Skip to main content

One Signature Certificates
draft-lamps-one-signature-certs-00

Document Type Replaced Internet-Draft (individual)
Expired & archived
Authors Stefan Santesson , Russ Housley
Last updated 2026-04-13 (Latest revision 2026-04-08)
Replaces draft-santesson-one-signature-certs
Replaced by draft-ietf-lamps-one-signature-certs
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-ietf-lamps-one-signature-certs
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

This document defines a profile for certificates that are issued for validation of the digital signature produced by a single signing operation. Each certificate is created at the time of signing and bound to the signed content. The associated signing key is generated, used to produce a single digital signature, and then immediately destroyed. The certificate never expires and is never revoked, which simplifies long-term validation.

Authors

Stefan Santesson
Russ Housley

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)