RFC 9709 · PROPOSED STANDARD · 2025

Encryption Key Derivation in the Cryptographic Message Syntax Using HKDF with SHA-256

Overview

RFC 9709, “Encryption Key Derivation in the Cryptographic Message Syntax Using HKDF with SHA-256”, is a Proposed Standard document published in January 2025 by R. Housley. The canonical text is published by the RFC Editor.

Abstract

This document specifies the derivation of the content-encryption key or the content-authenticated-encryption key in the Cryptographic Message Syntax (CMS) using the HMAC-based Extract-and-Expand Key Derivation Function (HKDF) with SHA-256. The use of this mechanism provides protection against an attacker that manipulates the content-encryption algorithm identifier or the content-authenticated-encryption algorithm identifier.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9709 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2025

Who Is Online

In total there are 96 users online: 0 registered, 88 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Baiduspider Bingbot Facebook Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372