Skip to main content

Leafy Greens - End Entity Name Restrictions
draft-leafy-greens-00

Document Type Replaced Internet-Draft (individual)
Expired & archived
Authors Bob Beck , Mike Ounsworth
Last updated 2026-06-25
Replaced by draft-beck-lamps-leafy-greens
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-beck-lamps-leafy-greens
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

The interaction of name constraint matching in [RFC5280] and wildcard subject alternative names creates a gap in which an excluded name constraint cannot be relied upon to prevent the issuance of certificates usable for the excluded name. This document defines End Entity Name Restrictions (EENR), a new critical X.509 extension for CA certificates that constrains the dNSName Subject Alternative Name entries which may appear in end entity certificates issued beneath the CA. EENR specifies its own matching semantics, including for wildcard dNSName entries, so that it does not depend on application- defined interpretations. The extension is scoped to use in certificate path validation for TLS client and TLS server authentication.

Authors

Bob Beck
Mike Ounsworth

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)