%% You should probably cite draft-ietf-lamps-csr-attestation-29 instead of this revision. @techreport{ietf-lamps-csr-attestation-09, number = {draft-ietf-lamps-csr-attestation-09}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-lamps-csr-attestation/09/}, author = {Mike Ounsworth and Hannes Tschofenig and Henk Birkholz and Monty Wiseman}, title = {{Use of Remote Attestation with Certification Signing Requests}}, pagetotal = 39, year = 2024, month = may, day = 10, abstract = {A PKI end entity requesting a certificate from a Certification Authority (CA) may wish to offer believable claims about the protections afforded to the corresponding private key, such as whether the private key resides on a hardware security module or the protection capabilities provided by the hardware. This document defines a new PKCS\#10 attribute attr-evidence and CRMF extension ext-evidence that allows placing any Evidence data, in any pre-existing format, along with any certificates needed to validate it, into a PKCS\#10 or CRMF CSR. Including Evidence along with a CSR can help to improve the assessment of the security posture for the private key, and the trustworthiness properties of the submitted key to the requested certificate profile. These Evidence Claims can include information about the hardware component's manufacturer, the version of installed or running firmware, the version of software installed or running in layers above the firmware, or the presence of hardware components providing specific protection capabilities or shielded locations (e.g., to protect keys).}, }