<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.wendt-stir-tn-domain-binding" target="https://datatracker.ietf.org/doc/html/draft-wendt-stir-tn-domain-binding-00">
   <front>
      <title>Binding a Domain Identifier to Telephone Number Authority in STIR Certificates</title>
      <author initials="C." surname="Wendt" fullname="Chris Wendt">
         <organization>Somos, Inc.</organization>
      </author>
      <date month="July" day="6" year="2026" />
      <abstract>
	 <t>   This document defines a mechanism for binding a domain identifier to
   telephone number authority within a STIR certificate.  A certificate
   produced under this mechanism carries, as a co-validated pair, the
   telephone numbers or service provider codes a subject is authorized
   for in a TNAuthList extension and a domain the subject controls in a
   SubjectAltName dNSName entry.  The binding is established at issuance
   by requiring proof of domain control and validation of a TNAuthList
   authority token within a single certificate issuance, such that the
   resulting certificate attests that the same entity holds both.  The
   mechanism applies to STIR certificates whose TNAuthList contains
   telephone number entries, service provider code entries, or both,
   allowing a domain to be bound to the right-to-use holder for a set of
   numbers or to the provider identified by a service provider code.
   This document defines the issuance conformance requirements and the
   relying party verification rule that together make the binding
   meaningful.  It does not define telephone number or service provider
   code authorization or domain validation, both of which are specified
   elsewhere and referenced here.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-wendt-stir-tn-domain-binding-00" />
   
</reference>
