[lamps] Fw: New Version Notification for draft-ietf-lamps-cms-euf-cma-signeddata-03.txt
Daniel Van Geest <daniel.vangeest@cryptonext-security.com> Mon, 14 September 2026 12:31 UTC
Received: from PAUP264CU001.outbound.protection.outlook.com (mail-francecentralazlp170110002.outbound.protection.outlook.com [IPv6:2a01:111:f403:c20a::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange secp256r1 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id 2345B46 for <spasm@ietf.org>; Mon, 14 Sep 2026 12:31:02 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=cryptonext-security.com header.s=selector1 header.b=n+6KQY06; arc=pass ("microsoft.com:s=arcselector10001:i=1"); dmarc=pass (policy=reject) header.from=cryptonext-security.com; spf=pass (mx.ietf.org: domain of daniel.vangeest@cryptonext-security.com designates 2a01:111:f403:c20a::2 as permitted sender) smtp.mailfrom=daniel.vangeest@cryptonext-security.com
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ninsoc/lfYAuTQ/W/p8elhTKeYtccDSYvXfwygz/c+t5Dv2IPUUtiD/ERlxXgr25AbWVwlkVUkcw/7s92198il+j2MJ5/Qr8mPt4TcAd1QwwuHj0ESMJSQ+G4F/KlAZ472epMFu2GYIlRYct8BkV2ZtYKEEdT+2C4owXH73XLStoehJQc1Xi0CErEhZULynpJEOe3JL4GrnNtFCuj2ht8JPYYDFxqGrvV8sCAj40sxHmhvifN7jZfn9213kdz70/8hlO63w9kUr5QCtj9xZ6ASQ9OZtETTK6VSouKvaIIXIcMPS8+PgXtSd2wT1nd9znC8TR5nIXXNeGK+NQsdojRw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=FCUqV1tmrDE+EQkPOnG2A6yg+UISxr4nFwO4o9AAuM4=; b=tU42CFa7zLYKnWrT1z/ZfzgriSQd7fQJnvgILuuEGPGt4ela2mkpERJYihTfTUjFk1jBU1FZML+H1Tkrl4tz3cU5619YVU+pDgT9Dg/SYPVvGfG3JYnTZmhQws5XQ960zmaokYHZT1EsfUWWJlSBQtLULGCWYtTM3aNuuw4Q/ltTfV5K5sjOAgoE8u60eryA5aV48X6AkRO2kaP08k8Z0JbDkkJWXeLO8i8OSa21+jgdaI+8AUQzzEkSfq2fOmfznGwejterbmaBZc3naAA91xDEish5qsr8jPSO/W9ECxYS+AJcwqMxY84t+UwNrd0iK40Z3qQwAVEWCI5AC6PEiQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cryptonext-security.com; dmarc=pass action=none header.from=cryptonext-security.com; dkim=pass header.d=cryptonext-security.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cryptonext-security.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=FCUqV1tmrDE+EQkPOnG2A6yg+UISxr4nFwO4o9AAuM4=; b=n+6KQY06CXi4QOZewODbGvPRZko62fmMoChBg4EgYjM8lx5BfCw72L/30eQBHKaer9y7Jk0FlMGKSR+N5kj3R3CxS1wE979N6GP+BtXCDyAmmD2atLFVANYZSTeNN40x5t8a5T0ZEoN/t6WShG6msTSCYZbqDHGVBONN4aaUw7W2SMkxdYS9KXnfdhtGmBmBRr2CmA+JC51YW5cswK5np/BXHlqzzCdhtbJnWpufAfU86/OhSta+CSOnyJK3tlnsDRauuF4fYcoNWYmMdWyW6msXgy8af9tlQFb6DsFW/1d7X8r8Hq8JI/jGcYB+VDuuUlbq6TaWG2RSdDfGcfmzRQ==
Received: from PA0P264MB6925.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:55a::5) by PR0P264MB2837.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:1d0::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.406.12; Mon, 14 Sep 2026 12:30:52 +0000
Received: from PA0P264MB6925.FRAP264.PROD.OUTLOOK.COM ([fe80::87e8:c70b:3b90:e83d]) by PA0P264MB6925.FRAP264.PROD.OUTLOOK.COM ([fe80::87e8:c70b:3b90:e83d%4]) with mapi id 15.21.0406.007; Mon, 14 Sep 2026 12:30:52 +0000
From: Daniel Van Geest <daniel.vangeest@cryptonext-security.com>
To: LAMPS <spasm@ietf.org>, Roman Danyliw <rdd@cert.org>
Thread-Topic: New Version Notification for draft-ietf-lamps-cms-euf-cma-signeddata-03.txt
Thread-Index: AQHdREIblUQ/0ZFG7UKWo55ZLstu7LbOAKa5
Date: Mon, 14 Sep 2026 12:30:52 +0000
Message-ID: <PA0P264MB69255BEE498640F68E139142B6BB2@PA0P264MB6925.FRAP264.PROD.OUTLOOK.COM>
References: <178938784895.558404.14178946821807155381@dt-datatracker-597c8c8754-4t7c8>
In-Reply-To: <178938784895.558404.14178946821807155381@dt-datatracker-597c8c8754-4t7c8>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PA0P264MB6925:EE_|PR0P264MB2837:EE_
x-ms-office365-filtering-correlation-id: c68c7742-b5be-4c7b-e8e4-08df125c03dd
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|23010399003|1800799024|366016|38070700021|11063799006|56012099006|10067099003|22082099003|18002099003|6133799003|3023799007|8096899003|13003099007;
x-microsoft-antispam-message-info: FZqZfyH878zvBYyRiOtIK/BE5T/4sPNKQDvzuDCONdVOa/X6U2IPpOf744e+n/Cvm4Qx1YXgGtDt0CaA/WOY0QZOwEmzKu0AxLLHtvEm63Z75bp2/HxYj6qNaDEgttahyYsQoGsCXsIg3cEoIiMc8aD6JsFWPmY7ljXE7C4MCulvAz08vhP1RneFE8vUTZcJgkC5I7RAhrqRw15Y7mM2thDWwHLs1RVTUF7cgVwb9//mT90tpW9KQlbbaISL3UST3Ur1PUofxvynB1ksYqXa54qpelNoIoWmY1RqFZdJvC+pcT3HxThhHgXhFAtjUl4O4achHWuRxVOFkpqqYbZVwU60nMDypdiB+03PeSlYFsOqwWJrJNHk0684IfhGekBkj5fDWxQ2k5USQbm+rLrovtPOcWgOgXMjVDKm8oAzNQcQGGCoZccarR23jOXNH+vG+exZnARZmN+Oouu3rZjslF9DRFx292OKJ2edai0Im3RuM1FWefQLIO+qn2XlCrUL31dJXHIhbMhshTZqy4QOiXqz+zn9R5SNK3/LGXlR2bK9TPfDS2mcrB4ed4IPGceRN1ZPbfoeDnl1wDGSvecaau4HeBKK+mBYAF65FSftDnhifoOmlrAKcsm4M4P5gdEJbHYyPP0cNA5k08qy02Uax34EZJzd0nB3jLN0o7fbfGo5mx/zbfMcvwtbeitG+UfKLurocGJ81RARnXc2zCSCFQRBT6220Bot1h7c8OBGeg8=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PA0P264MB6925.FRAP264.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(23010399003)(1800799024)(366016)(38070700021)(11063799006)(56012099006)(10067099003)(22082099003)(18002099003)(6133799003)(3023799007)(8096899003)(13003099007);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 7BGZK1FxhcjDk4uWz9e3YrCWK2VGPsBmVLM18qQWIwN0PxSgeZOncgviuT6rUsNXIoZeK2/DxdxsWTDzhwwqNv764r9q9xE4MYnCdHev7SFo0qlVt/zYNJMlsy1GO5SUycNtCNmtJ+C1RfaBOx3ASz6ssnaR9CRhZJEsyfhJnuvQcT1EbbAAeLkWeRF5I/YRcrzxXI7n2wbe7ZTIOzO0nbvUOaqrN1+aDN8p2OyJcnFv0sOAaD1nB0uZ5/qatwKJfK8Qxzbwzt6F8pOMaUqrwqbYgIX3FpagqB2KGjX+2Uv6vzYdazfALxzOn+dobzE4blrvb7vwbK55d5hLaH/2yExoYXNSTbl2rV+JExcVuLfAYusBjrCqPWQ03oASqQq6K+MBsdxPzlns12qzWr9HE0hzuqMic5EQnEDr98RwTOXKTop6GwsTeDS8P7qOs8KpRuvfwxWrtw/fvoadr8TmTSy/osL0hlkId2qlDNgv9WzdKzOVea80yrdafLOsJ8pe+gH7kETj8UmEfDBGKSlrVg2L3owoLZjvyqoDU0F30PoXLtbtA0iCbiyouewy+ooxab1vvTrwwagIX3wQWlhuX0RIAgeS8PHzD24WM6b1/le71wUSfqI+C83Zs/ZWI8m1C+yfuDtsGXqSFi6BrFV/VqQ9SYJ1P++pIjdGb2VRUY3stsdbkUNbvaELuc+V6CNLp/KRmGmdxAYC3YAaasq5z+imB5jFt8nuSRIuUOZFN9zMFMN47KxI7TC0dznPG7C9oXpREjAVUf8+FGe64QR67aFSloWeYiUhHiks4WwPRB8yEBe6kp+M0br5nxwq5UmvM7gKVgoqZK9cgm6IaZxerQse9Q9Jozod3Pi4O2vgO6ggwlL7y19P7hxMLe6wGbMpTUH+wdIwOklA7d65yph8lT6yOHXB1dC72HLLwg+tN5A0cUmNKH5R5P5qg3EKOfYkVeQdiytlOdRm2Gz9C0KdRcYOivYgNOVMOd8DMGlfurabZ8qzr/myr/LXSQn8f+qTlWKt9emcvaDCbPo0OIufVMsht1Lo1jF9DmNXYUihOXZ9yA1PDys4LLXSyuHHqR5E+HEdvyfuatQylTyAVtLZ/1Yx/b/A2KN7cPIioN/1RCOE0ozsM0fOmHCPDdvvS9lizumXoHnjc2PJHB+zmz0n7SC7A45dZ0LeTq4ol6fckw9iMyf4tIIJkqoiGnMtuMkAIQrw9I6Ul8VBDlBBAtud5zEO8FurO7IYnbO1SChL7olJMvTbVk4nR8zOkmtXz7+NAy1YQX3wlfC1AG1oO4ctQcqKO8kQAHxdtF/gkSdJEhSa6OW+QHUUgSyx/A7iqMDzsptXVpiiOGIUfZeMzQ+rHOfA843SB9EP6eyG+SUHXH0dPgA6Ird4jsRhO4tndbFNHrjcBi+9cFTv2lhmchhxAkriFvD+Wc4Izrn8jcraO03f4KZOQqFaGviDpVg2MvnxAqa/8sgdOaSiydiLO1wbCbMIB6DqdegH38ykp33B6uuwHoupDh6KUin92hHEBME7WBPTuXJdwnocYFFK2sITTEdb3B4OQ0KJRn0nDRuPX4tN3cFdD2BPUopoKdVQxA9EDBq28IxfE8cey1bOsGDXhoBg3OuZAJPxOPi+UdDDATfdPgf4BbWguoMqBr7CyGK2UQNQylnTA4DN5M72fkGJ3btxBZa75uEALk6tIYceqDIjgSd5Y1/1NEgnzq4Wm6uuLGGA35HXZoC8hxk7tE2ZGNyG9GupSlK+FBd9I7nYnZm21Q0k70fglkhMRqvEpRfQ
Content-Type: multipart/alternative; boundary="_000_PA0P264MB69255BEE498640F68E139142B6BB2PA0P264MB6925FRAP_"
MIME-Version: 1.0
X-OriginatorOrg: cryptonext-security.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PA0P264MB6925.FRAP264.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: c68c7742-b5be-4c7b-e8e4-08df125c03dd
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Sep 2026 12:30:52.1007 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: da4a2df1-4b1b-489d-a7f4-224b58fd4200
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: PDAiJd+c7SkRIbdylBASv4PaJoKSJy0VHNWoBgDwKqAkSGVSrMBZB22qsj2gBYB07RVY2pUcwK3I705ZfC3sDYUVr+00tfnLN8MNzlSkBd5TDAOSc6CsrI4drVJ2YlyB
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PR0P264MB2837
X-Spamd-Bar: --
Message-ID-Hash: OLXTTIQ7O7UUSCRBIKIMBNAB7VGGC6EX
X-Message-ID-Hash: OLXTTIQ7O7UUSCRBIKIMBNAB7VGGC6EX
X-MailFrom: daniel.vangeest@cryptonext-security.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-spasm.ietf.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [lamps] Fw: New Version Notification for draft-ietf-lamps-cms-euf-cma-signeddata-03.txt
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/isSB48CC9FA6mGdYkesAtfInwEw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>
This version address Roman's AD review. Falko also performed a Claude Fable 5.1 review of the document, which pointed out a key separation issue which is addressed in a new section. If this document is followed and signedAttrs is mandated (either through using a non-id-data content type, or explicitly by a protocol which defines a use of CMS SignedData), but the signing key is used in another context (other protocol or content type where signedAttrs is not mandated), then the other context might be used as a signing oracle against the stronger context. In particular, this issue arises if you update a protocol to require signedAttrs but an application has to continue to support signing with the older version with the same key for backwards compatibility reasons. This is also an issue if you have multiple applications signing with the same key (e.g. desktop and mobile S/MIME client) and they are not updated at the same time. Mitigations for this are to use separate keys (not always possible) or apply the sender detection mitigations (difficult because this could apply to deployed code). Significant changes: * This document now updates RFC 5652. * "new use" of CMS Signed data is defined in the Conventions and Definitions section. * Give more details on the contents of the mimeData content type. * Add explanations for SHOULDs. * Add Key Separation section and security considerations. * Change some SHOULDs to MUSTs when it is a new use of CMS SignedData. Daniel ________________________________ From: internet-drafts@ietf.org <internet-drafts@ietf.org> Sent: Monday, September 14, 2026 1:10 PM To: Daniel Van Geest <daniel.vangeest@cryptonext-security.com>; Falko Strenzke <falko.strenzke@mtg.de> Subject: New Version Notification for draft-ietf-lamps-cms-euf-cma-signeddata-03.txt A new version of Internet-Draft draft-ietf-lamps-cms-euf-cma-signeddata-03.txt has been successfully submitted by Daniel Van Geest and posted to the IETF repository. Name: draft-ietf-lamps-cms-euf-cma-signeddata Revision: 03 Title: Best Practices for Signed Attributes in CMS SignedData Date: 2026-09-14 Group: lamps Pages: 19 URL: https://www.ietf.org/archive/id/draft-ietf-lamps-cms-euf-cma-signeddata-03.txt Status: https://datatracker.ietf.org/doc/draft-ietf-lamps-cms-euf-cma-signeddata/ HTML: https://www.ietf.org/archive/id/draft-ietf-lamps-cms-euf-cma-signeddata-03.html HTMLized: https://datatracker.ietf.org/doc/html/draft-ietf-lamps-cms-euf-cma-signeddata Diff: https://author-tools.ietf.org/iddiff?url2=draft-ietf-lamps-cms-euf-cma-signeddata-03 Abstract: The Cryptographic Message Syntax (CMS) has different signature verification behaviour based on whether signed attributes are present or not. This results in a potential existential forgery vulnerability in CMS and protocols which use CMS. This document describes the vulnerability and lists mitigations and best practices to avoid it. This document updates RFC 5652 by prohibiting the use of the id-data content type for new uses of the CMS SignedData type. The IETF Secretariat
- [lamps] Fw: New Version Notification for draft-ie… Daniel Van Geest