<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-rats-pkix-key-attestation" target="https://datatracker.ietf.org/doc/html/draft-ietf-rats-pkix-key-attestation-02">
   <front>
      <title>PKIX Evidence for Remote Attestation of Hardware Security Modules</title>
      <author initials="M." surname="Ounsworth" fullname="Mike Ounsworth">
         <organization>Entrust Limited</organization>
      </author>
      <author initials="J." surname="Fiset" fullname="Jean-Pierre Fiset">
         <organization>Crypto4A Inc.</organization>
      </author>
      <author initials="H." surname="Tschofenig" fullname="Hannes Tschofenig">
         <organization>University of Applied Sciences Bonn-Rhein-Sieg</organization>
      </author>
      <author initials="H." surname="Birkholz" fullname="Henk Birkholz">
         <organization>Fraunhofer SIT</organization>
      </author>
      <author initials="M." surname="Wiseman" fullname="Monty Wiseman">
         </author>
      <author initials="N." surname="Smith" fullname="Ned Smith">
         <organization>Intel Corporation</organization>
      </author>
      <date month="October" day="10" year="2025" />
      <abstract>
	 <t>   This document specifies a vendor-agnostic format for evidence
   produced and verified within a PKIX context.  The evidence produced
   this way includes claims collected about a cryptographic module and
   elements found within it such as cryptographic keys.

   One scenario envisaged is that the state information about the
   cryptographic module can be securely presented to a remote operator
   or auditor in a vendor-agnostic verifiable format.  A more complex
   scenario would be to submit this evidence to a Certification
   Authority to aid in determining whether the storage properties of
   this key meet the requirements of a given certificate profile.

   This specification also offers a format for requesting a
   cryptographic module to produce evidence tailored for expected use.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-rats-pkix-key-attestation-02" />
   
</reference>
