%% You should probably cite rfc9155 instead of this I-D. @techreport{ietf-tls-md5-sha1-deprecate-08, number = {draft-ietf-tls-md5-sha1-deprecate-08}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-tls-md5-sha1-deprecate/08/}, author = {Loganaden Velvindron and Kathleen Moriarty and Alessandro Ghedini}, title = {{Deprecating MD5 and SHA-1 signature hashes in (D)TLS 1.2}}, pagetotal = 6, year = 2021, month = sep, day = 3, abstract = {The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack and this document deprecates their use in TLS 1.2 digital signatures. However, this document does not deprecate SHA-1 in HMAC for record protection. This document updates RFC 5246.}, }