RFC 9709: Encryption Key Derivation in the Cryptographic Message Syntax (CMS) Using HKDF with SHA-256
In plain English — editorial summary, not part of the RFC
This document specifies the derivation of the content-encryption key or the content-authenticated-encryption key in the Cryptographic Message Syntax (CMS) using the HMAC-based Extract-and-Expand Key Derivation Function (HKDF) with SHA-256. The use of this mechanism provides protection against an attacker that manipulates the content-encryption algorithm identifier or the content-authenticated-encryption algorithm identifier.
Document record
- Document ID
- RFC9709
- Published
- January 2025
- Authors
- R. Housley
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 13
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9708Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax (CMS)Current
January 2025
- RFC 9711The Entity Attestation Token (EAT)Current
April 2025
- RFC 9701JSON Web Token (JWT) Response for OAuth Token IntrospectionCurrent
January 2025
- RFC 9700Best Current Practice for OAuth 2.0 SecurityCurrent
January 2025
- RFC 9728OAuth 2.0 Protected Resource MetadataCurrent
April 2025
- RFC 9690Use of the RSA-KEM Algorithm in the Cryptographic Message Syntax (CMS)Current
February 2025
- RFC 9688Use of the SHA3 One-Way Hash Functions in the Cryptographic Message Syntax (CMS)Current
November 2024
- RFC 9684A YANG Data Model for Challenge-Response-Based Remote Attestation (CHARRA) Procedures Using Trusted Platform Modules (TPMs)Current
December 2024
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?