Skip to main content

Online Certificate Status Protocol Algorithm Agility

Approval announcement
Draft of message to be sent after approval:


From: The IESG <>
To: IETF-Announce <>
Cc: Internet Architecture Board <>,
    RFC Editor <>,
    pkix mailing list <>,
    pkix chair <>
Subject: Protocol Action: 'Online Certificate Status Protocol Algorithm Agility' to Proposed Standard (draft-ietf-pkix-ocspagility-10.txt)

The IESG has approved the following document:
- 'Online Certificate Status Protocol Algorithm Agility'
  (draft-ietf-pkix-ocspagility-10.txt) as a Proposed Standard

This document is the product of the Public-Key Infrastructure (X.509)
Working Group.

The IESG contact persons are Tim Polk and Sean Turner.

A URL of this Internet Draft is:

Ballot Text

Technical Summary

The Online Certificate Status protocol (OCSP), RFC 2560 is a core PKIX query
response protocol for obtaining certificate status information. The OSCP
specification requires server responses to be signed but does not specify a
mechanism for selecting the signature algorithm to be used leading to possible
interoperability failures in contexts where multiple signature algorithms are in
use. This document specifies an algorithm for server signature algorithm
selection and an extension that allows a client to advise a server that specific
signature algorithms are supported.

Work Group Summary

The first draft was submitted about a year ago but did not gain momentum as the
author changed employment. A second author was assigned in July to speed up the
process. The WG discussions focused mainly on the algorithm selection algorithm,
mandatory to implement algorithms and how to specify algorithms. The discussions
were productive but non-controversial.

Document Quality

The document is brief and clearly written.


Steve Kent is the Document Shepherd.  Tim Polk is the
Responsible Area Director.

RFC Editor Note