%% You should probably cite draft-ietf-rats-pkix-key-attestation-07 instead of this revision. @techreport{ietf-rats-pkix-key-attestation-02, number = {draft-ietf-rats-pkix-key-attestation-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-rats-pkix-key-attestation/02/}, author = {Mike Ounsworth and Jean-Pierre Fiset and Hannes Tschofenig and Henk Birkholz and Monty Wiseman and Ned Smith}, title = {{PKIX Evidence for Remote Attestation of Hardware Security Modules}}, pagetotal = 53, year = , month = , day = , abstract = {This document specifies a vendor-agnostic format for evidence produced and verified within a PKIX context. The evidence produced this way includes claims collected about a cryptographic module and elements found within it such as cryptographic keys. One scenario envisaged is that the state information about the cryptographic module can be securely presented to a remote operator or auditor in a vendor-agnostic verifiable format. A more complex scenario would be to submit this evidence to a Certification Authority to aid in determining whether the storage properties of this key meet the requirements of a given certificate profile. This specification also offers a format for requesting a cryptographic module to produce evidence tailored for expected use.}, }