RFC 8812: CBOR Object Signing and Encryption (COSE) and JSON Object Signing and Encryption (JOSE) Registrations for Web Authentication (WebAuthn) Algorithms
In plain English — editorial summary, not part of the RFC
The W3C Web Authentication (WebAuthn) specification and the FIDO Alliance FIDO2 Client to Authenticator Protocol (CTAP) specification use CBOR Object Signing and Encryption (COSE) algorithm identifiers. This specification registers the following algorithms (which are used by WebAuthn and CTAP implementations) in the IANA "COSE Algorithms" registry: RSASSA-PKCS1-v1_5 using SHA-256, SHA-384, SHA-512, and SHA-1; and Elliptic Curve Digital Signature Algorithm (ECDSA) using the secp256k1 curve and SHA-256. It registers the secp256k1 elliptic curve in the IANA "COSE Elliptic Curves" registry. Also, for use with JSON Object Signing and Encryption (JOSE), it registers the algorithm ECDSA using the secp256k1 curve and SHA-256 in the IANA "JSON Web Signature and Encryption Algorithms" registry and the secp256k1 elliptic curve in the IANA "JSON Web Key Elliptic Curve" registry.
Document record
- Document ID
- RFC8812
- Published
- August 2020
- Authors
- M. Jones
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 10
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8230Using RSA Algorithms with CBOR Object Signing and Encryption (COSE) MessagesCurrent
September 2017
- RFC 9787Guidance on End-to-End Email SecurityCurrent
August 2025
- RFC 9980Post-Quantum Cryptography in OpenPGPCurrent
June 2026
- RFC 4491Using the GOST R 34.10-94, GOST R 34.10-2001, and GOST R 34.11-94 Algorithms with the Internet X.509 Public Key Infrastructure Certificate and CRL ProfileCurrent
May 2006
- RFC 5091Identity-Based Cryptography Standard (IBCS) #1: Supersingular Curve Implementations of the BF and BB1 CryptosystemsUpdated
December 2007
- RFC 8778Use of the HSS/LMS Hash-Based Signature Algorithm with CBOR Object Signing and Encryption (COSE)Current
April 2020
- RFC 8725JSON Web Token Best Current PracticesCurrent
February 2020
- RFC 8708Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax (CMS)Obsoleted
February 2020
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?