4 ms·
Yes, the situation is somewhat confusing. RFCs produced by the IRTF are not IETF standards. However, as a practical matter, when the IETF wants to specify cryp
by ekr____ 2y ago
Yes, the situation is somewhat confusing.
RFCs produced by the IRTF are not IETF standards. However, as a practical matter, when the IETF wants to specify cryptographic algorithms, it has the Cryptographic Forum Research Group (part of IRTF) do it. HPKE is one such case, but see also X25519 (RFC 7748), Verifiable Random Functions (RFC 9381), etc. The CFRG has its own consensus development process that terminates in RFCs which are then treated more or less as standards even they are formally not.
This doesn't apply to other IRTF RFCs, which generally aren't treated as having any special status.