@techreport{ietf-cose-cbor-encoded-cert-20, number = {draft-ietf-cose-cbor-encoded-cert-20}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-cose-cbor-encoded-cert/20/}, author = {John Preuß Mattsson and Göran Selander and Shahid Raza and Joel Höglund and Martin Furuhed and Lijun Liao}, title = {{CBOR Encoded X.509 Certificates (C509 Certificates)}}, pagetotal = 98, year = 2026, month = jun, day = 30, abstract = {This document specifies a CBOR encoding of X.509 certificates. The resulting certificates are called C509 certificates. The CBOR encoding supports a large subset of RFC 5280 and common certificate profiles, and it is extensible. Two types of C509 certificates are defined. One type is an invertible CBOR re-encoding of DER-encoded X.509 certificates with the signature field copied from the DER encoding. The other type is identical except that the signature is computed over the CBOR encoding instead of the DER encoding, thereby avoiding the use of ASN.1. Both types of certificates have the same semantics as X.509 while providing comparable size reduction. This document also specifies CBOR-encoded data structures for certification requests and certification request templates, new COSE headers, as well as a TLS certificate type and a file format for C509. This document updates RFC 6698 by extending the TLSA selectors registry to include C509 certificates.}, }