%% You should probably cite rfc9155 instead of this I-D. @techreport{ietf-tls-md5-sha1-deprecate-09, number = {draft-ietf-tls-md5-sha1-deprecate-09}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-tls-md5-sha1-deprecate/09/}, author = {Loganaden Velvindron and Kathleen Moriarty and Alessandro Ghedini}, title = {{Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2}}, pagetotal = 5, year = 2021, month = sep, day = 20, abstract = {The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digital signatures. However, this document does not deprecate SHA-1 with Hashed Message Authentication Code (HMAC), as used in record protection. This document updates RFC 5246.}, }