<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.westerbaan-secdispatch-mpic" target="https://datatracker.ietf.org/doc/html/draft-westerbaan-secdispatch-mpic-00">
   <front>
      <title>Multi-Perspective Issuance Corroboration (MPIC) Service</title>
      <author initials="S." surname="Ahmad" fullname="Syed Suleman Ahmad">
         <organization>Cloudflare</organization>
      </author>
      <author initials="B." surname="Westerbaan" fullname="Bas Westerbaan">
         <organization>Cloudflare</organization>
      </author>
      <author initials="H." surname="Birge-Lee" fullname="Henry Birge-Lee">
         <organization>Princeton University</organization>
      </author>
      <date month="October" day="21" year="2024" />
      <abstract>
	 <t>   This memo defines an API for Multi-Perspective Issuance Corroboration
   (MPIC) services to facilitate domain control validation (DCV) from
   multiple network perspectives.  MPIC enhances the security of
   publicly-trusted certificate issuance by mitigating the risk of
   localized, equally-specific BGP hijacking attacks that can undermine
   traditional DCV methods permitted by the CA/Browser Forum Baseline
   Requirements for TLS Server Certificates.  This API enables
   Certification Authorities (CAs) to more reliably integrate with
   external MPIC providers, promoting a more robust and resilient Web
   PKI ecosystem.  The API design prioritizes flexibility, scalability,
   and interoperability, allowing for diverse implementations and
   deployment models.  This standardization effort is driven by the need
   to consistently address vulnerabilities in the domain validation
   process highlighted by recent research and real-world attacks, as
   reflected in Ballot SC-067 V3 of the CA/Browser Forum&#x27;s Server
   Certificate Working Group.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-westerbaan-secdispatch-mpic-00" />
   
</reference>
