X.509 Certificate Extensions for Attestation Results
draft-ounsworth-lamps-x509-ar-00
| Document | Type |
Expired Internet-Draft
(individual)
Expired & archived
|
|
|---|---|---|---|
| Authors | Mike Ounsworth , Monty Wiseman , Hannes Tschofenig , Tirumaleswar Reddy.K , Ned Smith | ||
| Last updated | 2025-11-02 (Latest revision 2025-04-26) | ||
| RFC stream | (None) | ||
| Intended RFC status | (None) | ||
| Formats | |||
| Stream | Stream state | (No stream defined) | |
| Consensus boilerplate | Unknown | ||
| RFC Editor Note | (None) | ||
| IESG | IESG state | Expired | |
| Telechat date | (None) | ||
| Responsible AD | (None) | ||
| Send notices to | (None) |
This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:
Abstract
This document defines extensions for X.509 certificates to include attestation results as part of the certificate's content. The primary use case for these extensions is in the context of Certificate Signing Request (CSR) attestation, where claims about the trustworthiness of an Attester are conveyed to the Certification Authority (CA) as part of the CSR process. These extensions enable the CA to appraise the submitted evidence and embed attestation results into the issued certificate. This allows Relying Parties to evaluate the Attester's trustworthiness consistently and efficiently, supporting scalable policies for verification in environments with diverse attestation technologies.
Authors
Mike Ounsworth
Monty Wiseman
Hannes Tschofenig
Tirumaleswar Reddy.K
Ned Smith
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)