RFC 4108: Using Cryptographic Message Syntax (CMS) to Protect Firmware Packages
In plain English — editorial summary, not part of the RFC
This document describes the use of the Cryptographic Message Syntax (CMS) to protect firmware packages, which provide object code for one or more hardware module components. CMS is specified in RFC 3852. A digital signature is used to protect the firmware package from undetected modification and to provide data origin authentication. Encryption is optionally used to protect the firmware package from disclosure, and compression is optionally used to reduce the size of the protected firmware package. A firmware package loading receipt can optionally be generated to acknowledge the successful loading of a firmware package. Similarly, a firmware package load error report can optionally be generated to convey the failure to load a firmware package. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4108
- Published
- August 2005
- Authors
- R. Housley
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- —
- Pages
- 61
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4056Use of the RSASSA-PSS Signature Algorithm in Cryptographic Message Syntax (CMS)Current
June 2005
- RFC 4359The Use of RSA/SHA-1 Signatures within Encapsulating Security Payload (ESP) and Authentication Header (AH)Current
January 2006
- RFC 4491Using the GOST R 34.10-94, GOST R 34.10-2001, and GOST R 34.11-94 Algorithms with the Internet X.509 Public Key Infrastructure Certificate and CRL ProfileCurrent
May 2006
- RFC 3653XML-Signature XPath Filter 2.0Current
December 2003
- RFC 4871DomainKeys Identified Mail (DKIM) SignaturesObsoleted
May 2007
- RFC 5652Cryptographic Message Syntax (CMS)Updated
September 2009
- RFC 7797JSON Web Signature (JWS) Unencoded Payload OptionCurrent
February 2016
- RFC 8230Using RSA Algorithms with CBOR Object Signing and Encryption (COSE) MessagesCurrent
September 2017
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?