Last Call Review of draft-ietf-pkix-sha2-dsa-ecdsa-

Request Review of draft-ietf-pkix-sha2-dsa-ecdsa
Requested rev. no specific revision (document currently at 10)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2009-10-20
Requested 2009-09-23
Other Reviews
Review State Completed
Reviewer Steve Hanna
Review review-ietf-pkix-sha2-dsa-ecdsa-secdir-lc-hanna-2009-10-22
Posted at
Draft last updated 2009-10-22
Review completed: 2009-10-22


Forgot to cc secdir.



-----Original Message-----
From: Stephen Hanna 
Sent: Tuesday, October 20, 2009 1:08 PM
To: 'draft-ietf-pkix-sha2-dsa-ecdsa at'; iesg at
Subject: secdir review for draft-ietf-pkix-sha2-dsa-ecdsa-10.txt

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
security area directors.  Document editors and WG chairs should treat
these comments just like any other last call comments.

This document defines ASN.1 OIDs for DSA and ECDSA digital signatures
with SHA-224, SHA-256, SHA-384 or SHA-512 as hashing algorithms. These
OIDs may be used in X.509 certificates to indicate the signature
algorithm used.

The specification is clear, well conceived, and well written. The
Security Considerations section is brief but it points to documents
that provide an appropriate level of supplementary information. In
summary, I do not have any security concerns related to this document.