Skip to main content

IETF Last Call Review of draft-ietf-jose-deprecate-none-rsa15-06
review-ietf-jose-deprecate-none-rsa15-06-artart-lc-leiba-2026-09-27-00

Request Review of draft-ietf-jose-deprecate-none-rsa15
Requested revision No specific revision (document currently at 06)
Type IETF Last Call Review
Team ART Area Review Team (artart)
Deadline 2026-10-09
Requested 2026-09-25
Authors Neil Madden
I-D last updated 2026-09-25 (Latest revision 2026-09-25)
Completed reviews Artart IETF Last Call review of -06 by Barry Leiba
Assignment Reviewer Barry Leiba
State Completed
Request IETF Last Call review on draft-ietf-jose-deprecate-none-rsa15 by ART Area Review Team Assigned
Posted at https://mailarchive.ietf.org/arch/msg/art/MiE9pSTOxXaPxabVxtRGOJA37Nc
Reviewed revision 06
Result Ready
Completed 2026-09-27
review-ietf-jose-deprecate-none-rsa15-06-artart-lc-leiba-2026-09-27-00
Thanks for a very clear document, and one that requires little comment.  There
are two parts to this: the part that deprecates the two registered algorithms
needs no comment at all.  The second part, in Section 7.2, adds three points to
the guidance for the designated expert.

All three points are good, and I have no issue with their substance.  I
suggest, though, that the common phrasing, “only algorithms that are reasonably
believed to meet the standard security goal of [something] are to be approved,”
can easily be taken to suggest that such algorithms *should* be approved, and
might not age well as expectations change over time.  Perhaps it might be
better to phrase these as, “only algorithms that are reasonably believed to
meet the standard security goal of [something] are to be considered for
approval,” with an additional paragraph that stresses that current security
expectations should be taken into account during that consideration, in
addition to these three points.

What do you think?