Skip to main content

X.509 Certificate Extensions for Attestation Results
draft-ounsworth-lamps-x509-ar-00

Document Type Expired Internet-Draft (individual)
Expired & archived
Authors Mike Ounsworth , Monty Wiseman , Hannes Tschofenig , Tirumaleswar Reddy.K , Ned Smith
Last updated 2025-11-02 (Latest revision 2025-04-26)
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

This document defines extensions for X.509 certificates to include attestation results as part of the certificate's content. The primary use case for these extensions is in the context of Certificate Signing Request (CSR) attestation, where claims about the trustworthiness of an Attester are conveyed to the Certification Authority (CA) as part of the CSR process. These extensions enable the CA to appraise the submitted evidence and embed attestation results into the issued certificate. This allows Relying Parties to evaluate the Attester's trustworthiness consistently and efficiently, supporting scalable policies for verification in environments with diverse attestation technologies.

Authors

Mike Ounsworth
Monty Wiseman
Hannes Tschofenig
Tirumaleswar Reddy.K
Ned Smith

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)