cryptography

Cryptography: algorithms, modes, parameters and their use in Internet protocols

cryptography subjects:

cryptography RFCs (152)

Display RFCs as
  • RFC 9923: The FNV Non-Cryptographic Hash Algorithm

    Informational
  • RFC 9904: DNSSEC Cryptographic Algorithm Recommendation Update Process

    Proposed Standard
  • RFC 9861: KangarooTwelve and TurboSHAKE

    Informational
  • RFC 9771: Properties of Authenticated Encryption with Associated Data (AEAD) Algorithms

    Informational
  • RFC 9672: Transferring Opportunistic Wireless Encryption to the IEEE 802.11 Working Group

    Informational
  • RFC 9691: A Profile for Resource Public Key Infrastructure (RPKI) Trust Anchor Keys (TAKs)

    Proposed Standard
  • RFC 9640: YANG Data Types and Groupings for Cryptography

    Proposed Standard
  • RFC 9646: Conveying a Certificate Signing Request (CSR) in a Secure Zero-Touch Provisioning (SZTP) Bootstrapping Request

    Proposed Standard
  • RFC 9605: Secure Frame (SFrame): Lightweight Authenticated Encryption for Real-Time Media

    Proposed Standard
  • RFC 9490: Report from the IAB Workshop on Management Techniques in Encrypted Networks (M-TEN)

    Informational
  • RFC 9500: Standard Public Key Cryptography (PKC) Test Keys

    Informational
  • RFC 9498: The GNU Name System

    Informational
  • RFC 9381: Verifiable Random Functions (VRFs)

    Informational
  • RFC 9419: Considerations on Application - Network Collaboration Using Path Signals

    Informational
  • RFC 9323: A Profile for RPKI Signed Checklists (RSCs)

    Proposed Standard
  • RFC 9231: Additional XML Security Uniform Resource Identifiers (URIs)

    Proposed Standard
  • RFC 9187: Sequence Number Extension for Windowed Protocols

    Informational
  • RFC 9145: Integrity Protection for the Network Service Header (NSH) and Encryption of Sensitive Context Headers

    Proposed Standard
  • RFC 9058: Multilinear Galois Mode (MGM)

    Informational
  • RFC 8817: RTP Payload Format for Tactical Secure Voice Cryptographic Interoperability Specification (TSVCIS) Codec

    Proposed Standard
  • RFC 8785: JSON Canonicalization Scheme (JCS)

    Informational
  • RFC 8645: Re-keying Mechanisms for Symmetric Keys

    Informational
  • RFC 8636: Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Algorithm Agility

    Proposed Standard
  • RFC 8546: The Wire Image of a Network Protocol

    Informational
  • RFC 8462: Report from the IAB Workshop on Managing Radio Networks in an Encrypted World (MaRNEW)

    Informational
  • RFC 8479: Storing Validation Parameters in PKCS#8

    Informational
  • RFC 8411: IANA Registration for the Cryptographic Algorithm Object Identifier Range

    Informational
  • RFC 8404: Effects of Pervasive Encryption on Operators

    Informational
  • RFC 8351: The PKCS #8 EncryptedPrivateKeyInfo Media Type

    Informational
  • RFC 8387: Practical Considerations and Implementation Experiences in Securing Smart Object Networks

    Informational
  • RFC 8301: Cryptographic Algorithm and Key Usage Update to DomainKeys Identified Mail (DKIM)

    Proposed Standard
  • RFC 8291: Message Encryption for Web Push

    Proposed Standard
  • RFC 8188: Encrypted Content-Encoding for HTTP

    Proposed Standard
  • RFC 8110: Opportunistic Wireless Encryption

    Informational
  • RFC 8070: Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Freshness Extension

    Proposed Standard
  • RFC 7861: Remote Procedure Call (RPC) Security Version 3

    Proposed Standard
  • RFC 7696: BCP 201: Guidelines for Cryptographic Algorithm Agility and Selecting Mandatory-to-Implement Algorithms

    Best Current Practice
  • RFC 7512: The PKCS #11 URI Scheme

    Proposed Standard
  • RFC 7494: IEEE 802.11 Medium Access Control (MAC) Profile for Control and Provisioning of Wireless Access Points (CAPWAP)

    Proposed Standard
  • RFC 7401: Host Identity Protocol Version 2 (HIPv2)

    Proposed Standard
  • RFC 7492: Analysis of Bidirectional Forwarding Detection (BFD) Security According to the Keying and Authentication for Routing Protocols (KARP) Design Guidelines

    Informational
  • RFC 7435: Opportunistic Security: Some Protection Most of the Time

    Informational
  • RFC 7425: Adobe's RTMFP Profile for Flash Communication

    Informational
  • RFC 7343: An IPv6 Prefix for Overlay Routable Cryptographic Hash Identifiers Version 2 (ORCHIDv2)

    Proposed Standard
  • RFC 7349: LDP Hello Cryptographic Authentication

    Proposed Standard
  • RFC 7292: PKCS #12: Personal Information Exchange Syntax v1.1

    Informational
  • RFC 7253: The OCB Authenticated-Encryption Algorithm

    Informational
  • RFC 7210: Database of Long-Lived Symmetric Cryptographic Keys

    Proposed Standard
  • RFC 7029: Extensible Authentication Protocol (EAP) Mutual Cryptographic Binding

    Informational
  • RFC 7008: A Description of the KCipher-2 Encryption Algorithm

    Informational
  • RFC 6975: Signaling Cryptographic Algorithm Understanding in DNS Security Extensions (DNSSEC)

    Proposed Standard
  • RFC 6920: Naming Things with Hashes

    Proposed Standard
  • RFC 6813: The Network Endpoint Assessment (NEA) Asokan Attack Analysis

    Informational
  • RFC 6786: Encrypting the Protocol for Carrying Authentication for Network Access (PANA) Attribute-Value Pairs

    Proposed Standard
  • RFC 6734: Diameter Attribute-Value Pairs for Cryptographic Key Transport

    Proposed Standard
  • RFC 6629: Considerations on the Application of the Level 3 Multihoming Shim Protocol for IPv6 (Shim6)

    Informational
  • RFC 6539: IBAKE: Identity-Based Authenticated Key Exchange

    Informational
  • RFC 6508: Sakai-Kasahara Key Encryption (SAKKE)

    Informational
  • RFC 6317: Basic Socket Interface Extensions for the Host Identity Protocol (HIP)

    Experimental
  • RFC 6283: Extensible Markup Language Evidence Record Syntax (XMLERS)

    Proposed Standard
  • RFC 6261: Encrypted Signaling Transport Modes for the Host Identity Protocol

    Experimental
  • RFC 6114: The 128-Bit Blockcipher CLEFIA

    Informational
  • RFC 6094: Summary of Cryptographic Authentication Algorithm Implementation Requirements for Routing Protocols

    Informational
  • RFC 6014: Cryptographic Algorithm Identifier Allocation for DNSSEC

    Proposed Standard
  • RFC 6039: Issues with Existing Cryptographic Protection Methods for Routing Protocols

    Informational
  • RFC 6008: Authentication-Results Registration for Differentiating among Cryptographic Results

    Proposed Standard
  • RFC 5959: Algorithms for Asymmetric Key Package Content Type

    Proposed Standard
  • RFC 5967: The application/pkcs10 Media Type

    Informational
  • RFC 5906: Network Time Protocol Version 4: Autokey Specification

    Informational
  • RFC 5926: Cryptographic Algorithms for the TCP Authentication Option (TCP-AO)

    Proposed Standard
  • RFC 5698: Data Structure for the Security Suitability of Cryptographic Algorithms (DSSC)

    Proposed Standard
  • RFC 5535: Hash-Based Addresses (HBA)

    Proposed Standard
  • RFC 5403: RPCSEC_GSS Version 2

    Proposed Standard
  • RFC 5338: Using the Host Identity Protocol with Legacy Applications

    Experimental
  • RFC 5201: Host Identity Protocol

    Experimental

    Obsoleted by RFC 7401

  • RFC 5116: An Interface and Algorithms for Authenticated Encryption

    Proposed Standard
  • RFC 5016: Requirements for a DomainKeys Identified Mail (DKIM) Signing Practices Protocol

    Informational
  • RFC 5014: IPv6 Socket API for Source Address Selection

    Informational
  • RFC 4982: Support for Multiple Hash Algorithms in Cryptographically Generated Addresses (CGAs)

    Proposed Standard
  • RFC 4784: Verizon Wireless Dynamic Mobile IP Key Update for cdma2000(R) Networks

    Informational
  • RFC 4866: Enhanced Route Optimization for Mobile IPv6

    Proposed Standard
  • RFC 4843: An IPv6 Prefix for Overlay Routable Cryptographic Hash Identifiers (ORCHID)

    Experimental

    Obsoleted by RFC 7343

  • RFC 4752: The Kerberos V5 ("GSSAPI") Simple Authentication and Security Layer (SASL) Mechanism

    Proposed Standard
  • RFC 4581: Cryptographically Generated Addresses (CGA) Extension Field Format

    Proposed Standard
  • RFC 4556: Public Key Cryptography for Initial Authentication in Kerberos (PKINIT)

    Proposed Standard
  • RFC 4557: Online Certificate Status Protocol (OCSP) Support for Public Key Cryptography for Initial Authentication in Kerberos (PKINIT)

    Proposed Standard
  • RFC 4534: Group Security Policy Token v1

    Proposed Standard
  • RFC 4422: Simple Authentication and Security Layer (SASL)

    Proposed Standard
  • RFC 4503: A Description of the Rabbit Stream Cipher Algorithm

    Informational
  • RFC 4418: UMAC: Message Authentication Code using Universal Hashing

    Informational
  • RFC 4269: The SEED Encryption Algorithm

    Informational
  • RFC 4270: Attacks on Cryptographic Hashes in Internet Protocols

    Informational
  • RFC 4210: Internet X.509 Public Key Infrastructure Certificate Management Protocol (CMP)

    Proposed Standard

    Obsoleted by RFC 9810

  • RFC 4211: Internet X.509 Public Key Infrastructure Certificate Request Message Format (CRMF)

    Proposed Standard
  • RFC 4051: Additional XML Security Uniform Resource Identifiers (URIs)

    Proposed Standard

    Obsoleted by RFC 6931

  • RFC 3972: Cryptographically Generated Addresses (CGA)

    Proposed Standard
  • RFC 4009: The SEED Encryption Algorithm

    Informational

    Obsoleted by RFC 4269

  • RFC 3961: Encryption and Checksum Specifications for Kerberos 5

    Proposed Standard
  • RFC 3923: End-to-End Signing and Object Encryption for the Extensible Messaging and Presence Protocol (XMPP)

    Proposed Standard
  • RFC 3766: BCP 86: Determining Strengths For Public Keys Used For Exchanging Symmetric Keys

    Best Current Practice
  • RFC 3647: Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework

    Informational
  • RFC 3610: Counter with CBC-MAC (CCM)

    Informational
  • RFC 3579: RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP)

    Informational
  • RFC 3575: IANA Considerations for RADIUS (Remote Authentication Dial In User Service)

    Proposed Standard
  • RFC 3567: Intermediate System to Intermediate System (IS-IS) Cryptographic Authentication

    Informational

    Obsoleted by RFC 5304

  • RFC 3195: Reliable Delivery for syslog

    Proposed Standard
  • RFC 3097: RSVP Cryptographic Authentication -- Updated Message Type Value

    Proposed Standard
  • RFC 3078: Microsoft Point-To-Point Encryption (MPPE) Protocol

    Informational
  • RFC 3079: Deriving Keys for use with Microsoft Point-to-Point Encryption (MPPE)

    Informational
  • RFC 2985: PKCS #9: Selected Object Classes and Attribute Types Version 2.0

    Informational
  • RFC 2986: PKCS #10: Certification Request Syntax Specification Version 1.7

    Informational
  • RFC 2994: A Description of the MISTY1 Encryption Algorithm

    Informational
  • RFC 2898: PKCS #5: Password-Based Cryptography Specification Version 2.0

    Informational

    Obsoleted by RFC 8018

  • RFC 2941: Telnet Authentication Option

    Proposed Standard
  • RFC 2942: Telnet Authentication: Kerberos Version 5

    Proposed Standard
  • RFC 2946: Telnet Data Encryption Option

    Proposed Standard
  • RFC 2949: Telnet Encryption: CAST-128 64 bit Output Feedback

    Proposed Standard
  • RFC 2950: Telnet Encryption: CAST-128 64 bit Cipher Feedback

    Proposed Standard
  • RFC 2951: TELNET Authentication Using KEA and SKIPJACK

    Informational
  • RFC 2875: Diffie-Hellman Proof-of-Possession Algorithms

    Proposed Standard

    Obsoleted by RFC 6955

  • RFC 2865: Remote Authentication Dial In User Service (RADIUS)

    Draft Standard
  • RFC 2866: RADIUS Accounting

    Informational
  • RFC 2867: RADIUS Accounting Modifications for Tunnel Protocol Support

    Informational
  • RFC 2868: RADIUS Attributes for Tunnel Protocol Support

    Informational
  • RFC 2869: RADIUS Extensions

    Informational
  • RFC 2773: Encryption using KEA and SKIPJACK

    Experimental
  • RFC 2747: RSVP Cryptographic Authentication

    Proposed Standard
  • RFC 2612: The CAST-256 Encryption Algorithm

    Informational
  • RFC 2617: HTTP Authentication: Basic and Digest Access Authentication

    Draft Standard

    Obsoleted by RFC 7235, RFC 7615, RFC 7616, RFC 7617

  • RFC 2628: Simple Cryptographic Program Interface (Crypto API)

    Informational
  • RFC 2510: Internet X.509 Public Key Infrastructure Certificate Management Protocols

    Proposed Standard

    Obsoleted by RFC 4210

  • RFC 2511: Internet X.509 Certificate Request Message Format

    Proposed Standard

    Obsoleted by RFC 4211

  • RFC 2527: Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework

    Informational

    Obsoleted by RFC 3647

  • RFC 2459: Internet X.509 Public Key Infrastructure Certificate and CRL Profile

    Proposed Standard

    Obsoleted by RFC 3280

  • RFC 2314: PKCS #10: Certification Request Syntax Version 1.5

    Informational

    Obsoleted by RFC 2986

  • RFC 2222: Simple Authentication and Security Layer (SASL)

    Proposed Standard

    Obsoleted by RFC 4422, RFC 4752

  • RFC 2144: The CAST-128 Encryption Algorithm

    Informational
  • RFC 2137: Secure Domain Name System Dynamic Update

    Proposed Standard

    Obsoleted by RFC 3007

  • RFC 2138: Remote Authentication Dial In User Service (RADIUS)

    Proposed Standard

    Obsoleted by RFC 2865

  • RFC 2139: RADIUS Accounting

    Informational

    Obsoleted by RFC 2866

  • RFC 2058: Remote Authentication Dial In User Service (RADIUS)

    Proposed Standard

    Obsoleted by RFC 2138

  • RFC 2059: RADIUS Accounting

    Informational

    Obsoleted by RFC 2139

  • RFC 2065: Domain Name System Security Extensions

    Proposed Standard

    Obsoleted by RFC 2535

  • RFC 2084: Considerations for Web Transaction Security

    Informational
  • RFC 2040: The RC5, RC5-CBC, RC5-CBC-Pad, and RC5-CTS Algorithms

    Informational
  • RFC 1984: BCP 200: IAB and IESG Statement on Cryptographic Technology and the Internet

    Best Current Practice
  • RFC 1968: The PPP Encryption Control Protocol (ECP)

    Proposed Standard
  • RFC 1915: BCP 3: Variance for The PPP Compression Control Protocol and The PPP Encryption Control Protocol

    Best Current Practice
  • RFC 1875: UNINETT PCA Policy Statements

    Informational
  • RFC 1824: The Exponential Security System TESS: An Identity-Based Cryptographic Protocol for Authenticated Key-Exchange (E.I.S.S.-Report 1995/4)

    Informational
  • RFC 1805: Location-Independent Data/Software Integrity Protocol

    Informational
  • RFC 1751: A Convention for Human-Readable 128-bit Keys

    Informational

Subscribe to cryptography

Get notified when:

  • RFC changes to status, obsoleted by, updates, updated by, or subseries.
  • New RFC added to this subject or below
  • The subject was merged into another.