Skip to main content

Legacy RSASSA-PKCS1-v1_5 codepoints for TLS 1.3
draft-ietf-tls-tls13-pkcs1-07

Approval announcement
Draft of message to be sent after approval:

Announcement

From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
Cc: The IESG <iesg@ietf.org>, draft-ietf-tls-tls13-pkcs1@ietf.org, paul.wouters@aiven.io, rfc-editor@rfc-editor.org, sean@sn3rd.com, tls-chairs@ietf.org, tls@ietf.org
Subject: Protocol Action: 'Legacy RSASSA-PKCS1-v1_5 codepoints for TLS 1.3' to Proposed Standard (draft-ietf-tls-tls13-pkcs1-07.txt)

The IESG has approved the following document:
- 'Legacy RSASSA-PKCS1-v1_5 codepoints for TLS 1.3'
  (draft-ietf-tls-tls13-pkcs1-07.txt) as Proposed Standard

This document is the product of the Transport Layer Security Working Group.

The IESG contact persons are Paul Wouters and Deb Cooley.

A URL of this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-tls-tls13-pkcs1/


Ballot Text

Technical Summary

   This document allocates code points for the use of RSASSA-PKCS1-v1_5
   with client certificates in TLS 1.3.  This removes an obstacle for
   some deployments to migrate to TLS 1.3.

Working Group Summary

There was broad agreement to adopt this I-D. The biggest point of controversy,
if you want to call it that, is whether to adopt the I-D at all. After ripping
RSA signatures out of TLS 1.3 nobody wanted to add them back, but people understood
and accepted thereality of the situation as discussed in the I-D.

Document Quality

Implementations: Chromium/BoringSSL and Edge browsers; Web server:
IIS/HTTP.SYS; HTTP client libraries WinInet, WinHTTP, .NET.

Personnel

   The Document Shepherd for this document is Sean Turner. The Responsible
   Area Director is Paul Wouters.

RFC Editor Note