Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax
RFC 9708, “Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax”, is a Proposed Standard document published in January 2025 by R. Housley. It obsoletes RFC 8708. The canonical text is published by the RFC Editor.
Abstract
This document specifies the conventions for using the Hierarchical Signature System (HSS) / Leighton-Micali Signature (LMS) hash-based signature algorithm with the Cryptographic Message Syntax (CMS). In addition, the algorithm identifier and public key syntax are provided. The HSS/LMS algorithm is one form of hash-based digital signature; it is described in RFC 8554. This document obsoletes RFC 8708.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9708 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9707 Report from the IAB Workshop on Barriers to Internet Access of Services
- RFC 9709 Encryption Key Derivation in the Cryptographic Message Syntax Using HKDF with SHA-256
- RFC 9706 TreeDN: Tree-Based Content Delivery Network for Live Streaming to Mass Audiences
- RFC 9710 Simple Fixes to the IP Flow Information Export Entities IANA Registry
- RFC 9705 Refresh-Interval Independent RSVP Fast Reroute Facility Protection
- RFC 9711 The Entity Attestation Token
- RFC 9704 Establishing Local DNS Authority in Validated Split-Horizon Environments
- RFC 9712 IETF Meeting Venue Requirements Review