RFC 6211 · PROPOSED STANDARD · 2011

Cryptographic Message Syntax Algorithm Identifier Protection Attribute

Overview

RFC 6211, “Cryptographic Message Syntax Algorithm Identifier Protection Attribute”, is a Proposed Standard document published in April 2011 by J. Schaad. The canonical text is published by the RFC Editor.

Abstract

The Cryptographic Message Syntax (CMS), unlike X.509/PKIX certificates, is vulnerable to algorithm substitution attacks. In an algorithm substitution attack, the attacker changes either the algorithm being used or the parameters of the algorithm in order to change the result of a signature verification process. In X.509 certificates, the signature algorithm is protected because it is duplicated in the TBSCertificate.signature field with the proviso that the validator is to compare both fields as part of the signature validation process. This document defines a new attribute that contains a copy of the relevant algorithm identifiers so that they are protected by the signature or authentication process. [STANDARDS-TRACK]

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 6211 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2011

Who Is Online

In total there are 37 users online: 0 registered, 30 guests and 7 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Baiduspider Facebook Majestic Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354