@techreport{beck-lamps-leafy-greens-00, number = {draft-beck-lamps-leafy-greens-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-beck-lamps-leafy-greens/00/}, author = {Bob Beck and Mike Ounsworth}, title = {{Leafy Greens - End Entity Name Restrictions}}, pagetotal = 10, year = 2026, month = jul, day = 3, abstract = {The interaction of name constraint matching in {[}RFC5280{]} and wildcard subject alternative names creates a gap in which an excluded name constraint cannot be relied upon to prevent the issuance of certificates usable for the excluded name. This document defines End Entity Name Restrictions (EENR), a new critical X.509 extension for CA certificates that constrains the dNSName Subject Alternative Name entries which may appear in end entity certificates issued beneath the CA. EENR specifies its own matching semantics, including for wildcard dNSName entries, so that it does not depend on application- defined interpretations. The extension is scoped to use in certificate path validation for TLS client and TLS server authentication.}, }