%% You should probably cite draft-ietf-lamps-csr-attestation-28 instead of this revision. @techreport{ietf-lamps-csr-attestation-27, number = {draft-ietf-lamps-csr-attestation-27}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-lamps-csr-attestation/27/}, author = {Mike Ounsworth and Hannes Tschofenig and Henk Birkholz and Monty Wiseman and Ned Smith}, title = {{Use of Remote Attestation with Certification Signing Requests}}, pagetotal = 17, year = 2026, month = may, day = 20, abstract = {Certification Authorities (CAs) issuing certificates to Public Key Infrastructure (PKI) end entities may require a certificate signing request (CSR) to include additional verifiable information to confirm policy compliance. For example, a CA may require an end entity to demonstrate that the private key corresponding to a CSR's public key is secured by a hardware security module (HSM), is not exportable, etc. The process of generating, transmitting, and verifying additional information required by the CA is called remote attestation. While work is currently underway to standardize various aspects of remote attestation, a variety of proprietary mechanisms have been in use for years, particularly regarding protection of private keys. This specification defines ASN.1 structures which may carry attestation data for PKCS\#10 and Certificate Request Message Format (CRMF) messages. Both standardized and proprietary attestation formats are supported by this specification.}, }