RFC 6211: Cryptographic Message Syntax (CMS) Algorithm Identifier Protection Attribute
In plain English — editorial summary, not part of the RFC
The Cryptographic Message Syntax (CMS), unlike X.509/PKIX certificates, is vulnerable to algorithm substitution attacks. In an algorithm substitution attack, the attacker changes either the algorithm being used or the parameters of the algorithm in order to change the result of a signature verification process. In X.509 certificates, the signature algorithm is protected because it is duplicated in the TBSCertificate.signature field with the proviso that the validator is to compare both fields as part of the signature validation process. This document defines a new attribute that contains a copy of the relevant algorithm identifiers so that they are protected by the signature or authentication process. [STANDARDS-TRACK]
Document record
- Document ID
- RFC6211
- Published
- April 2011
- Authors
- J. Schaad
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- —
- Pages
- 11
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9216S/MIME Example Keys and CertificatesCurrent
April 2022
- RFC 6210Experiment: Hash Functions with Parameters in the Cryptographic Message Syntax (CMS) and S/MIMECurrent
April 2011
- RFC 6109La Posta Elettronica Certificata - Italian Certified Electronic MailCurrent
April 2011
- RFC 6025ASN.1 TranslationCurrent
October 2010
- RFC 5912New ASN.1 Modules for the Public Key Infrastructure Using X.509 (PKIX)Updated
June 2010
- RFC 5911New ASN.1 Modules for Cryptographic Message Syntax (CMS) and S/MIMEUpdated
June 2010
- RFC 7131Session Initiation Protocol (SIP) History-Info Header Call Flow ExamplesCurrent
March 2014
- RFC 7165Use Cases and Requirements for JSON Object Signing and Encryption (JOSE)Current
April 2014
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?