I have submitted a personal draft -- draft-ramsdell-smime-sha256 to
address what I believe is consensus in the WG about this issue. There
are some holes that need to be filled (specifically references for
the exact threat, and guidance text for the use of the algorithm),
and we need to decide on a final form (do we revise RFC3850 and
RFC3851 or do we publish an errata document).
The boilerplate for RFCs dwarfs the actual content -- it's pretty
simple stuff. When it pops out in the repository I will mention it on
the mailing list.
Blake
--
Blake Ramsdell | Sendmail, Inc. | http://www.sendmail.com