Last Call Review of draft-ietf-pkix-sha2-dsa-ecdsa-
Forgot to cc secdir.
From: Stephen Hanna
Sent: Tuesday, October 20, 2009 1:08 PM
To: 'draft-ietf-pkix-sha2-dsa-ecdsa at tools.ietf.org'; iesg at ietf.org
Subject: secdir review for draft-ietf-pkix-sha2-dsa-ecdsa-10.txt
I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG. These comments were written primarily for the benefit of the
security area directors. Document editors and WG chairs should treat
these comments just like any other last call comments.
This document defines ASN.1 OIDs for DSA and ECDSA digital signatures
with SHA-224, SHA-256, SHA-384 or SHA-512 as hashing algorithms. These
OIDs may be used in X.509 certificates to indicate the signature
The specification is clear, well conceived, and well written. The
Security Considerations section is brief but it points to documents
that provide an appropriate level of supplementary information. In
summary, I do not have any security concerns related to this document.