@techreport{ietf-lamps-one-signature-certs-02, number = {draft-ietf-lamps-one-signature-certs-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-lamps-one-signature-certs/02/}, author = {Stefan Santesson and Russ Housley}, title = {{One Signature Certificates}}, pagetotal = 17, year = 2026, month = jul, day = 1, abstract = {This document defines the signedDocumentBinding certificate extension, which binds a certificate to the signed content of a digital signature produced by a single signing operation. Each certificate is created at the time of signing and the associated signing key is generated, used to produce a single digital signature, and then immediately destroyed. Certificates carrying this extension are intended to be issued without a revocation mechanism and with no expiration, which simplifies long-term validation.}, }