<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-tls-subcerts" target="https://datatracker.ietf.org/doc/html/draft-ietf-tls-subcerts-12">
   <front>
      <title>Delegated Credentials for (D)TLS</title>
      <author initials="R." surname="Barnes" fullname="Richard Barnes">
         <organization>Cisco</organization>
      </author>
      <author initials="S." surname="Iyengar" fullname="Subodh Iyengar">
         <organization>Facebook</organization>
      </author>
      <author initials="N." surname="Sullivan" fullname="Nick Sullivan">
         <organization>Cloudflare</organization>
      </author>
      <author initials="E." surname="Rescorla" fullname="Eric Rescorla">
         <organization>Mozilla</organization>
      </author>
      <date month="March" day="7" year="2022" />
      <abstract>
	 <t>   The organizational separation between the operator of a (D)TLS
   endpoint and the certification authority can create limitations.  For
   example, the lifetime of certificates, how they may be used, and the
   algorithms they support are ultimately determined by the
   certification authority.  This document describes a mechanism to to
   overcome some of these limitations by enabling operators to delegate
   their own credentials for use in (D)TLS without breaking
   compatibility with peers that do not support this specification.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-tls-subcerts-12" />
   
</reference>
