IETF Last Call Review of draft-ietf-jose-deprecate-none-rsa15-06
review-ietf-jose-deprecate-none-rsa15-06-artart-lc-leiba-2026-09-27-00
| Request | Review of | draft-ietf-jose-deprecate-none-rsa15 |
|---|---|---|
| Requested revision | No specific revision (document currently at 06) | |
| Type | IETF Last Call Review | |
| Team | ART Area Review Team (artart) | |
| Deadline | 2026-10-09 | |
| Requested | 2026-09-25 | |
| Authors | Neil Madden | |
| I-D last updated | 2026-09-25 (Latest revision 2026-09-25) | |
| Completed reviews |
Artart IETF Last Call review of -06
by Barry Leiba
|
|
| Assignment | Reviewer | Barry Leiba |
| State | Completed | |
| Request | IETF Last Call review on draft-ietf-jose-deprecate-none-rsa15 by ART Area Review Team Assigned | |
| Posted at | https://mailarchive.ietf.org/arch/msg/art/MiE9pSTOxXaPxabVxtRGOJA37Nc | |
| Reviewed revision | 06 | |
| Result | Ready | |
| Completed | 2026-09-27 |
review-ietf-jose-deprecate-none-rsa15-06-artart-lc-leiba-2026-09-27-00
Thanks for a very clear document, and one that requires little comment. There are two parts to this: the part that deprecates the two registered algorithms needs no comment at all. The second part, in Section 7.2, adds three points to the guidance for the designated expert. All three points are good, and I have no issue with their substance. I suggest, though, that the common phrasing, “only algorithms that are reasonably believed to meet the standard security goal of [something] are to be approved,” can easily be taken to suggest that such algorithms *should* be approved, and might not age well as expectations change over time. Perhaps it might be better to phrase these as, “only algorithms that are reasonably believed to meet the standard security goal of [something] are to be considered for approval,” with an additional paragraph that stresses that current security expectations should be taken into account during that consideration, in addition to these three points. What do you think?