Use of the HSS and XMSS Hash-Based Signature Algorithms in Internet X.509 Public Key Infrastructure
RFC 9802, “Use of the HSS and XMSS Hash-Based Signature Algorithms in Internet X.509 Public Key Infrastructure”, is a Proposed Standard document published in June 2025 by D. Van Geest, K. Bashiri, S. Fluhrer, S. Gazdag, S. Kousidis. The canonical text is published by the RFC Editor.
Abstract
This document specifies algorithm identifiers and ASN.1 encoding formats for the following stateful Hash-Based Signature (HBS) schemes: Hierarchical Signature System (HSS), eXtended Merkle Signature Scheme (XMSS), and XMSS^MT (a multi-tree variant of XMSS). This specification applies to the Internet X.509 Public Key Infrastructure (PKI) when digital signatures are used to sign certificates and certificate revocation lists (CRLs).
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9802 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9801 Private Line Emulation over Packet Switched Networks
- RFC 9803 Extensible Provisioning Protocol Mapping for DNS Time-to-Live Values
- RFC 9800 Compressed SRv6 Segment List Encoding
- RFC 9804 Simple Public Key Infrastructure S-Expressions
- RFC 9799 Automated Certificate Management Environment Extensions for ".onion" Special-Use Domain Names
- RFC 9805 Deprecation of the IPv6 Router Alert Option for New Protocols
- RFC 9798 PIM Join/Prune Attributes for Locator/ID Separation Protocol Environments Using Underlay Multicast
- RFC 9806 Updates to SIP-Based Media Recording to Correct Metadata Media Type