United States Department of Veterans Affairs

One-VA Technical Reference Model (TRM) v13.3

TRM LogoIETF RFC 3852, Cryptographic Message Syntax (CMS)Link for Help

Add Request Summary

Description: The CMS describes an encapsulation syntax for data protection. It supports digital signatures and encryption. The syntax allows multiple encapsulations; one encapsulation envelope can be nested inside another. Likewise, one party can digitally sign some previously encapsulated data. It also allows arbitrary attributes, such as signing time, to be signed along with the message content, and provides for other attributes such as countersignatures to be associated with a signature. The CMS can support a variety of architectures for certificate-based key management, such as the one defined by the PKIX working group [PROFILE]. The CMS values are generated using ASN.1 [X.208-88], using BER-encoding [X.209-88]. Values are typically represented as octet strings. While many systems are capable of transmitting arbitrary octet strings reliably, it is well known that many electronic mail systems are not. This document does not address mechanisms for encoding octet strings for reliable transmission in such environments. Website: http://tools.ietf.org/html/rfc3852
TRM Owner: IS
Business Need: To comply with Homeland Security Presidential Directive 12 (HSPD 12). FIPS Pub 201-1 was created to implement this Directive and is currently listed on the standards profile. FIPS Pub 201-1 recommends specific standards to comply with HSPD-12.
Major Initiative: Not Provided
Planned Usage: This standard has been identified in the CY11 version of the DoD/VA Target Standards Profile (TSP) for interoperability.
Requirements: n/a at this time
Waiver: Not Provided
Required Assessment Date: Not Provided
TRM Entries Considered: n/a
Version Number:
Vendor Name: The Internet Engineering Task Force (IETF)
Date Requested: 12/13/2010
Status: Resolved
Status Date: 5/19/2011 10:18:05 AM
Licensing Needs: Not Provided
Deployment Locations: Not Provided
Open Source:
Assigned To: IS
VA Category: This request has not been classified.
Resolution: This is a standard from The Internet Engineering Task Force (IETF) and can be found here, http://datatracker.ietf.org/doc/rfc3852/. While this standard can be used it is also noted that it has been made obsolete by IETF RFC 5652. This updated standard can be found here, http://datatracker.ietf.org/doc/rfc5652/.