CMS Signer Algorithm Support

The following lists algorithm support for the CMS Signer.

Signature Algorithms

The signer also relies on support for the algorithm in the Crypto Token used. Ensure that the desired algorithm is supported by the configured crypto token. 

The following lists supported algorithms that are tested and known to work with a Crypto Token supporting it and therefore the list may not be complete.

Support

Algorithm Name

Also Known As

Comment

check mark

SHA1withECDSA

ECDSA using SHA1


check mark

SHA224withECDSA

ECDSA using SHA224


check mark

SHA256withECDSA

ECDSA using SHA256


check mark

SHA384withECDSA

ECDSA using SHA384


check mark

SHA512withECDSA

ECDSA using SHA512


minus

NONEwithECDSA

ECDSA

Not applicable to CMS signatures.

check mark

Ed25519

Pure EdDSA with Edwards25519


check mark

Ed448

Pure EdDSA with Edwards448


check mark

SHA1withRSA

RSASSA-PKCS1_v1.5 using SHA1


check mark

SHA224withRSA

RSASSA-PKCS1_v1.5 using SHA224


check mark

SHA256withRSA

RSASSA-PKCS1_v1.5 using SHA256


check mark

SHA384withRSA

RSASSA-PKCS1_v1.5 using SHA384


check mark

SHA512withRSA

RSASSA-PKCS1_v1.5 using SHA512


minus

NONEwithRSA

RSASSA-PKCS1_v1.5

Not applicable to CMS signatures.

check mark

SHA1withRSAandMGF1

RSASSA-PSS using SHA1


check mark

SHA224withRSAandMGF1

RSASSA-PSS using SHA224


check mark

SHA256withRSAandMGF1

RSASSA-PSS using SHA256


check mark

SHA384withRSAandMGF1

RSASSA-PSS using SHA384


check mark

SHA512withRSAandMGF1

RSASSA-PSS using SHA512


minus

NONEwithRSAandMGF1

RSASSA-PSS

Not applicable to CMS signatures.

warning

ML-DSA-44

Pure ML-DSA-44

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

ML-DSA-65

Pure ML-DSA-65

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

ML-DSA-87

Pure ML-DSA-87

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHA2-128F

Pure SLH-DSA-SHA2-128F

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHA2-128S

Pure SLH-DSA-SHA2-128S

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHA2-192F

Pure SLH-DSA-SHA2-192F

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHA2-192S

Pure SLH-DSA-SHA2-192S

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHA2-256F

Pure SLH-DSA-SHA2-256F

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHA2-256S

Pure SLH-DSA-SHA2-256S

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHAKE-128F

Pure SLH-DSA-SHAKE-128F

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHAKE-128S

Pure SLH-DSA-SHAKE-128S

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHAKE-192F

Pure SLH-DSA-SHAKE-192F

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHAKE-192S

Pure SLH-DSA-SHAKE-192S

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHAKE-256F

Pure SLH-DSA-SHAKE-256F

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

SLH-DSA-SHAKE-256S

Pure SLH-DSA-SHAKE-256S

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

MLDSA44-RSA2048-PSS-SHA256

-

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

MLDSA87-RSA3072-PSS-SHA512

-

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

MLDSA44-ECDSA-P256-SHA256

-

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

warning

MLDSA87-ECDSA-P521-SHA512

-

Supported but as the standard for use of this algorithm in CMS is not finalized the signature format may change in the future.

Digest Algorithms

Support

Algorithm Name

Comment

check mark

SHA1


check mark

SHA224


check mark

SHA256


check mark

SHA384


check mark

SHA512