Skip to main content

JOSE: Deprecate 'none' and 'RSA1_5'
draft-ietf-jose-deprecate-none-rsa15-06

Revision differences

Document history

Date Rev. By Action
2026-09-27
06 Barry Leiba Request for IETF Last Call review by ARTART Completed: Ready. Reviewer: Barry Leiba. Sent review to list.
2026-09-27
06 Barry Leiba Request for IETF Last Call review by ARTART is assigned to Barry Leiba
2026-09-25
06 Morgan Condie IANA Review state changed to IANA - Review Needed
2026-09-25
06 Morgan Condie
The following Last Call announcement was sent out (ends 2026-10-09):

From: The IESG
To: IETF-Announce
CC: debcooley1@gmail.com, draft-ietf-jose-deprecate-none-rsa15@ietf.org, jose-chairs@ietf.org, jose@ietf.org, kodonog@pobox.com …
The following Last Call announcement was sent out (ends 2026-10-09):

From: The IESG
To: IETF-Announce
CC: debcooley1@gmail.com, draft-ietf-jose-deprecate-none-rsa15@ietf.org, jose-chairs@ietf.org, jose@ietf.org, kodonog@pobox.com
Reply-To: last-call@ietf.org, jose@ietf.org
Sender:
Subject: Last Call:  (JOSE: Deprecate 'none' and 'RSA1_5') to Proposed Standard


The IESG has received a request from the Javascript Object Signing and
Encryption WG (jose) to consider the following document:
  'JOSE: Deprecate 'none' and 'RSA1_5''
  as Proposed Standard

The IESG plans to make a decision on this document in the coming weeks, and
solicits last-call comments. Please send substantive comments to the
last-call@ietf.org mailing list, with jose@ietf.org copied, no later than
2026-10-09.  Please retain the beginning of the Subject line to facilitate
automated sorting.

Abstract

  This document updates RFC 7518 to deprecate the JWS algorithm "none"
  and the JWE algorithm "RSA1_5".  These algorithms have known security
  weaknesses.  It also updates the Review Instructions for Designated
  Experts to establish baseline security requirements that future
  algorithm registrations are expected to meet.



The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-jose-deprecate-none-rsa15/


No IPR declarations have been submitted directly on this I-D.




2026-09-25
06 Morgan Condie IESG state changed to In Last Call from Last Call Requested
2026-09-25
06 Deb Cooley Last call was requested
2026-09-25
06 Deb Cooley Last call announcement was generated
2026-09-25
06 Deb Cooley Ballot approval text was generated
2026-09-25
06 Deb Cooley IESG state changed to Last Call Requested from AD Evaluation::AD Followup
2026-09-25
06 (System) Changed action holders to Deb Cooley (IESG state changed)
2026-09-25
06 (System) Sub state has been changed to AD Followup from Revised I-D Needed
2026-09-25
06 Neil Madden New version available: draft-ietf-jose-deprecate-none-rsa15-06.txt
2026-09-25
06 (System) New version approved
2026-09-25
06 (System) Request for posting confirmation emailed to previous authors: Neil Madden
2026-09-25
06 Neil Madden Uploaded new revision
2026-09-24
05 Deb Cooley AD comments can be found here:  https://mailarchive.ietf.org/arch/msg/jose/M7fKp0weAnV_GOe8pU3d9zQwp00/
2026-09-24
05 (System) Changed action holders to Neil Madden (IESG state changed)
2026-09-24
05 Deb Cooley IESG state changed to AD Evaluation::Revised I-D Needed from AD Evaluation
2026-09-21
05 Deb Cooley IESG state changed to AD Evaluation from Publication Requested
2026-09-21
05 Deb Cooley Ballot writeup was changed
2026-09-21
05 Deb Cooley Ballot writeup was changed
2026-09-06
05 Karen O'Donoghue
Document Shepherd Write-Up for draft-ietf-jose-deprecate-none-rsa15

Document History

1. Does the working group (WG) consensus represent the strong concurrence of a few individuals, with others being …
Document Shepherd Write-Up for draft-ietf-jose-deprecate-none-rsa15

Document History

1. Does the working group (WG) consensus represent the strong concurrence of a few individuals, with others being silent, or did it reach broad agreement?

This document received support and no opposition during the working group last call.
The working group last call was extended to obtain additional feedback. In addition, at IETF 126, a poll of participants resulted in 27 participants supporting publication, 0 opposing publication, and 8 expressing no opinion. Given this the shepherd believes there is sufficient working group consensus to advance the document.

2. Was there controversy about particular points, or were there decisions where the consensus was particularly rough?

There was discussion regarding how the document should characterize legitimate historical uses of the JWS “none” algorithm, particularly uses in OpenID Connect.

Following discussion at IETF 124, the chairs conducted a two-week consensus call on the mailing list in February 2026 concerning whether and how these uses should be described. The discussion resulted in compromise text acknowledging the historical OpenID Connect use cases while retaining the document’s conclusion that the security benefits of deprecating “none” outweigh the risk of affecting those uses.

The resulting text was incorporated into the document, and the issue did not result in any opposition during working group last call.

3. Has anyone threatened an appeal or otherwise indicated extreme discontent? If so, please summarize the areas of conflict in separate email messages to the responsible Area Director.

No. The shepherd is not aware of anyone threatening an appeal or otherwise expressing extreme discontent regarding this document.

4. For protocol documents, are there existing implementations of the contents of the document? Have a significant number of potential implementers indicated plans to implement? Are any existing implementations reported somewhere, either in the document itself (as RFC 7942 recommends) or elsewhere (where)?

This document does not define a new protocol mechanism requiring implementation. It changes the recommended status of two existing JOSE algorithms and provides guidance to JOSE library and application developers. It also updates the review criteria for future registrations in the JOSE algorithms registry.

Additional Reviews

5. Do the contents of this document closely interact with technologies in other IETF working groups or external organizations, and would it therefore benefit from their review? Have those reviews occurred? If yes, describe which reviews took place.

The document relates primarily to JOSE. It also discusses RSA PKCS#1 v1.5 security guidance being developed in the IRTF CFRG and cites NIST SP 800-131A. It discusses historical uses of the “none” algorithm in OpenID Connect.

The relationship to OpenID Connect received specific working group discussion, including input from participants familiar with OpenID Connect, and resulted in the explanatory text in Section 2.

No additional formal cross-working-group or external-organization review is believed necessary prior to IETF Last Call.

6. Describe how the document meets any required formal expert review criteria, such as the MIB Doctor, YANG Doctor, media type, and URI type reviews.

No such formal expert reviews are required. The document contains no MIB or YANG modules and does not define media types, URI schemes, or similar constructs requiring specialized review.

The document does update the review instructions for the Designated Experts for the IANA “JSON Web Signature and Encryption Algorithms” registry. These changes were reviewed as part of the JOSE working group’s consideration of the document.

7. If the document contains a YANG module, has the final version of the module been checked with any of the recommended validation tools for syntax and formatting validation? If there are any resulting errors or warnings, what is the justification for not fixing them at this time? Does the YANG module comply with the Network Management Datastore Architecture (NMDA) as specified in RFC 8342?

Not applicable. The document contains no YANG modules.

8. Describe reviews and automated checks performed to validate sections of the final version of the document written in a formal language, such as XML code, BNF rules, MIB definitions, CBOR’s CDDL, etc.

Not applicable. The document contains no such formal-language specifications.

Document Shepherd Checks

9. Based on the shepherd’s review of the document, is it their opinion that this document is needed, clearly written, complete, correctly designed, and ready to be handed off to the responsible Area Director?

Yes. The shepherd has reviewed the document and believes that it is needed, clearly written, complete, and technically appropriate.

The document is ready to be handed to the responsible Area Director. There are some minor document nits noted below that will be resolved by the author after the review of the responsible Area Director.

10. Several IETF Areas have assembled lists of common issues that their reviewers encounter. For which areas have such issues been identified and addressed? For which does this still need to happen in subsequent reviews?

The document is primarily a Security Area document, and security considerations are fundamental to its purpose rather than being an ancillary aspect of the specification. The document provides the security rationale for both algorithm deprecations and specifies security properties to be considered by Designated Experts for future algorithm registrations.

No issues from other Area-specific review lists have been identified that require resolution before progressing the document. Additional review will occur as part of IETF Last Call and IESG evaluation.

11. What type of RFC publication is being requested on the IETF stream (Best Current Practice, Proposed Standard, Internet Standard, Informational, Experimental or Historic)? Why is this the proper type of RFC? Do all Datatracker state attributes correctly reflect this intent?

Publication as a Proposed Standard on the IETF stream is requested.

This is appropriate because the document updates the Proposed Standars RFC 7518, changes requirements applicable to JOSE implementations and future specifications, and updates the Designated Expert review criteria associated with the JOSE algorithm registry.

12. Have reasonable efforts been made to remind all authors of the intellectual property rights (IPR) disclosure obligations described in BCP 79? To the best of your knowledge, have all required disclosures been filed? If not, explain why. If yes, summarize any relevant discussion, including links to publicly-available messages when applicable.

Yes. The working group last-call announcement explicitly reminded the author and working group participants of their IPR disclosure obligations under BCP 79. The

To the best of the shepherd’s knowledge, there are no outstanding IPR disclosure issues associated with this document.

13. Has each author, editor, and contributor shown their willingness to be listed as such? If the total number of authors and editors on the front page is greater than five, please provide a justification.

There is only one author, Neil Madden, who has continued to actively maintain the document through working group review and has therefore demonstrated willingness to be listed as the author.

14. Document any remaining I-D nits in this document. Simply running the idnits tool is not enough; please review the “Content Guidelines” on authors.ietf.org.

Minor nits have been identified in the -05 version of the document. The author will correct these after the AD review when addressing any issues she identifies.

No other substantive formatting or content-guideline issues were identified in the shepherd review.

15. Should any informative references be normative or vice-versa? See the IESG Statement on Normative and Informative References.

The normative/informative reference classification appears appropriate.

RFC 7518 is normative because this document updates its requirements and registry instructions. RFC 5116 is appropriately normative because the new Designated Expert criteria rely on the AEAD security property defined there. RFCs 2119 and 8174 are normative for interpretation of requirements language.

The references to RFC 8017, NIST SP 800-131A, the CFRG RSA guidance document, OpenID Connect, the cited cryptography textbook, CVE/CVSS material, and other background material are appropriately informative.

16. List any normative references that are not freely available to anyone. Did the community have sufficient access to review any such normative references?

None. All normative references are published RFCs and are freely available.

17. Are there any normative downward references (see RFC 3967 and BCP 97) that are not already listed in the DOWNREF registry? If so, list them.

There are no normative downward references requiring special treatment.

The Datatracker currently identifies RFC 5116 and RFC 7518 as downward references because the document’s metadata incorrectly indicates an intended status of Internet Standard. Correcting the intended status to Proposed Standard resolves this issue.

18. Are there normative references to documents that are not ready to be submitted to the IESG for publication or are otherwise in an unclear state? If so, what is the plan for their completion?

No. All normative references are published RFCs.

The reference to the CFRG RSA guidance Internet-Draft is informative and therefore does not create a normative dependency.

19. Will publication of this document change the status of any existing RFCs? If so, does the Datatracker metadata correctly reflect this and are those RFCs listed on the title page, in the abstract, and discussed in the introduction? If not, explain why and point to the part of the document where the relationship of this document to these other RFCs is discussed.

The document updates RFC 7518 but does not change RFC 7518’s publication status.

20. Describe the document shepherd’s review of the IANA considerations section, especially with regard to its consistency with the body of the document. Confirm that all aspects of the document requiring IANA assignments are associated with the appropriate reservations in IANA registries. Confirm that any referenced IANA registries have been clearly identified. Confirm that each newly created IANA registry specifies its initial contents, allocations procedures, and a reasonable name.

The shepherd has reviewed the IANA Considerations section and believes it is consistent with the body of the document.

No new IANA registries are created.

21. List any new IANA registries that require Designated Expert Review for future allocations. Are the instructions to the Designated Expert clear? Please include suggestions of designated experts, if appropriate.

No new IANA registries are created. This document updates the instructions for existing Designated Experts for the “JSON Web Signature and Encryption Algorithms” registry. These instructions are clear. And, given that this document updates existing registries, no new designated experts are required.
2026-09-06
05 Karen O'Donoghue IETF WG state changed to Submitted to IESG for Publication from WG Consensus: Waiting for Write-Up
2026-09-06
05 Karen O'Donoghue IESG state changed to Publication Requested from I-D Exists
2026-09-06
05 (System) Changed action holders to Deb Cooley (IESG state changed)
2026-09-06
05 Karen O'Donoghue Responsible AD changed to Deb Cooley
2026-09-06
05 Karen O'Donoghue Document is now in IESG state Publication Requested
2026-09-06
05 Karen O'Donoghue
Document Shepherd Write-Up for draft-ietf-jose-deprecate-none-rsa15

Document History

1. Does the working group (WG) consensus represent the strong concurrence of a few individuals, with others being …
Document Shepherd Write-Up for draft-ietf-jose-deprecate-none-rsa15

Document History

1. Does the working group (WG) consensus represent the strong concurrence of a few individuals, with others being silent, or did it reach broad agreement?

This document received support and no opposition during the working group last call.
The working group last call was extended to obtain additional feedback. In addition, at IETF 126, a poll of participants resulted in 27 participants supporting publication, 0 opposing publication, and 8 expressing no opinion. Given this the shepherd believes there is sufficient working group consensus to advance the document.

2. Was there controversy about particular points, or were there decisions where the consensus was particularly rough?

There was discussion regarding how the document should characterize legitimate historical uses of the JWS “none” algorithm, particularly uses in OpenID Connect.

Following discussion at IETF 124, the chairs conducted a two-week consensus call on the mailing list in February 2026 concerning whether and how these uses should be described. The discussion resulted in compromise text acknowledging the historical OpenID Connect use cases while retaining the document’s conclusion that the security benefits of deprecating “none” outweigh the risk of affecting those uses.

The resulting text was incorporated into the document, and the issue did not result in any opposition during working group last call.

3. Has anyone threatened an appeal or otherwise indicated extreme discontent? If so, please summarize the areas of conflict in separate email messages to the responsible Area Director.

No. The shepherd is not aware of anyone threatening an appeal or otherwise expressing extreme discontent regarding this document.

4. For protocol documents, are there existing implementations of the contents of the document? Have a significant number of potential implementers indicated plans to implement? Are any existing implementations reported somewhere, either in the document itself (as RFC 7942 recommends) or elsewhere (where)?

This document does not define a new protocol mechanism requiring implementation. It changes the recommended status of two existing JOSE algorithms and provides guidance to JOSE library and application developers. It also updates the review criteria for future registrations in the JOSE algorithms registry.

Additional Reviews

5. Do the contents of this document closely interact with technologies in other IETF working groups or external organizations, and would it therefore benefit from their review? Have those reviews occurred? If yes, describe which reviews took place.

The document relates primarily to JOSE. It also discusses RSA PKCS#1 v1.5 security guidance being developed in the IRTF CFRG and cites NIST SP 800-131A. It discusses historical uses of the “none” algorithm in OpenID Connect.

The relationship to OpenID Connect received specific working group discussion, including input from participants familiar with OpenID Connect, and resulted in the explanatory text in Section 2.

No additional formal cross-working-group or external-organization review is believed necessary prior to IETF Last Call.

6. Describe how the document meets any required formal expert review criteria, such as the MIB Doctor, YANG Doctor, media type, and URI type reviews.

No such formal expert reviews are required. The document contains no MIB or YANG modules and does not define media types, URI schemes, or similar constructs requiring specialized review.

The document does update the review instructions for the Designated Experts for the IANA “JSON Web Signature and Encryption Algorithms” registry. These changes were reviewed as part of the JOSE working group’s consideration of the document.

7. If the document contains a YANG module, has the final version of the module been checked with any of the recommended validation tools for syntax and formatting validation? If there are any resulting errors or warnings, what is the justification for not fixing them at this time? Does the YANG module comply with the Network Management Datastore Architecture (NMDA) as specified in RFC 8342?

Not applicable. The document contains no YANG modules.

8. Describe reviews and automated checks performed to validate sections of the final version of the document written in a formal language, such as XML code, BNF rules, MIB definitions, CBOR’s CDDL, etc.

Not applicable. The document contains no such formal-language specifications.

Document Shepherd Checks

9. Based on the shepherd’s review of the document, is it their opinion that this document is needed, clearly written, complete, correctly designed, and ready to be handed off to the responsible Area Director?

Yes. The shepherd has reviewed the document and believes that it is needed, clearly written, complete, and technically appropriate.

The document is ready to be handed to the responsible Area Director. There are some minor document nits noted below that will be resolved by the author after the review of the responsible Area Director.

10. Several IETF Areas have assembled lists of common issues that their reviewers encounter. For which areas have such issues been identified and addressed? For which does this still need to happen in subsequent reviews?

The document is primarily a Security Area document, and security considerations are fundamental to its purpose rather than being an ancillary aspect of the specification. The document provides the security rationale for both algorithm deprecations and specifies security properties to be considered by Designated Experts for future algorithm registrations.

No issues from other Area-specific review lists have been identified that require resolution before progressing the document. Additional review will occur as part of IETF Last Call and IESG evaluation.

11. What type of RFC publication is being requested on the IETF stream (Best Current Practice, Proposed Standard, Internet Standard, Informational, Experimental or Historic)? Why is this the proper type of RFC? Do all Datatracker state attributes correctly reflect this intent?

Publication as a Proposed Standard on the IETF stream is requested.

This is appropriate because the document updates the Proposed Standars RFC 7518, changes requirements applicable to JOSE implementations and future specifications, and updates the Designated Expert review criteria associated with the JOSE algorithm registry.

12. Have reasonable efforts been made to remind all authors of the intellectual property rights (IPR) disclosure obligations described in BCP 79? To the best of your knowledge, have all required disclosures been filed? If not, explain why. If yes, summarize any relevant discussion, including links to publicly-available messages when applicable.

Yes. The working group last-call announcement explicitly reminded the author and working group participants of their IPR disclosure obligations under BCP 79. The

To the best of the shepherd’s knowledge, there are no outstanding IPR disclosure issues associated with this document.

13. Has each author, editor, and contributor shown their willingness to be listed as such? If the total number of authors and editors on the front page is greater than five, please provide a justification.

There is only one author, Neil Madden, who has continued to actively maintain the document through working group review and has therefore demonstrated willingness to be listed as the author.

14. Document any remaining I-D nits in this document. Simply running the idnits tool is not enough; please review the “Content Guidelines” on authors.ietf.org.

Minor nits have been identified in the -05 version of the document. The author will correct these after the AD review when addressing any issues she identifies.

No other substantive formatting or content-guideline issues were identified in the shepherd review.

15. Should any informative references be normative or vice-versa? See the IESG Statement on Normative and Informative References.

The normative/informative reference classification appears appropriate.

RFC 7518 is normative because this document updates its requirements and registry instructions. RFC 5116 is appropriately normative because the new Designated Expert criteria rely on the AEAD security property defined there. RFCs 2119 and 8174 are normative for interpretation of requirements language.

The references to RFC 8017, NIST SP 800-131A, the CFRG RSA guidance document, OpenID Connect, the cited cryptography textbook, CVE/CVSS material, and other background material are appropriately informative.

16. List any normative references that are not freely available to anyone. Did the community have sufficient access to review any such normative references?

None. All normative references are published RFCs and are freely available.

17. Are there any normative downward references (see RFC 3967 and BCP 97) that are not already listed in the DOWNREF registry? If so, list them.

There are no normative downward references requiring special treatment.

The Datatracker currently identifies RFC 5116 and RFC 7518 as downward references because the document’s metadata incorrectly indicates an intended status of Internet Standard. Correcting the intended status to Proposed Standard resolves this issue.

18. Are there normative references to documents that are not ready to be submitted to the IESG for publication or are otherwise in an unclear state? If so, what is the plan for their completion?

No. All normative references are published RFCs.

The reference to the CFRG RSA guidance Internet-Draft is informative and therefore does not create a normative dependency.

19. Will publication of this document change the status of any existing RFCs? If so, does the Datatracker metadata correctly reflect this and are those RFCs listed on the title page, in the abstract, and discussed in the introduction? If not, explain why and point to the part of the document where the relationship of this document to these other RFCs is discussed.

The document updates RFC 7518 but does not change RFC 7518’s publication status.

20. Describe the document shepherd’s review of the IANA considerations section, especially with regard to its consistency with the body of the document. Confirm that all aspects of the document requiring IANA assignments are associated with the appropriate reservations in IANA registries. Confirm that any referenced IANA registries have been clearly identified. Confirm that each newly created IANA registry specifies its initial contents, allocations procedures, and a reasonable name.

The shepherd has reviewed the IANA Considerations section and believes it is consistent with the body of the document.

No new IANA registries are created.

21. List any new IANA registries that require Designated Expert Review for future allocations. Are the instructions to the Designated Expert clear? Please include suggestions of designated experts, if appropriate.

No new IANA registries are created. This document updates the instructions for existing Designated Experts for the “JSON Web Signature and Encryption Algorithms” registry. These instructions are clear. And, given that this document updates existing registries, no new designated experts are required.
2026-09-06
05 Karen O'Donoghue Intended Status changed to Proposed Standard from Internet Standard
2026-07-22
05 Karen O'Donoghue IETF WG state changed to WG Consensus: Waiting for Write-Up from In WG Last Call
2026-07-22
05 Karen O'Donoghue Notification list changed to kodonog@pobox.com because the document shepherd was set
2026-07-22
05 Karen O'Donoghue Document shepherd changed to Karen O'Donoghue
2026-07-22
05 Karen O'Donoghue Changed consensus to Yes from Unknown
2026-07-22
05 Karen O'Donoghue Intended Status changed to Internet Standard from None
2026-07-09
05 Karen O'Donoghue Added to session: IETF-126: jose  Tue-1200
2026-06-23
05 Neil Madden New version available: draft-ietf-jose-deprecate-none-rsa15-05.txt
2026-06-23
05 Neil Madden New version approved
2026-06-23
05 (System) Request for posting confirmation emailed to previous authors: Neil Madden
2026-06-23
05 Neil Madden Uploaded new revision
2026-05-06
04 Karen O'Donoghue IETF WG state changed to In WG Last Call from WG Document
2026-03-16
04 Michael P Added to session: IETF-125: jose  Tue-0100
2026-03-02
04 Neil Madden New version available: draft-ietf-jose-deprecate-none-rsa15-04.txt
2026-03-02
04 (System) New version approved
2026-03-02
04 (System) Request for posting confirmation emailed to previous authors: Neil Madden
2026-03-02
04 Neil Madden Uploaded new revision
2025-11-02
03 Karen O'Donoghue Added to session: IETF-124: jose  Wed-1430
2025-09-19
03 Neil Madden New version available: draft-ietf-jose-deprecate-none-rsa15-03.txt
2025-09-19
03 (System) New version approved
2025-09-19
03 (System) Request for posting confirmation emailed to previous authors: Neil Madden
2025-09-19
03 Neil Madden Uploaded new revision
2025-07-18
02 Karen O'Donoghue Added to session: IETF-123: jose  Thu-1500
2025-04-02
02 Neil Madden New version available: draft-ietf-jose-deprecate-none-rsa15-02.txt
2025-04-02
02 Neil Madden New version approved
2025-04-02
02 (System) Request for posting confirmation emailed to previous authors: Neil Madden
2025-04-02
02 Neil Madden Uploaded new revision
2025-03-20
01 Neil Madden New version available: draft-ietf-jose-deprecate-none-rsa15-01.txt
2025-03-20
01 (System) New version approved
2025-03-20
01 (System) Request for posting confirmation emailed to previous authors: Neil Madden , jose-chairs@ietf.org
2025-03-20
01 Neil Madden Uploaded new revision
2024-11-04
00 Karen O'Donoghue Added to session: IETF-121: jose  Mon-1300
2024-11-04
00 Karen O'Donoghue This document now replaces draft-madden-jose-deprecate-none-rsa15 instead of None
2024-11-03
00 Neil Madden New version available: draft-ietf-jose-deprecate-none-rsa15-00.txt
2024-11-03
00 Karen O'Donoghue WG -00 approved
2024-11-03
00 Neil Madden Set submitter to "Neil Madden ", replaces to (none) and sent approval email to group chairs: jose-chairs@ietf.org
2024-11-03
00 Neil Madden Uploaded new revision