Skip to main content

Guide for building an EC PKI

Document Type Expired Internet-Draft (individual)
Expired & archived
Authors Robert Moskowitz , Henk Birkholz , Michael Richardson
Last updated 2024-08-04 (Latest revision 2024-02-01)
Replaces draft-moskowitz-eddsa-pki
RFC stream (None)
Intended RFC status (None)
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:


This memo provides a guide for building a PKI (Public Key Infrastructure) of EC certificates using openSSL. Certificates in this guide can use either ECDSA or EdDSA. Along with common End Entity certificates, this guide provides instructions for creating IEEE 802.1AR iDevID Secure Device certificates.


Robert Moskowitz
Henk Birkholz
Michael Richardson

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)