Forgot to cc secdir. Thanks, Steve -----Original Message----- From: Stephen Hanna Sent: Tuesday, October 20, 2009 1:08 PM To: 'draft-ietf-pkix-sha2-dsa-ecdsa at tools.ietf.org'; iesg at ietf.org Subject: secdir review for draft-ietf-pkix-sha2-dsa-ecdsa-10.txt I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. This document defines ASN.1 OIDs for DSA and ECDSA digital signatures with SHA-224, SHA-256, SHA-384 or SHA-512 as hashing algorithms. These OIDs may be used in X.509 certificates to indicate the signature algorithm used. The specification is clear, well conceived, and well written. The Security Considerations section is brief but it points to documents that provide an appropriate level of supplementary information. In summary, I do not have any security concerns related to this document.