Skip to main content

Remote Attestation with Exported Authenticators
draft-fossati-tls-exported-attestation-02

Document Type Replaced Internet-Draft (individual)
Expired & archived
Authors Thomas Fossati , Muhammad Usama Sardar , Tirumaleswar Reddy.K , Yaron Sheffer , Hannes Tschofenig , Ionuț Mihalcea
Last updated 2025-07-03
Replaced by draft-fossati-seat-expat
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-fossati-seat-expat
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

This specification defines a method for two parties in a communication interaction to exchange Evidence and Attestation Results using exported authenticators, as defined in RFC 9261. Additionally, it introduces the cmw_attestation extension, which allows attestation credentials to be included directly in the Certificate message sent during the Exported Authenticator-based post-handshake authentication. The approach supports both the passport and background check models from the RATS architecture while ensuring that attestation remains bound to the underlying communication channel.

Authors

Thomas Fossati
Muhammad Usama Sardar
Tirumaleswar Reddy.K
Yaron Sheffer
Hannes Tschofenig
Ionuț Mihalcea

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)