Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.


For more information on products and upcoming events around #dominoforever, please visit: HCL Domino Page


Status Under Consideration
Workspace Domino
Categories Security
Created by Guest
Created on Mar 2, 2026

Support for OID 1.2.840.113549.1.1.10 signature algorithm

Domino currently does not support the signature algorithm 1.2.840.113549.1.1.10. This request is to enable support.

  • Attach files
  • Guest
    Jul 9, 2026

    In what context? S/MIME certificates signed with RSA-PSS? S/MIME messages signed with RSA-PSS? TLS certificates signed with RSA-PSS? Something else? (Please note that Let's Encrypt and most commercial CAs don't actually support certificate requests signed with RSA-PSS or issuing certs signed with RSA-PSS)


    The current push within the security community is to add support for Post-Quantum Cryptography, including composite Post-Quantum/Traditional (PQ/T) hybrid algorithms that use RSA-PSS for their Traditional component. See

    https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-sigs/

    and

    https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-kem/

    for details. Adding support for a new Traditional-only signing algorithm in this day and age would be a dead-end path.

  • Guest
    Mar 3, 2026

    If this is for the RSA-PSS signing only and not RSA-PSS keys, I would vote yes.
    Why do you specify the OID only and not the name?