Merkle Tree Certificates
draft-davidben-tls-merkle-tree-certs-10
| Document | Type |
Replaced Internet-Draft
(plants WG)
Expired & archived
|
|
|---|---|---|---|
| Authors | David Benjamin , Devon O'Brien , Bas Westerbaan , Luke Valenta , Filippo Valsorda | ||
| Last updated | 2026-02-18 (Latest revision 2026-01-22) | ||
| Replaced by | draft-ietf-plants-merkle-tree-certs | ||
| RFC stream | Internet Engineering Task Force (IETF) | ||
| Intended RFC status | (None) | ||
| Formats | |||
| Additional resources | Mailing list discussion | ||
| Stream | WG state | Adopted by a WG | |
| Document shepherd | (None) | ||
| IESG | IESG state | Replaced by draft-ietf-plants-merkle-tree-certs | |
| Consensus boilerplate | Unknown | ||
| Telechat date | (None) | ||
| Responsible AD | (None) | ||
| Send notices to | (None) |
This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:
Abstract
This document describes Merkle Tree certificates, a new form of X.509 certificates which integrate public logging of the certificate, in the style of Certificate Transparency. The integrated design reduces logging overhead in the face of both shorter-lived certificates and large post-quantum signature algorithms, while still achieving comparable security properties to traditional X.509 and Certificate Transparency. Merkle Tree certificates additionally admit an optional signatureless optimization, which decreases the message size by avoiding signatures altogether, at the cost of only applying to up-to-date relying parties and older certificates.
Authors
David Benjamin
Devon O'Brien
Bas Westerbaan
Luke Valenta
Filippo Valsorda
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)