<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.beck-lamps-leafy-greens" target="https://datatracker.ietf.org/doc/html/draft-beck-lamps-leafy-greens-00">
   <front>
      <title>Leafy Greens - End Entity Name Restrictions</title>
      <author initials="B." surname="Beck" fullname="Bob Beck">
         <organization>OpenSSL</organization>
      </author>
      <author initials="M." surname="Ounsworth" fullname="Mike Ounsworth">
         <organization>Cryptic Forest Software</organization>
      </author>
      <date month="July" day="3" year="2026" />
      <abstract>
	 <t>   The interaction of name constraint matching in [RFC5280] and wildcard
   subject alternative names creates a gap in which an excluded name
   constraint cannot be relied upon to prevent the issuance of
   certificates usable for the excluded name.  This document defines End
   Entity Name Restrictions (EENR), a new critical X.509 extension for
   CA certificates that constrains the dNSName Subject Alternative Name
   entries which may appear in end entity certificates issued beneath
   the CA.  EENR specifies its own matching semantics, including for
   wildcard dNSName entries, so that it does not depend on application-
   defined interpretations.  The extension is scoped to use in
   certificate path validation for TLS client and TLS server
   authentication.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-beck-lamps-leafy-greens-00" />
   
</reference>
