELMPCOhKChP4B
KpeuSu/hB1v6DFfxsTZkxlXn3jPraO+Peq6zxpw2vHs3iC832N5/H1+ldNGD
H9AZZU0bPvarp7Y0gbG9Hsd7zKXOerCoNnx1y3o8pp3U5l8YO0ZpYFI6Q/40
to47u4+iqd48dwqyLL1nYHy6Y9eP0i+0mQc27XzwmGme9n0VxaNRwliXy6Bv
kdGkROJY94TQZrb7YujcWffkpBc1bbJ8k3b8VgYJV1hYF2B0Dry2Va2Vbo6B
EAmh8L1nzzAu7VCyJah0sK5DXj5DrVjkWeVjE9wGhLjVMK6v1O7k3dHLpHvW
mHj6BBNPn27i6VeYKJKE8nnqg5NpEGKy0B6oHMuc8hrqWmtKuQOjQCF0jhqA
BzLJOk85EvuJwpk2mvuCsLP4RKtEyiTNfdNH6t4B/fFlpwt2+gvfbEuI8ozE
Rv3LvnA412TTCpDTBRbSU9Et5crDFNFsbOhU5udaqQwFVfSIVltVxvb0pTN7
7L67q3NrvW4D+gJTLbNsBVQEcVHtm9j6Bl/lm2Df4AvfKKVJJVn6gCR5QCEw
NoBBVNxZp1h3QfUt6PAIOAxnlRWemx3IJX+yC0sLOi8yZGQkO+b58SbObaBO
x36uQGnFe1PpBXS2QMfdfYqpLD1pMgj0rSIkD5k/czZvNBO0SvBqSx/uHwqH
Oisa5GrXHhKqYrckWFysLNojBrvuF+s1W9Hcn67XpG9kQCoVY9yOG06tWm2i
vZMn4BnnsJABJLWtwEua2eBhqbNMtLRJs1IxPpRMDBL10SBNihuF2wFSbMdp
o6YV7eM9GCqKWOviejyBy/cTQh5+ozhQdUNeZkFTCBvlMYTNTP4osxJJPdLk
Cy1aFGFv9mikqqKjcWBpT4e/ltphVS9UBVNeF31RQHDOS61YRtQ1XwVgWx1V
3hjUMbh7lFEyWu7faSwz5HaeourUpVr+hTtEPGlwFTgrWYK8sdktwqwMpWPb
Nkk51RmNHJrutpxm6DvcDLZUZFwjfLyb5EK8f3dOQ+Xz5891y4T9JR2pzmRy
NXp9PRlCr/cd3G0E+G/y84chs4Q9YrvLRufDy8nozWh4Dq9/hru6g+yXg/VG
ci34iiM0s1lmlzRO9yR8c+kfzC5W0wS/Jzb6H7Xi/eu3w8Fka/lV5Txobw+6
h7vOQY75FF3CRXNwfEh1ffDy5OgQnJfK64Nu9/npydkhFDepJ8n4fXZAD06P
yUMOgLgc/vjfxWLw/vpyMoaL/k/QfThGD/b4/zY4+4bMvx6Zeyp8rnM86L44
pKCwjm3UdousXxRolP4E/Uer7Olx/SdB3V9d+6CrS2tdo/xkjJstK6yfhm8j
/PcV8L/P//8Lgo9lZ2QNA2I3VISu4jkEtL3PJhqay+SIORZNpIaJblfRgNoy
q2+ac9hf1LMkhWBn1EZiSQ1AfcE5WaVCr+em4nVEQGjAxTYh/EY9nW7LyBu2
jYMOvZ7OEmXckE0lMqJ9RVtoyVwbSYSfyZUXzD4ayTYzW7JLpjfUmHKrtm0p
r34AaNfUA6sBfyszmvikTLAyYjwkMSNGQhO9UVoTiMbHHUajK97qy5TYiacR
LkqTsYc0/rf8E4mdMpvkDT0dQx8mg5Epo2iQrfn/lPzhkPTTG2OXGao5q/Xi
rmdKTi1U37Vmko68rTWHR5obz3B/kGUGE53nmEXVU+QGzlbMtPMBiFd4coJW
+sJGOrw9FexEsbOrc2AdkebX1hjMsjZc6BuEcXhrF4bicy6Npr0+UhC+R/Sh
DQPpMjomZ5lMK+jFGyfNH79bQu6Kjut0Li43bmtHLMoxEaKcvNW4jKHinzaC
4xMP0SI6O0fPq8NGc/IhZXmZLsjBQGBv2fusVlup64g/AaE+E0ItEgAA

-->

</rfc>
