Network Working Group R. Housley Request for Comments: 4853 Vigil Security Updates: 3852 April 2007 Category: Standards TrackCryptographic Message Syntax (CMS) Multiple Signer Clarification
Housley Standards Track [Page 1]
RFC 4853 CMS Multiple Signer Clarification April 2007 1. IntroductionThis document updates the Cryptographic Message Syntax [CMS]. The CMS SignedData protected content type allows multiple digital signatures, but the specification is unclear about the appropriate processing by a recipient of such a signed content. This document provides replacement text for a few paragraphs, making it clear that the protected content is validly signed by a given signer, if any of the digital signatures from that signer are valid.
2. Terminology
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in RFC 2119 [STDWORDS].
3. Update to RFC 3852, Section 5: Signed-data Content Type
RFC 3852, section 5, the next to the last paragraph says:
Housley Standards Track [Page 2]
RFC 4853 CMS Multiple Signer Clarification April 2007
This block of text is replaced with:
4. Update to RFC 3852, Section 5.1: SignedData Type
RFC 3852, section 5.1, the next to the last paragraph says:
Housley Standards Track [Page 3]
RFC 4853 CMS Multiple Signer Clarification April 2007 6. Security ConsiderationsThe replacement text will reduce the likelihood of interoperability errors during the transition from MD5 and SHA-1 to stronger one-way hash functions, or to better signature algorithms.
7. Normative References
[CMS] Housley, R., "Cryptographic Message Syntax (CMS)", RFC
Housley Standards Track [Page 4]
RFC 4853 CMS Multiple Signer Clarification April 2007
Full Copyright Statement