<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.bonnell-lamps-chameleon-certs" target="https://datatracker.ietf.org/doc/html/draft-bonnell-lamps-chameleon-certs-07">
   <front>
      <title>A Mechanism for Encoding Differences in Paired Certificates</title>
      <author initials="C." surname="Bonnell" fullname="Corey Bonnell">
         <organization>DigiCert</organization>
      </author>
      <author initials="J." surname="Gray" fullname="John Gray">
         <organization>Entrust</organization>
      </author>
      <author initials="D." surname="Hook" fullname="D. Hook">
         <organization>KeyFactor</organization>
      </author>
      <author initials="T." surname="Okubo" fullname="Tomofumi Okubo">
         <organization>DigiCert</organization>
      </author>
      <author initials="M." surname="Ounsworth" fullname="Mike Ounsworth">
         <organization>Entrust</organization>
      </author>
      <date month="October" day="18" year="2025" />
      <abstract>
	 <t>   This document specifies a method to efficiently convey the
   differences between two certificates in an X.509 version 3 extension.
   This method allows a relying party to extract information sufficient
   to reconstruct the paired certificate and perform certification path
   validation using the reconstructed certificate.  In particular, this
   method is especially useful as part of a key or signature algorithm
   migration, where subjects may be issued multiple certificates
   containing different public keys or signed with different CA private
   keys or signature algorithms.  This method does not require any
   changes to the certification path validation algorithm as described
   in RFC 5280.  Additionally, this method does not violate the
   constraints of serial number uniqueness for certificates issued by a
   single certification authority.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-bonnell-lamps-chameleon-certs-07" />
   
</reference>
